Netapp
netapp
2,507 CVEs • 371 products
Products (371)
Click to collapseToggle
Products (371)
Click to collapse
CVEs (2,507)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Canonical FreebsdNetapp+1 more4Element Software FreebsdNtp+1 moreNov 21, 2024 Mar 8, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Buffer overflow in the decodearr function in ntpq in ntp 4.2.8p6 through 4.2.8p10 allows remote attackers to execute arbitrary code by leveraging an ntpq query and sending a response with a crafted array. |
6Canonical HpeNetapp+3 more16Diskstation Manager Fujitsu M10 1 FirmwareFujitsu M10 4 Firmware+13 moreJan 14, 2025 Mar 6, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The protocol engine in ntp 4.2.6 before 4.2.8p11 allows a remote attackers to cause a denial of service (disruption) by continually sending a packet with a zero-origin timestamp and source IP address of the "other side"...Show more |
5Canonical NetappNtp+2 more10Cloud Backup Diskstation ManagerNtp+7 moreJan 14, 2025 Mar 6, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 ntpd in ntp 4.2.8p4 before 4.2.8p11 drops bad packets before updating the "received" timestamp, which allows remote attackers to cause a denial of service (disruption) by sending a packet with a zero-origin timestamp cau...Show more |
3Canonical NetappNtp3Element Software NtpUbuntu LinuxNov 21, 2024 Mar 6, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The ctl_getitem method in ntpd in ntp-4.2.8p6 before 4.2.8p11 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted mode 6 packet with a ntpd instance from 4.2.8p6 through 4.2.8p10. |
4Hpe NetappNtp+1 more9Diskstation Manager HciHpux Ntp+6 moreJan 14, 2025 Mar 6, 2018 N/A· v4 5.3 MEDIUM· v3 3.5 LOW· v2 ntpd in ntp 4.2.x before 4.2.8p7 and 4.3.x before 4.3.92 allows authenticated users that know the private symmetric key to create arbitrarily-many ephemeral associations in order to win the clock selection of ntpd and mo...Show more |
Versions of SnapCenter 2.0 through 3.0.1 allow unauthenticated remote attackers to view and modify backup related data via the Plug-in for NAS File Services. All users are urged to move to version 3.0.1 and perform the m...Show more |
1Netapp 2Oncommand Api Services Service Level ManagerNov 21, 2024 Feb 23, 2018 N/A· v4 7.8 HIGH· v3 2.1 LOW· v2 All versions of OnCommand API Services prior to 2.1 and NetApp Service Level Manager prior to 1.0RC4 log a privileged database user account password. All users are urged to move to a fixed version. Since the affected pas...Show more |
5Debian FasterxmlNetapp+2 more21Banking Platform Communications Billing And Revenue ManagementCommunications Communications Policy Management+18 moreNov 21, 2024 Feb 6, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to t...Show more |
5Debian FasterxmlNetapp+2 more24Banking Platform ClusterwareCommunications Billing And Revenue Management+21 moreNov 21, 2024 Feb 6, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readV...Show more |
4Gnu NetappOracle+1 more15Cloud Backup Communications Session Border ControllerData Ontap Edge+12 moreNov 21, 2024 Feb 1, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An integer overflow in the implementation of the posix_memalign in memalign functions in the GNU C Library (aka glibc or libc6) 2.26 and earlier could cause these functions to return a pointer to a heap area that is too...Show more |
2Ibm Netapp2Cognos Analytics Oncommand InsightNov 21, 2024 Jan 29, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 IBM Cognos Analytics 11.0 could produce results in temporary files that contain highly sensitive information that can be read by a local user. IBM X-Force ID: 136858. |
2Ibm Netapp2Cognos Analytics Oncommand InsightNov 21, 2024 Jan 29, 2018 N/A· v4 4.0 MEDIUM· v3 2.1 LOW· v2 IBM Cognos Analytics 11.0 could allow a local user to change parameters set from the Cognos Analytics menus without proper authentication. IBM X-Force ID: 136857. |
2Ibm Netapp2Cognos Analytics Oncommand InsightNov 21, 2024 Jan 29, 2018 N/A· v4 7.8 HIGH· v3 2.1 LOW· v2 IBM Cognos Analytics 11.0 could store cached credentials locally that could be obtained by a local user. IBM X-Force ID: 136824. |
4Debian FasterxmlNetapp+1 more9Debian Linux E Series Santricity Os ControllerE Series Santricity Web Services Proxy+6 moreNov 21, 2024 Jan 22, 2018 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 FasterXML jackson-databind through 2.8.11 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 and CVE-2017-17485 deserialization flaws. This is exploita...Show more |
4Canonical DebianNetapp+1 more12Cloud Backup Clustered Data OntapData Ontap+9 moreApr 29, 2026 Jan 21, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 sshd in OpenSSH before 7.4 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an out-of-sequence NEWKEYS message, as demonstrated by Honggfuzz, related to kex.c and packe...Show more |
6Canonical DebianMariadb+3 more15Active Iq Unified Manager Debian LinuxEnterprise Linux Desktop+12 moreNov 21, 2024 Jan 18, 2018 N/A· v4 6.5 MEDIUM· v3 6.8 MEDIUM· v2 Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.5.58 and prior, 5.6.38 and prior and 5.7.20 and prior. Easily exploitable vulnerab...Show more |
6Canonical DebianMariadb+3 more15Active Iq Unified Manager Debian LinuxEnterprise Linux Desktop+12 moreNov 21, 2024 Jan 18, 2018 N/A· v4 6.5 MEDIUM· v3 6.8 MEDIUM· v2 Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.5.58 and prior, 5.6.38 and prior and 5.7.20 and prior. Easily exploitable vulnerab...Show more |
6Canonical DebianMariadb+3 more15Active Iq Unified Manager Debian LinuxEnterprise Linux Desktop+12 moreNov 21, 2024 Jan 18, 2018 N/A· v4 6.5 MEDIUM· v3 6.8 MEDIUM· v2 Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.5.58 and prior, 5.6.38 and prior and 5.7.20 and prior. Easily exploitable vulnerab...Show more |
3Netapp OracleRedhat24Active Iq Unified Manager Cloud BackupE Series Santricity Management Plug Ins+21 moreNov 21, 2024 Jan 18, 2018 N/A· v4 8.3 HIGH· v3 5.1 MEDIUM· v2 Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Supported versions that are affected are Java SE: 8u152 and 9.0.1. Difficult to exploit vulnerability allows unauthenticated attacker w...Show more |
3Netapp OracleRedhat20Active Iq Unified Manager Cloud BackupE Series Santricity Management Plug Ins+17 moreMay 6, 2025 Jan 18, 2018 N/A· v4 7.5 HIGH· v3 3.7 LOW· v2 Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Installer). Supported versions that are affected are Java SE: 8u152 and 9.0.1. Difficult to exploit vulnerability allows low privileged attacker wit...Show more |