Netapp
netapp
2,510 CVEs • 373 products
Products (373)
Click to collapseToggle
Products (373)
Click to collapse
CVEs (2,510)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Netapp Oracle5Cloud Insights Acquisition Unit Cloud Insights Storage Workload Security AgentGraalvm For Jdk+2 moreJun 17, 2026 Oct 17, 2023 N/A· v4 3.7 LOW· v3 N/A· v2 Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition, product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u381-perf, 17.0.8...Show more |
2Netapp Oracle2Mysql Oncommand InsightJun 17, 2026 Oct 17, 2023 N/A· v4 4.9 MEDIUM· v3 N/A· v2 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 5.7.42 and prior and 8.0.31 and prior. Easily exploitable vulnerability allows high pri...Show more |
2Linux Netapp5H300s Firmware H410s FirmwareH500s Firmware+2 moreJun 17, 2026 Oct 16, 2023 N/A· v4 6.3 MEDIUM· v3 N/A· v2 extract_user_to_sg in lib/scatterlist.c in the Linux kernel before 6.4.12 fails to unpin pages in a certain situation, as demonstrated by a WARNING for try_grab_page. |
2Linux Netapp3Active Iq Unified Manager H410c FirmwareLinux KernelJun 17, 2026 Oct 14, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 An issue was discovered in drivers/usb/storage/ene_ub6250.c for the ENE UB6250 reader driver in the Linux kernel before 6.2.5. An object could potentially extend beyond the end of an allocation. |
SnapCenter versions 4.8 through 4.9 are susceptible to a
vulnerability which may allow an authenticated SnapCenter Server user to
become an admin user on a remote system where a SnapCenter plug-in has
been installed. |
ONTAP 9 versions prior to 9.8P19, 9.9.1P16, 9.10.1P12, 9.11.1P8,
9.12.1P2 and 9.13.1 are susceptible to a vulnerability which could allow
a remote unauthenticated attacker to cause a crash of the HTTP service. |
SnapCenter versions 3.x and 4.x prior to 4.9 are susceptible to a
vulnerability which may allow an authenticated unprivileged user to gain
access as an admin user.
|
SnapCenter Plugin for VMware vSphere versions 4.6 prior to 4.9 are susceptible to a vulnerability which may allow authenticated unprivileged users to modify email and snapshot name settings within the VMware vSphere u...Show more |
SnapGathers versions prior to 4.9 are susceptible to a vulnerability
which could allow a local authenticated attacker to discover plaintext
domain user credentials |
3Fedoraproject GolangNetapp5Astra Trident Astra Trident AutosupportFedora+2 moreJun 17, 2026 Oct 11, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 A malicious HTTP/2 client which rapidly creates requests and immediately resets them can cause excessive server resource consumption. While the total number of requests is bounded by the http2.Server.MaxConcurrentStreams...Show more |
33Akka AmazonApache+30 more165.net 3scale Api Management PlatformAdvanced Cluster Management For Kubernetes+162 moreJun 17, 2026 Oct 10, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. |
4Fedoraproject LibtiffNetapp+1 more4Active Iq Unified Manager Enterprise LinuxFedora+1 moreJun 17, 2026 Oct 5, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 LibTIFF is vulnerable to an integer overflow. This flaw allows remote attackers to cause a denial of service (application crash) or possibly execute an arbitrary code via a crafted tiff image, which triggers a heap-based...Show more |
7Canonical DebianFedoraproject+4 more39Bootstrap Os Codeready Linux BuilderCodeready Linux Builder Eus+36 moreJun 17, 2026 Oct 3, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES env...Show more |
6Apple DebianFedoraproject+3 more14Active Iq Unified Manager Cloud Insights Acquisition UnitCloud Insights Storage Workload Security Agent+11 moreJun 17, 2026 Sep 21, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploit...Show more |
4Debian FedoraprojectIsc+1 more8Bind Debian LinuxFedora+5 moreJun 17, 2026 Sep 20, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw in the networking code handling DNS-over-TLS queries may cause `named` to terminate unexpectedly due to an assertion failure. This happens when internal data structures are incorrectly reused under significant DNS...Show more |
4Fedoraproject GnuNetapp+1 more27Codeready Linux Builder Eus Codeready Linux Builder Eus For Power Little EndianCodeready Linux Builder Eus For Power Little Endian Eus+24 moreJun 17, 2026 Sep 18, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in glibc. When the getaddrinfo function is called with the AF_UNSPEC address family and the system is configured with no-aaaa mode via /etc/resolv.conf, a DNS response via TCP larger than 2048 bytes can...Show more |
2Netapp Redhat16Build Of Quarkus Decision ManagerFuse+13 moreJun 17, 2026 Sep 14, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, where the loop never terminates. |
4Fedoraproject GnuNetapp+1 more16Active Iq Unified Manager Enterprise LinuxEnterprise Linux Eus+13 moreJun 17, 2026 Sep 12, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 A flaw has been identified in glibc. In an uncommon situation, the gaih_inet function may use memory that has been freed, resulting in an application crash. This issue is only exploitable when the getaddrinfo function is...Show more |
9Bandisoft BentleyDebian+6 more12Active Iq Unified Manager ChromeDebian Linux+9 moreJun 17, 2026 Sep 12, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical...Show more |
4Debian FedoraprojectNetapp+1 more5Debian Linux FedoraOntap Select Deploy Administration Utility+2 moreJun 17, 2026 Aug 31, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-6A952214-0E5E-4CCF-9D2A-90948FF643EC.html in a target virtual machine may be able t...Show more |