Netapp
netapp
2,507 CVEs • 371 products
Products (371)
Click to collapseToggle
Products (371)
Click to collapse
CVEs (2,507)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Canonical DebianHaxx+2 more7Clustered Data Ontap Communications Operations MonitorDebian Linux+4 moreNov 21, 2024 Feb 6, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 libcurl versions from 7.34.0 to before 7.64.0 are vulnerable to a heap out-of-bounds read in the code handling the end-of-response for SMTP. If the buffer passed to `smtp_endofresp()` isn't NUL terminated and contains no...Show more |
7Canonical DebianHaxx+4 more16Active Iq Unified Manager Clustered Data OntapCommunications Operations Monitor+13 moreNov 21, 2024 Feb 6, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 libcurl versions from 7.36.0 to before 7.64.0 are vulnerable to a stack-based buffer overflow. The function creating an outgoing NTLM type-3 header (`lib/vauth/ntlm.c:Curl_auth_create_ntlm_type3_message()`), generates th...Show more |
8Canonical DebianF5+5 more10Big Ip Access Policy Manager Clustered Data OntapCommunications Operations Monitor+7 moreNov 21, 2024 Feb 6, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 libcurl versions from 7.36.0 to before 7.64.0 is vulnerable to a heap buffer out-of-bounds read. The function handling incoming NTLM type-2 messages (`lib/vauth/ntlm.c:ntlm_decode_type2_target`) does not validate incomin...Show more |
10Canonical DebianHp+7 more32Active Iq Unified Manager Cloud BackupDebian Linux+29 moreMay 28, 2026 Feb 4, 2019 N/A· v4 5.3 MEDIUM· v3 2.6 LOW· v2 png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_safe_execute. |
Clustered Data ONTAP versions 9.0 through 9.4 are susceptible to a vulnerability which allows remote authenticated attackers to cause a Denial of Service (DoS) in NFS and SMB environments. Exploitation of this vulnerabil...Show more |
4Netapp OpenbsdSiemens+1 more7Element Software Ontap Select DeployOpenssh+4 moreDec 18, 2025 Jan 31, 2019 N/A· v4 6.8 MEDIUM· v3 4.0 MEDIUM· v2 In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-The-Middle attacker) can manipulate the client output, for example to use ANSI control codes to hide...Show more |
9Canonical DebianFedoraproject+6 more20Debian Linux Element SoftwareEnterprise Linux+17 moreMay 28, 2026 Jan 31, 2019 N/A· v4 6.8 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered in OpenSSH 7.9. Due to missing character encoding in the progress display, a malicious server (or Man-in-The-Middle attacker) can employ crafted object names to manipulate the client output, e.g.,...Show more |
5Apache CanonicalDebian+2 more6Debian Linux Enterprise Manager Ops CenterHttp Server+3 moreNov 21, 2024 Jan 30, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Apache HTTP Server 2.4 release 2.4.37 and prior, mod_session checks the session expiry time before decoding the session. This causes session expiry time to be ignored for mod_session_cookie sessions since the expiry t...Show more |
7Apache CanonicalDebian+4 more12Debian Linux Enterprise Manager Ops CenterFedora+9 moreNov 21, 2024 Jan 30, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In Apache HTTP server versions 2.4.37 and prior, by sending request bodies in a slow loris way to plain resources, the h2 stream for that request unnecessarily occupied a server thread cleaning up that incoming data. Thi...Show more |
3Canonical DebianNetapp5Active Iq Advanced Package ToolDebian Linux+2 moreNov 21, 2024 Jan 28, 2019 N/A· v4 8.1 HIGH· v3 9.3 HIGH· v2 Incorrect sanitation of the 302 redirect field in HTTP transport method of apt versions 1.4.8 and earlier can lead to content injection by a MITM attacker, potentially leading to remote code execution on the target machi...Show more |
5Canonical DebianLibgd+2 more5Debian Linux LibgdPhp+2 moreNov 21, 2024 Jan 27, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 gdImageColorMatch in gd_color_match.c in the GD Graphics Library (aka LibGD) 2.2.5, as used in the imagecolormatch function in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1, has a heap...Show more |
Clustered Data ONTAP versions prior to 9.1P16, 9.3P10 and 9.4P5 are susceptible to a vulnerability which discloses sensitive information to an unauthorized user. |
2Aspeedtech Netapp3Ast2400 Firmware Ast2500 FirmwareFas/aff Baseboard Management ControllerNov 21, 2024 Jan 22, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The ASPEED ast2400 and ast2500 Baseband Management Controller (BMC) hardware and firmware implement Advanced High-performance Bus (AHB) bridges, which allow arbitrary read and write access to the BMC's physical address s...Show more |
2Brocade Netapp2Brocade Network Advisor Network AdvisorNov 21, 2024 Jan 22, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A Vulnerability in Brocade Network Advisor versions before 14.0.3 could allow a remote unauthenticated attacker to export the current user database which includes the encrypted (not hashed) password of the systems. The a...Show more |
2Brocade Netapp2Brocade Network Advisor Network AdvisorNov 21, 2024 Jan 22, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A Vulnerability in Brocade Network Advisor versions before 14.1.0 could allow a remote unauthenticated attacker to execute arbitray code. The vulnerability could also be exploited to execute arbitrary OS Commands. |
2Brocade Netapp2Brocade Network Advisor Network AdvisorNov 21, 2024 Jan 22, 2019 N/A· v4 8.1 HIGH· v3 4.3 MEDIUM· v2 A vulnerability in Brocade Network Advisor Versions before 14.3.1 could allow an unauthenticated, remote attacker to log in to the JBoss Administration interface of an affected system using an undocumented user credentia...Show more |
7Canonical DebianHp+4 more11Bind Data Ontap EdgeDebian Linux+8 moreNov 21, 2024 Jan 16, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 "deny-answer-aliases" is a little-used feature intended to help recursive server operators protect end users against DNS rebinding attacks, a potential method of circumventing the security model used by client browsers....Show more |
2Isc Netapp3Bind Cloud BackupData Ontap EdgeNov 21, 2024 Jan 16, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A problem with the implementation of the new serve-stale feature in BIND 9.12 can lead to an assertion failure in rbtdb.c, even when stale-answer-enable is off. Additionally, problematic interaction between the serve-sta...Show more |
2Isc Netapp3Bind Cloud BackupData Ontap EdgeNov 21, 2024 Jan 16, 2019 N/A· v4 5.3 MEDIUM· v3 3.5 LOW· v2 An error in zone database reference counting can lead to an assertion failure if a server which is running an affected version of BIND attempts several transfers of a slave zone in quick succession. This defect could be...Show more |
2Isc Netapp3Bind Data Ontap EdgeSolidfire Element Os Management NodeNov 21, 2024 Jan 16, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 While handling a particular type of malformed packet BIND erroneously selects a SERVFAIL rcode instead of a FORMERR rcode. If the receiving view has the SERVFAIL cache feature enabled, this can trigger an assertion failu...Show more |