Netapp
netapp
2,510 CVEs • 373 products
Products (373)
Click to collapseToggle
Products (373)
Click to collapse
CVEs (2,510)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Debian NetappNtp+2 more13Clustered Data Ontap Data OntapDebian Linux+10 moreMay 13, 2026 Aug 7, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash) via crafted packets containing particular autokey operations. NOTE: This...Show more |
NetApp SnapCenter Server 1.0 allows remote authenticated users to list and delete backups. |
4Apache DebianNetapp+1 more11Clustered Data Ontap Debian LinuxEnterprise Linux Desktop+8 moreMay 13, 2026 Jul 27, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Apache HTTP Server, in all releases prior to 2.2.32 and 2.4.25, was liberal in the whitespace accepted from requests and sent in response lines and headers. Accepting these different behaviors represented a security conc...Show more |
1Netapp 1Oncommand Api Services May 13, 2026 Jul 25, 2017 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 NetApp OnCommand API Services before 1.2P3 logs the LDAP BIND password when a user attempts to log in using the REST API, which allows remote authenticated users to obtain sensitive password information via unspecified v...Show more |
5Debian NetappNtp+2 more13Clustered Data Ontap Data OntapDebian Linux+10 moreMay 13, 2026 Jul 24, 2017 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 The "pidfile" or "driftfile" directives in NTP ntpd 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77, when ntpd is configured to allow remote configuration, allows remote attackers with an IP address that is allowed to send...Show more |
1Netapp 1Clustered Data Ontap May 13, 2026 Jul 17, 2017 N/A· v4 6.5 MEDIUM· v3 5.0 MEDIUM· v2 NetApp Clustered Data ONTAP before 8.3.2P11, 9.0 before P4, and 9.1 before P5 allow attackers to obtain sensitive password information by leveraging logging of passwords entered non-interactively on the command line. |
6Apache AppleDebian+3 more15Debian Linux Enterprise Linux DesktopEnterprise Linux Server+12 moreMay 13, 2026 Jul 13, 2017 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 In Apache httpd before 2.2.34 and 2.4.x before 2.4.27, the value placeholder in [Proxy-]Authorization headers of type 'Digest' was not initialized or reset before or between successive key=value assignments by mod_auth_d...Show more |
2Netapp Php2Clustered Data Ontap PhpMay 13, 2026 Jul 10, 2017 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 In PHP before 5.6.30 and 7.x before 7.0.15, the PHAR archive handler could be used by attackers supplying malicious archive files to crash the PHP interpreter or potentially disclose information due to a buffer over-read...Show more |
1Netapp 1Oncommand System Manager May 13, 2026 Jul 3, 2017 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 NetApp OnCommand System Manager before 9.0 allows remote attackers to obtain sensitive credentials via vectors related to cluster peering setup. |
NetApp AltaVault 4.1 and earlier allows man-in-the-middle attackers to obtain sensitive information, gain privileges, or cause a denial of service via vectors related to the SMB protocol. |
NetApp Clustered Data ONTAP allows man-in-the-middle attackers to obtain sensitive information, gain privileges, or cause a denial of service by leveraging failure to enable SMB signing enforcement in its default state. |
NetApp Data ONTAP 8.1 and 8.2, when operating in 7-Mode, allows man-in-the-middle attackers to obtain sensitive information, gain privileges, or cause a denial of service via vectors related to the SMB protocol. |
6Apache AppleDebian+3 more13Clustered Data Ontap Debian LinuxEnterprise Linux Desktop+10 moreMay 13, 2026 Jun 20, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The HTTP strict parsing changes added in Apache httpd 2.2.32 and 2.4.24 introduced a bug in token list parsing, which allows ap_find_token() to search past the end of its input string. By maliciously crafting a sequence...Show more |
6Apache AppleDebian+3 more14Clustered Data Ontap Debian LinuxEnterprise Linux Desktop+11 moreMay 13, 2026 Jun 20, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, use of the ap_get_basic_auth_pw() by third-party modules outside of the authentication phase may lead to authentication requirements being bypassed. |
1Netapp 1Oncommand Unified Manager Core Package May 13, 2026 May 26, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 NetApp OnCommand Unified Manager Core Package 5.x before 5.2.2P1 might allow remote attackers to obtain sensitive information via vectors involving error messages. |
1Netapp 1Oncommand Unified Manager Core Package May 13, 2026 May 26, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 SQL injection vulnerability in NetApp OnCommand Unified Manager Core Package 5.x before 5.2.2P1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. |
10Apple CanonicalDebian+7 more24Active Iq Unified Manager Database ServerDebian Linux+21 moreMay 13, 2026 May 23, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The crc32_big function in crc32.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving big-endian CRC calculation. |
9Apple CanonicalDebian+6 more39Active Iq Unified Manager Cloud BackupDatabase Server+36 moreJul 14, 2026 May 23, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic. |
2Netapp Php3Clustered Data Ontap PhpStorage Automation StoreMay 13, 2026 May 21, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The i_zval_ptr_dtor function in Zend/zend_variables.h in PHP 7.1.5 allows attackers to cause a denial of service (memory consumption and application crash) or possibly have unspecified other impact by triggering crafted...Show more |
3Debian Dropbear Ssh ProjectNetapp3Debian Linux Dropbear SshH410c FirmwareMay 13, 2026 May 19, 2017 N/A· v4 8.8 HIGH· v3 8.5 HIGH· v2 The server in Dropbear before 2017.75 might allow post-authentication root remote code execution because of a double free in cleanup of TCP listeners when the -a option is enabled. |