← Back

Netapp

netapp

2,507 CVEs • 371 products

Products (371)

Click to collapse
Toggle
Snapcenter
snapcenter
Cloud Backup
cloud_backup
Solidfire
solidfire
Snapmanager
snapmanager
Storagegrid
storagegrid
Bootstrap Os
bootstrap_os
Data Ontap
data_ontap
Ontap Tools
ontap_tools
H300s
h300s
H500s
h500s
H700s
h700s
H410s
h410s
Ontap
ontap
Fas/aff Bios
fas/aff_bios
A250 Firmware
a250_firmware
Cloud Manager
cloud_manager
Snapdrive
snapdrive
Snapprotect
snapprotect
A400 Firmware
a400_firmware
Hci
hci
8300 Firmware
8300_firmware
8700 Firmware
8700_firmware

CVEs (2,507)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Linux
NetappOpensuse
7Active Iq Unified Manager
Data Availability ServicesH410c Firmware+4 more
May 28, 2026
Aug 19, 2019
N/A· v4
4.6 MEDIUM· v3
4.9 MEDIUM· v2
An issue was discovered in the Linux kernel before 5.2.3. There is a use-after-free caused by a malicious USB device in the drivers/media/usb/dvb-usb/dvb-usb-init.c driver.
5Canonical
DebianLinux+2 more
9Active Iq Unified Manager
Data Availability ServicesDebian Linux+6 more
Nov 21, 2024
Aug 19, 2019
N/A· v4
4.6 MEDIUM· v3
4.9 MEDIUM· v2
An issue was discovered in the Linux kernel before 5.1.8. There is a double-free caused by a malicious USB device in the drivers/usb/misc/rio500.c driver.
5Canonical
DebianLinux+2 more
9Active Iq Unified Manager
Data Availability ServicesDebian Linux+6 more
Nov 21, 2024
Aug 19, 2019
N/A· v4
4.6 MEDIUM· v3
4.9 MEDIUM· v2
An issue was discovered in the Linux kernel before 5.2.6. There is a use-after-free caused by a malicious USB device in the drivers/media/v4l2-core/v4l2-dev.c driver because drivers/media/radio/radio-raremono.c does not...Show more
An issue was discovered in the Linux kernel before 5.2.6. There is a use-after-free caused by a malicious USB device in the drivers/media/v4l2-core/v4l2-dev.c driver because drivers/media/radio/radio-raremono.c does not properly allocate memory.Show less
5Canonical
DebianLinux+2 more
10Active Iq Unified Manager
Data Availability ServicesDebian Linux+7 more
Nov 21, 2024
Aug 16, 2019
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
check_input_term in sound/usb/mixer.c in the Linux kernel through 5.2.9 mishandles recursion, leading to kernel stack exhaustion.
5Canonical
DebianLinux+2 more
8Active Iq Performance Analytics Services
Active Iq Unified ManagerData Availability Services+5 more
Nov 21, 2024
Aug 16, 2019
N/A· v4
4.6 MEDIUM· v3
4.9 MEDIUM· v2
drivers/net/wireless/ath/ath6kl/usb.c in the Linux kernel through 5.2.9 has a NULL pointer dereference via an incomplete address in an endpoint descriptor.
12Apache
AppleCanonical+9 more
23Clustered Data Ontap
Communications Element ManagerDebian Linux+20 more
Jan 14, 2025
Aug 13, 2019
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service. The attacker opens the HTTP/2 window so the peer can send without constraint; however, they...Show more
Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service. The attacker opens the HTTP/2 window so the peer can send without constraint; however, they leave the TCP window closed so the peer cannot actually write (many of) the bytes on the wire. The attacker then sends a stream of requests for a large response object. Depending on how the servers queue the responses, this can consume excess memory, CPU, or both.Show less
13Apache
AppleCanonical+10 more
28Big Ip Local Traffic Manager
Cloud InsightsDebian Linux+25 more
Jan 14, 2025
Aug 13, 2019
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and sends an invalid request over each stream that should solicit a stream o...Show more
Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and sends an invalid request over each stream that should solicit a stream of RST_STREAM frames from the peer. Depending on how the peer queues the RST_STREAM frames, this can consume excess memory, CPU, or both.Show less
6Belden
NetappOracle+3 more
13Communications Eagle
E Series Santricity Os ControllerGarrettcom Magnum Dx940e Firmware+10 more
Nov 21, 2024
Aug 9, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Wind River VxWorks 6.7 though 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 3 of 4). This is an IPNET security vulnerability: TCP Urgent Pointer state confusion during connect() to a remote host.
6Belden
NetappOracle+3 more
13Communications Eagle
E Series Santricity Os ControllerGarrettcom Magnum Dx940e Firmware+10 more
Nov 21, 2024
Aug 9, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 2 of 4). This is an IPNET security vulnerability: TCP Urgent Pointer state confusion caused by a malformed TCP AO option.
5Belden
NetappSiemens+2 more
12E Series Santricity Os Controller
Garrettcom Magnum Dx940e FirmwareHirschmann Hios+9 more
Nov 21, 2024
Aug 9, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Wind River VxWorks 6.6 through vx7 has Session Fixation in the TCP component. This is a IPNET security vulnerability: DoS of TCP connection via malformed TCP options.
5Belden
NetappSiemens+2 more
12E Series Santricity Os Controller
Garrettcom Magnum Dx940e FirmwareHirschmann Hios+9 more
Nov 21, 2024
Aug 9, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Wind River VxWorks has a Buffer Overflow in the TCP component (issue 1 of 4). This is a IPNET security vulnerability: TCP Urgent Pointer = 0 that leads to an integer underflow.
5Belden
NetappSiemens+2 more
12E Series Santricity Os Controller
Garrettcom Magnum Dx940e FirmwareHirschmann Hios+9 more
Nov 21, 2024
Aug 9, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Wind River VxWorks 6.5, 6.6, 6.7, 6.8, 6.9.3 and 6.9.4 has a Memory Leak in the IGMPv3 client component. There is an IPNET security vulnerability: IGMP Information leak via IGMPv3 specific membership report.
5Belden
NetappSiemens+2 more
12E Series Santricity Os Controller
Garrettcom Magnum Dx940e FirmwareHirschmann Hios+9 more
Nov 21, 2024
Aug 9, 2019
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
Wind River VxWorks 6.9.4 and vx7 has a Buffer Overflow in the TCP component (issue 4 of 4). There is an IPNET security vulnerability: TCP Urgent Pointer state confusion due to race condition.
1Netapp
1Oncommand Insight
Nov 21, 2024
Aug 9, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
OnCommand Insight versions through 7.3.6 may disclose sensitive account information to an authenticated user.
5Belden
NetappSiemens+2 more
10E Series Santricity Os Controller
Garrettcom Magnum Dx940e FirmwareHirschmann Hios+7 more
Nov 21, 2024
Aug 9, 2019
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
Wind River VxWorks 6.6 through 6.9 has a Buffer Overflow in the DHCP client component. There is an IPNET security vulnerability: Heap overflow in DHCP Offer/ACK parsing inside ipdhcpc.
5Belden
NetappSiemens+2 more
12E Series Santricity Os Controller
Garrettcom Magnum Dx940e FirmwareHirschmann Hios+9 more
Nov 21, 2024
Aug 9, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the IPv4 component. There is an IPNET security vulnerability: Stack overflow in the parsing of IPv4 packets’ IP options.
1Netapp
1Data Ontap
Nov 21, 2024
Aug 5, 2019
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
SMB in Data ONTAP operating in 7-Mode versions prior to 8.2.5P3 has weak cryptography which when exploited could lead to information disclosure or addition or modification of data.
1Netapp
1Data Ontap
Nov 21, 2024
Aug 2, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Data ONTAP operating in 7-Mode versions prior to 8.2.5P3 may disclose sensitive LDAP account information to unauthenticated remote attackers.
1Netapp
1Data Ontap
Nov 21, 2024
Aug 2, 2019
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
Data ONTAP operating in 7-Mode versions prior to 8.2.5P3 are susceptible to a vulnerability which discloses information to an unauthenticated attacker. A successful attack requires that multiple non-default options be en...Show more
Data ONTAP operating in 7-Mode versions prior to 8.2.5P3 are susceptible to a vulnerability which discloses information to an unauthenticated attacker. A successful attack requires that multiple non-default options be enabled.Show less
3Linux
NetappRedhat
20Cloud Backup
Developer ToolsEnterprise Linux+17 more
Nov 21, 2024
Jul 30, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A flaw was found in the Linux kernel's NFS implementation, all versions 3.x and all versions 4.x up to 4.20. An attacker, who is able to mount an exported NFS filesystem, is able to trigger a null pointer dereference by...Show more
A flaw was found in the Linux kernel's NFS implementation, all versions 3.x and all versions 4.x up to 4.20. An attacker, who is able to mount an exported NFS filesystem, is able to trigger a null pointer dereference by using an invalid NFS sequence. This can panic the machine and deny access to the NFS server. Any outstanding disk writes to the NFS server will be lost.Show less