Netapp
netapp
2,510 CVEs • 373 products
Products (373)
Click to collapseToggle
Products (373)
Click to collapse
CVEs (2,510)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The Data Warehouse component in NetApp OnCommand Insight before 7.2.3 allows remote attackers to obtain administrative access by leveraging a default privileged account. |
7Debian FreebsdNetapp+4 more17Clustered Data Ontap Communications User Data RepositoryData Ontap+14 moreMay 13, 2026 Jan 30, 2017 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The MATCH_ASSOC function in NTP before version 4.2.8p9 and 4.3.x before 4.3.92 allows remote attackers to cause an out-of-bounds reference via an addpeer request with a large hmode value. |
8Canonical DebianFedoraproject+5 more10Clustered Data Ontap Debian LinuxFedora+7 moreMay 13, 2026 Jan 30, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 ntpd in NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to cause a denial of service (NULL pointer dereference) via a ntpdc reslist command. |
5Canonical FreebsdNetapp+2 more7Clustered Data Ontap FreebsdNtp+4 moreMay 13, 2026 Jan 30, 2017 N/A· v4 6.5 MEDIUM· v3 5.8 MEDIUM· v2 NTP before 4.2.8p6 and 4.3.x before 4.3.90, when configured in broadcast mode, allows man-in-the-middle attackers to conduct replay attacks by sniffing the network. |
3Debian NetappPhp3Clustered Data Ontap Debian LinuxPhpMay 13, 2026 Jan 24, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Off-by-one error in the phar_parse_pharfile function in ext/phar/phar.c in PHP before 5.6.30 and 7.0.x before 7.0.15 allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary...Show more |
4Debian IscNetapp+1 more12Bind Data Ontap EdgeDebian Linux+9 moreMay 6, 2026 Jan 12, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 named in ISC BIND 9.x before 9.9.9-P5, 9.10.x before 9.10.4-P5, and 9.11.x before 9.11.0-P2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed response to an RTYPE AN...Show more |
1Netapp 1Metrocluster Tiebreaker May 6, 2026 Jan 11, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 MetroCluster Tiebreaker for clustered Data ONTAP in versions before 1.2 discloses sensitive information in cleartext which may be viewed by an unauthenticated user. |
Clustered Data ONTAP versions 8.0, 8.3.1, and 8.3.2 contain a default privileged account which under certain conditions can be used for unauthorized information disclosure. |
2Netapp Php2Clustered Data Ontap PhpMay 6, 2026 Jan 11, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The SplObjectStorage unserialize implementation in ext/spl/spl_observer.c in PHP before 7.0.12 does not verify that a key is an object, which allows remote attackers to execute arbitrary code or cause a denial of service...Show more |
2Netapp Php2Clustered Data Ontap PhpMay 6, 2026 Jan 11, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Zend/zend_hash.c in PHP before 7.0.15 and 7.1.x before 7.1.1 mishandles certain cases that require large array allocations, which allows remote attackers to execute arbitrary code or cause a denial of service (integer ov...Show more |
2Netapp Ntp6Clustered Data Ontap Data Ontap Operating In 7 ModeNtp+3 moreMay 23, 2025 Jan 6, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An integer overflow can occur in NTP-dev.4.3.70 leading to an out-of-bounds memory copy operation when processing a specially crafted private mode packet. The crafted packet needs to have the correct message authenticati...Show more |
NetApp Snap Creator Framework before 4.3.1 discloses sensitive information which could be viewed by an unauthorized user. |
NetApp Plug-in for Symantec NetBackup prior to version 2.0.1 makes use of a non-unique server certificate, making it vulnerable to impersonation. |
7Canonical DebianFedoraproject+4 more18Cloud Backup Debian LinuxEnterprise Linux+15 moreApr 21, 2026 Nov 10, 2016 N/A· v4 7.0 HIGH· v3 7.2 HIGH· v2 Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature to write to a read-only memory mapping,...Show more |
4Debian IscNetapp+1 more11Bind Data Ontap EdgeDebian Linux+8 moreMay 6, 2026 Nov 2, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 named in ISC BIND 9.x before 9.9.9-P4, 9.10.x before 9.10.4-P4, and 9.11.x before 9.11.0-P1 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a DNAME record in the answer sectio...Show more |
2Ietf Netapp13Clustered Data Ontap Antivirus Connector Data Ontap EdgeHost Agent+10 moreMay 6, 2026 Sep 21, 2016 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 The TLS protocol 1.2 and earlier supports the rsa_fixed_dh, dss_fixed_dh, rsa_fixed_ecdh, and ecdsa_fixed_ecdh values for ClientCertificateType but does not directly document the ability to compute the master secret in c...Show more |
1Netapp 1Oncommand System Manager May 6, 2026 Sep 1, 2016 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 NetApp OnCommand System Manager 8.3.x before 8.3.2P5 allows remote authenticated users to cause a denial of service via unspecified vectors. |
NetApp Clustered Data ONTAP before 8.2.4P4 and 8.3.x before 8.3.2P2 allows remote authenticated users to obtain sensitive cluster and tenant information via unspecified vectors. |
8Apache CanonicalDebian+5 more38Cassandra Debian LinuxE Series Santricity Management Plug Ins+35 moreApr 22, 2026 Apr 21, 2016 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX. |
NetApp Clustered Data ONTAP 8.3.1 does not properly verify X.509 certificates from TLS servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. |