Netapp
netapp
2,507 CVEs • 371 products
Products (371)
Click to collapseToggle
Products (371)
Click to collapse
CVEs (2,507)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Apache DebianNetapp+2 more10Activemq Debian LinuxDrill+7 moreNov 21, 2024 May 23, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 An issue is present in Apache ZooKeeper 1.0.0 to 3.4.13 and 3.5.0-alpha to 3.5.4-beta. ZooKeeper’s getACL() command doesn’t check any permission when retrieves the ACLs of the requested node and returns all information c...Show more |
2Netapp Systemd Project4Cn1610 Firmware SnapprotectSolidfire & Hci Management Node+1 moreMay 5, 2025 May 17, 2019 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 systemd 242 changes the VT1 mode upon a logout, which allows attackers to read cleartext passwords in certain circumstances, such as watching a shutdown, or using Ctrl-Alt-F1 and Ctrl-Alt-F2. This occurs because the KDGK...Show more |
5Fedoraproject HpeNetapp+2 more6Clustered Data Ontap Data OntapFedora+3 moreNov 21, 2024 May 15, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 NTP through 4.2.8p12 has a NULL Pointer Dereference. |
Oncommand Insight versions prior to 7.3.5 shipped without certain HTTP Security headers configured which could allow an attacker to obtain sensitive information via unspecified vectors. |
1Netapp 1Oncommand Unified Manager Nov 21, 2024 May 10, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 OnCommand Unified Manager for VMware vSphere, Linux and Windows prior to 9.5 shipped without certain HTTP Security headers configured which could allow an attacker to obtain sensitive information via unspecified vectors. |
1Netapp 1Oncommand Unified Manager Nov 21, 2024 May 10, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 OnCommand Unified Manager 7-Mode prior to version 5.2.4 shipped without certain HTTP Security headers configured which could allow an attacker to obtain sensitive information via unspecified vectors. |
5Canonical DebianLinux+2 more14Active Iq Unified Manager Cn1610 FirmwareDebian Linux+11 moreNov 21, 2024 May 8, 2019 N/A· v4 8.1 HIGH· v3 9.3 HIGH· v2 An issue was discovered in rds_tcp_kill_sock in net/rds/tcp.c in the Linux kernel before 5.0.8. There is a race condition leading to a use-after-free, related to net namespace cleanup. |
6Canonical DebianF5+3 more13Active Iq Unified Manager Debian LinuxHci Compute Node+10 moreNov 21, 2024 May 7, 2019 N/A· v4 8.1 HIGH· v3 9.3 HIGH· v2 An issue was discovered in the Linux kernel before 4.20. There is a race condition in smp_task_timedout() and smp_task_done() in drivers/scsi/libsas/sas_expander.c, leading to a use-after-free. |
1Netapp 2Element Plug In For Vcenter Server Hyper Converged Infrastructure Compute NodeNov 21, 2024 Apr 29, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Element Plug-in for vCenter Server versions prior to 4.2.3 may disclose sensitive account information to an unauthenticated attacker. NetApp HCI Compute Node versions prior to 1.4P2 bundle affected versions of Element Pl...Show more |
3Canonical NetappSystemd Project6Cn1610 Firmware Hci Management NodeSnapprotect+3 moreNov 21, 2024 Apr 26, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 It was discovered that a systemd service that uses DynamicUser property can get new privileges through the execution of SUID binaries, which would allow to create binaries owned by the service transient group with the se...Show more |
4Canonical FedoraprojectNetapp+1 more7Cn1610 Firmware FedoraHci Management Node+4 moreNov 21, 2024 Apr 26, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 It was discovered that a systemd service that uses DynamicUser property can create a SUID/SGID binary that would be allowed to run as the transient service UID/GID even after the service is terminated. A local attacker m...Show more |
7Canonical DebianFedoraproject+4 more14Active Iq Unified Manager For Vmware Vsphere Cn1610 FirmwareDebian Linux+11 moreNov 21, 2024 Apr 25, 2019 N/A· v4 7.7 HIGH· v3 6.8 MEDIUM· v2 An infinite loop issue was found in the vhost_net kernel module in Linux Kernel up to and including v5.1-rc6, while handling incoming packets in handle_rx(). It could occur if one end sends packets faster than the other...Show more |
6Canonical DebianFedoraproject+3 more13Active Iq Unified Manager For Vmware Vsphere Cn1610 FirmwareDebian Linux+10 moreNov 21, 2024 Apr 24, 2019 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 A flaw was found in the Linux kernel's vfio interface implementation that permits violation of the user's locked memory limit. If a device is bound to a vfio driver, such as vfio-pci, and the local attacker is administra...Show more |
4Debian LinuxNetapp+1 more10Active Iq Debian LinuxHci Management Node+7 moreNov 21, 2024 Apr 23, 2019 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 The Siemens R3964 line discipline driver in drivers/tty/n_r3964.c in the Linux kernel before 5.0.8 has multiple race conditions. |
4Debian EclipseNetapp+1 more26Autovue Communications AnalyticsCommunications Element Manager+23 moreNov 21, 2024 Apr 22, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In Eclipse Jetty version 7.x, 8.x, 9.2.27 and older, 9.3.26 and older, and 9.4.16 and older, the server running on any OS and Jetty version combination will reveal the configured fully qualified directory base resource l...Show more |
3Eclipse NetappOracle25Autovue Communications AnalyticsCommunications Element Manager+22 moreNov 21, 2024 Apr 22, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the fully qualified Base Resource directory name on Windows to a remote client when it is configured for sho...Show more |
3Debian LinuxNetapp10Active Iq Unified Manager For Vmware Vsphere Cn1610 FirmwareDebian Linux+7 moreNov 21, 2024 Apr 22, 2019 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 A race condition in perf_event_open() allows local attackers to leak sensitive data from setuid programs. As no relevant locks (in particular the cred_guard_mutex) are held during the ptrace_may_access() call, it is poss...Show more |
3Kubernetes NetappRedhat3Kubernetes Openshift Container PlatformTridentNov 21, 2024 Apr 22, 2019 N/A· v4 5.0 MEDIUM· v3 1.9 LOW· v2 In Kubernetes v1.8.x-v1.14.x, schema info is cached by kubectl in the location specified by --cache-dir (defaulting to $HOME/.kube/http-cache), written with world-writeable permissions (rw-rw-rw-). If --cache-dir is spec...Show more |
2Kubernetes Netapp2Kubernetes TridentNov 21, 2024 Apr 22, 2019 N/A· v4 8.1 HIGH· v3 4.3 MEDIUM· v2 In Kubernetes v1.12.0-v1.12.4 and v1.13.0, the rest.AnonymousClientConfig() method returns a copy of the provided config, with credentials removed (bearer token, username/password, and client certificate/key data). In th...Show more |
11Backdropcms DebianDrupal+8 more105Agile Product Lifecycle Management For Process Application ExpressApplication Service Level Management+102 moreNov 21, 2024 Apr 20, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ p...Show more |