← Back

Netapp

netapp

2,510 CVEs • 373 products

Products (373)

Click to collapse
Toggle
Snapcenter
snapcenter
Cloud Backup
cloud_backup
Solidfire
solidfire
Snapmanager
snapmanager
Storagegrid
storagegrid
Bootstrap Os
bootstrap_os
Data Ontap
data_ontap
Ontap Tools
ontap_tools
H300s
h300s
H500s
h500s
H700s
h700s
H410s
h410s
Ontap
ontap
Fas/aff Bios
fas/aff_bios
A250 Firmware
a250_firmware
Cloud Manager
cloud_manager
Snapdrive
snapdrive
Snapprotect
snapprotect
A400 Firmware
a400_firmware
Hci
hci
8300 Firmware
8300_firmware
8700 Firmware
8700_firmware

CVEs (2,510)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
5Debian
NetappNtp+2 more
13Clustered Data Ontap
Data OntapDebian Linux+10 more
May 13, 2026
Aug 7, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash) via crafted packets containing particular autokey operations. NOTE: This...Show more
The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash) via crafted packets containing particular autokey operations. NOTE: This vulnerability exists due to an incomplete fix for CVE-2014-9750.Show less
1Netapp
1Snapcenter Server
May 13, 2026
Aug 7, 2017
N/A· v4
8.1 HIGH· v3
6.5 MEDIUM· v2
NetApp SnapCenter Server 1.0 allows remote authenticated users to list and delete backups.
4Apache
DebianNetapp+1 more
11Clustered Data Ontap
Debian LinuxEnterprise Linux Desktop+8 more
May 13, 2026
Jul 27, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Apache HTTP Server, in all releases prior to 2.2.32 and 2.4.25, was liberal in the whitespace accepted from requests and sent in response lines and headers. Accepting these different behaviors represented a security conc...Show more
Apache HTTP Server, in all releases prior to 2.2.32 and 2.4.25, was liberal in the whitespace accepted from requests and sent in response lines and headers. Accepting these different behaviors represented a security concern when httpd participates in any chain of proxies or interacts with back-end application servers, either through mod_proxy or using conventional CGI mechanisms, and may result in request smuggling, response splitting and cache pollution.Show less
1Netapp
1Oncommand Api Services
May 13, 2026
Jul 25, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
NetApp OnCommand API Services before 1.2P3 logs the LDAP BIND password when a user attempts to log in using the REST API, which allows remote authenticated users to obtain sensitive password information via unspecified v...Show more
NetApp OnCommand API Services before 1.2P3 logs the LDAP BIND password when a user attempts to log in using the REST API, which allows remote authenticated users to obtain sensitive password information via unspecified vectors.Show less
5Debian
NetappNtp+2 more
13Clustered Data Ontap
Data OntapDebian Linux+10 more
May 13, 2026
Jul 24, 2017
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
The "pidfile" or "driftfile" directives in NTP ntpd 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77, when ntpd is configured to allow remote configuration, allows remote attackers with an IP address that is allowed to send...Show more
The "pidfile" or "driftfile" directives in NTP ntpd 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77, when ntpd is configured to allow remote configuration, allows remote attackers with an IP address that is allowed to send configuration requests, and with knowledge of the remote configuration password to write to arbitrary files via the :config command.Show less
1Netapp
1Clustered Data Ontap
May 13, 2026
Jul 17, 2017
N/A· v4
6.5 MEDIUM· v3
5.0 MEDIUM· v2
NetApp Clustered Data ONTAP before 8.3.2P11, 9.0 before P4, and 9.1 before P5 allow attackers to obtain sensitive password information by leveraging logging of passwords entered non-interactively on the command line.
6Apache
AppleDebian+3 more
15Debian Linux
Enterprise Linux DesktopEnterprise Linux Server+12 more
May 13, 2026
Jul 13, 2017
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
In Apache httpd before 2.2.34 and 2.4.x before 2.4.27, the value placeholder in [Proxy-]Authorization headers of type 'Digest' was not initialized or reset before or between successive key=value assignments by mod_auth_d...Show more
In Apache httpd before 2.2.34 and 2.4.x before 2.4.27, the value placeholder in [Proxy-]Authorization headers of type 'Digest' was not initialized or reset before or between successive key=value assignments by mod_auth_digest. Providing an initial key with no '=' assignment could reflect the stale value of uninitialized pool memory used by the prior request, leading to leakage of potentially confidential information, and a segfault in other cases resulting in denial of service.Show less
2Netapp
Php
2Clustered Data Ontap
Php
May 13, 2026
Jul 10, 2017
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
In PHP before 5.6.30 and 7.x before 7.0.15, the PHAR archive handler could be used by attackers supplying malicious archive files to crash the PHP interpreter or potentially disclose information due to a buffer over-read...Show more
In PHP before 5.6.30 and 7.x before 7.0.15, the PHAR archive handler could be used by attackers supplying malicious archive files to crash the PHP interpreter or potentially disclose information due to a buffer over-read in the phar_parse_pharfile function in ext/phar/phar.c.Show less
1Netapp
1Oncommand System Manager
May 13, 2026
Jul 3, 2017
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
NetApp OnCommand System Manager before 9.0 allows remote attackers to obtain sensitive credentials via vectors related to cluster peering setup.
1Netapp
1Altavault
May 13, 2026
Jul 3, 2017
N/A· v4
8.1 HIGH· v3
5.1 MEDIUM· v2
NetApp AltaVault 4.1 and earlier allows man-in-the-middle attackers to obtain sensitive information, gain privileges, or cause a denial of service via vectors related to the SMB protocol.
1Netapp
1Clustered Data Ontap
May 13, 2026
Jul 3, 2017
N/A· v4
7.5 HIGH· v3
6.8 MEDIUM· v2
NetApp Clustered Data ONTAP allows man-in-the-middle attackers to obtain sensitive information, gain privileges, or cause a denial of service by leveraging failure to enable SMB signing enforcement in its default state.
1Netapp
1Data Ontap
May 13, 2026
Jul 3, 2017
N/A· v4
7.5 HIGH· v3
6.8 MEDIUM· v2
NetApp Data ONTAP 8.1 and 8.2, when operating in 7-Mode, allows man-in-the-middle attackers to obtain sensitive information, gain privileges, or cause a denial of service via vectors related to the SMB protocol.
6Apache
AppleDebian+3 more
13Clustered Data Ontap
Debian LinuxEnterprise Linux Desktop+10 more
May 13, 2026
Jun 20, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The HTTP strict parsing changes added in Apache httpd 2.2.32 and 2.4.24 introduced a bug in token list parsing, which allows ap_find_token() to search past the end of its input string. By maliciously crafting a sequence...Show more
The HTTP strict parsing changes added in Apache httpd 2.2.32 and 2.4.24 introduced a bug in token list parsing, which allows ap_find_token() to search past the end of its input string. By maliciously crafting a sequence of request headers, an attacker may be able to cause a segmentation fault, or to force ap_find_token() to return an incorrect value.Show less
6Apache
AppleDebian+3 more
14Clustered Data Ontap
Debian LinuxEnterprise Linux Desktop+11 more
May 13, 2026
Jun 20, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, use of the ap_get_basic_auth_pw() by third-party modules outside of the authentication phase may lead to authentication requirements being bypassed.
1Netapp
1Oncommand Unified Manager Core Package
May 13, 2026
May 26, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
NetApp OnCommand Unified Manager Core Package 5.x before 5.2.2P1 might allow remote attackers to obtain sensitive information via vectors involving error messages.
1Netapp
1Oncommand Unified Manager Core Package
May 13, 2026
May 26, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
SQL injection vulnerability in NetApp OnCommand Unified Manager Core Package 5.x before 5.2.2P1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
10Apple
CanonicalDebian+7 more
24Active Iq Unified Manager
Database ServerDebian Linux+21 more
May 13, 2026
May 23, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The crc32_big function in crc32.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving big-endian CRC calculation.
9Apple
CanonicalDebian+6 more
39Active Iq Unified Manager
Cloud BackupDatabase Server+36 more
Jul 14, 2026
May 23, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
2Netapp
Php
3Clustered Data Ontap
PhpStorage Automation Store
May 13, 2026
May 21, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The i_zval_ptr_dtor function in Zend/zend_variables.h in PHP 7.1.5 allows attackers to cause a denial of service (memory consumption and application crash) or possibly have unspecified other impact by triggering crafted...Show more
The i_zval_ptr_dtor function in Zend/zend_variables.h in PHP 7.1.5 allows attackers to cause a denial of service (memory consumption and application crash) or possibly have unspecified other impact by triggering crafted operations on array data structures.Show less
3Debian
Dropbear Ssh ProjectNetapp
3Debian Linux
Dropbear SshH410c Firmware
May 13, 2026
May 19, 2017
N/A· v4
8.8 HIGH· v3
8.5 HIGH· v2
The server in Dropbear before 2017.75 might allow post-authentication root remote code execution because of a double free in cleanup of TCP listeners when the -a option is enabled.