Netapp
netapp
2,510 CVEs • 373 products
Products (373)
Click to collapseToggle
Products (373)
Click to collapse
CVEs (2,510)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Netapp 1E Series Santricity Os Controller Jun 17, 2026 Jun 2, 2022 N/A· v4 4.4 MEDIUM· v3 2.1 LOW· v2 E-Series SANtricity OS Controller Software versions 11.40 through 11.70.2 store the LDAP BIND password in plaintext within a file accessible only to privileged users. |
2Linux Netapp6H300s Firmware H410c FirmwareH410s Firmware+3 moreJun 17, 2026 Jun 2, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A use-after-free flaw was found in the Linux kernel’s io_uring subsystem in the way a user sets up a ring with IORING_SETUP_IOPOLL with more than one task completing submissions on this ring. This flaw allows a local use...Show more |
4Debian LinuxNetapp+1 more8Debian Linux Enterprise LinuxH300s Firmware+5 moreJun 17, 2026 Jun 2, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Linux Kernel could allow a local attacker to execute arbitrary code on the system, caused by a concurrency use-after-free flaw in the bad_flp_intr function. By executing a specially-crafted program, an attacker could exp...Show more |
5Brocade DebianHaxx+2 more12Bootstrap Os Clustered Data OntapCurl+9 moreJun 17, 2026 May 26, 2022 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections without properly making sure that the connection was authenticated with the...Show more |
2Linux Netapp9H300e Firmware H300s FirmwareH410c Firmware+6 moreJun 17, 2026 May 26, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A use-after-free flaw was found in the Linux kernel’s pipes functionality in how a user performs manipulations with the pipe post_one_notification() after free_pipe_info() that is already called. This flaw allows a local...Show more |
2Debian Netapp3Debian Linux DpkgOntap Select Deploy Administration UtilityJun 17, 2026 May 26, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Dpkg::Source::Archive in dpkg, the Debian package management system, before version 1.21.8, 1.20.10, 1.19.8, 1.18.26 is prone to a directory traversal vulnerability. When extracting untrusted source packages in v2 and v3...Show more |
2Linux Netapp17Active Iq Unified Manager Bootstrap OsCloud Volumes Ontap Mediator+14 moreJun 17, 2026 May 25, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in the Linux Kernel from 4.18 to 4.19, an improper update of sock reference in TCP pacing can lead to memory/netns leak, which can be used by remote clients. |
2Netapp Redhat8Active Iq Unified Manager IntegrationJboss Enterprise Application Platform+5 moreJun 17, 2026 May 24, 2022 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 A flaw was found in Undertow. A potential security issue in flow control handling by the browser over http/2 may potentially cause overhead or a denial of service in the server. The highest threat from this vulnerability...Show more |
2Netapp Redhat8Active Iq Unified Manager FuseJboss Enterprise Application Platform+5 moreJun 17, 2026 May 24, 2022 N/A· v4 5.9 MEDIUM· v3 2.6 LOW· v2 A flaw was found in undertow. The HTTP2SourceChannel fails to write the final frame under some circumstances, resulting in a denial of service. The highest threat from this vulnerability is availability. This flaw affect...Show more |
2Netapp Yaml Project2Astra Trident YamlJun 17, 2026 May 19, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue in the Unmarshal function in Go-Yaml v3 causes the program to crash when attempting to deserialize invalid input. |
3Netapp OracleVmware3Active Iq Unified Manager Financial Services Crime And Compliance Management StudioSpring SecurityJun 17, 2026 May 19, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In spring security versions prior to 5.4.11+, 5.5.7+ , 5.6.4+ and older unsupported versions, RegexRequestMatcher can easily be misconfigured to be bypassed on some servlet containers. Applications using RegexRequestMatc...Show more |
3Netapp OracleVmware3Active Iq Unified Manager Financial Services Crime And Compliance Management StudioSpring SecurityJun 17, 2026 May 19, 2022 N/A· v4 5.3 MEDIUM· v3 4.3 MEDIUM· v2 Spring Security versions 5.5.x prior to 5.5.7, 5.6.x prior to 5.6.4, and earlier unsupported versions contain an integer overflow vulnerability. When using the BCrypt class with the maximum work factor (31), the encoder...Show more |
2Isc Netapp6Bind H300s FirmwareH410c Firmware+3 moreJun 17, 2026 May 19, 2022 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 On vulnerable configurations, the named daemon may, in some circumstances, terminate with an assertion failure. Vulnerable configurations are those that include a reference to http within the listen-on statements in thei...Show more |
3Debian LinuxNetapp10Debian Linux H300e FirmwareH300s Firmware+7 moreJun 17, 2026 May 18, 2022 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 A flaw in Linux Kernel found in nfcmrvl_nci_unregister_dev() in drivers/nfc/nfcmrvl/main.c can lead to use after free both read or write when non synchronized between cleanup routine and firmware download routine. |
4Canonical DebianLinux+1 more11Debian Linux H300e FirmwareH300s Firmware+8 moreJun 17, 2026 May 17, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Improper Update of Reference Count vulnerability in net/sched of Linux Kernel allows local attacker to cause privilege escalation to root. This issue affects: Linux Kernel versions prior to 5.18; version 4.14 and later v...Show more |
2Linux Netapp5H300s Firmware H410s FirmwareH500s Firmware+2 moreJun 17, 2026 May 17, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Integer Overflow or Wraparound vulnerability in io_uring of Linux Kernel allows local attacker to cause memory corruption and escalate privileges to root. This issue affects: Linux Kernel versions prior to 5.4.189; versi...Show more |
4Fedoraproject NetappPcre+1 more12Active Iq Unified Manager Enterprise LinuxFedora+9 moreJun 17, 2026 May 16, 2022 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects recursions in JIT-compiled regular expressions caused...Show more |
5Debian FedoraprojectNetapp+2 more13Active Iq Unified Manager Debian LinuxEnterprise Linux+10 moreJun 17, 2026 May 16, 2022 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regul...Show more |
3Debian LinuxNetapp10Debian Linux H300e FirmwareH300s Firmware+7 moreJun 17, 2026 May 16, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A use-after-free flaw was found in the Linux kernel’s Atheros wireless adapter driver in the way a user forces the ath9k_htc_wait_for_target function to fail with some input messages. This flaw allows a local user to cra...Show more |
3Netapp OracleVmware4Cloud Secure Agent Financial Services Crime And Compliance Management StudioOncommand Insight+1 moreJun 17, 2026 May 12, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user. |