Netapp
netapp
2,510 CVEs • 373 products
Products (373)
Click to collapseToggle
Products (373)
Click to collapse
CVEs (2,510)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Netapp OracleVmware6Active Iq Unified Manager Brocade San NavigatorCloud Secure Agent+3 moreJun 17, 2026 May 12, 2022 N/A· v4 5.3 MEDIUM· v3 3.5 LOW· v2 In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servle...Show more |
3Debian IntelNetapp399Celeron J1750 Firmware Celeron J1800 FirmwareCeleron J1850 Firmware+396 moreJun 17, 2026 May 12, 2022 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Processor optimization removal or modification of security-critical code for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. |
Improper access control for some 3rd Generation Intel(R) Xeon(R) Scalable Processors before BIOS version MR7, may allow a local attacker to potentially enable information disclosure via local access. |
3Debian LinuxNetapp138300 Firmware 8700 FirmwareA400 Firmware+10 moreJun 17, 2026 May 12, 2022 N/A· v4 7.8 HIGH· v3 4.4 MEDIUM· v2 The Linux kernel before 5.17.2 mishandles seccomp permissions. The PTRACE_SEIZE code path allows attackers to bypass intended restrictions on setting the PT_SUSPEND_SECCOMP flag. |
4Debian FedoraprojectLibtiff+1 more4Debian Linux FedoraLibtiff+1 moreJun 17, 2026 May 11, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 LibTIFF master branch has an out-of-bounds read in LZWDecode in libtiff/tif_lzw.c:624, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is avai...Show more |
4Apple FedoraprojectLibtiff+1 more7Fedora Iphone OsLibtiff+4 moreJun 17, 2026 May 11, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 LibTIFF master branch has an out-of-bounds read in LZWDecode in libtiff/tif_lzw.c:619, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is avai...Show more |
5Apple DebianFedoraproject+2 more6Debian Linux FedoraHci Management Node+3 moreJun 17, 2026 May 8, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Heap-based Buffer Overflow in function cmdline_erase_chars in GitHub repository vim/vim prior to 8.2.4899. This vulnerabilities are capable of crashing software, modify memory, and possible remote execution |
3Netapp NettyOracle5Active Iq Unified Manager Financial Services Crime And Compliance Management StudioNetty+2 moreJun 17, 2026 May 6, 2022 N/A· v4 5.5 MEDIUM· v3 1.9 LOW· v2 Netty is an open-source, asynchronous event-driven network application framework. The package `io.netty:netty-codec-http` prior to version 4.1.77.Final contains an insufficient fix for CVE-2021-21290. When Netty's multip...Show more |
4Debian FedoraprojectNetapp+1 more4Active Iq Unified Manager Debian LinuxFedora+1 moreJun 17, 2026 May 6, 2022 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 Rsyslog is a rocket-fast system for log processing. Modules for TCP syslog reception have a potential heap buffer overflow when octet-counted framing is used. This can result in a segfault or some other malfunction. As o...Show more |
3Debian NetappOpenldap8Debian Linux H300s FirmwareH410c Firmware+5 moreJun 17, 2026 May 4, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In OpenLDAP 2.x before 2.5.12 and 2.6.x before 2.6.2, a SQL injection vulnerability exists in the experimental back-sql backend to slapd, via a SQL statement within an LDAP query. This can occur during an LDAP search ope...Show more |
2Netapp Openssl26A250 Firmware A700s FirmwareActive Iq Unified Manager+23 moreJun 17, 2026 May 3, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The OPENSSL_LH_flush() function, which empties a hash table, contains a bug that breaks reuse of the memory occuppied by the removed hash table entries. This function is used when decoding certificates or keys. If a long...Show more |
2Netapp Openssl26A250 Firmware A700s FirmwareActive Iq Unified Manager+23 moreJun 17, 2026 May 3, 2022 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The OpenSSL 3.0 implementation of the RC4-MD5 ciphersuite incorrectly uses the AAD data as the MAC key. This makes the MAC key trivially predictable. An attacker could exploit this issue by performing a man-in-the-middle...Show more |
2Netapp Openssl26A250 Firmware A700s FirmwareActive Iq Unified Manager+23 moreJun 17, 2026 May 3, 2022 N/A· v4 5.3 MEDIUM· v3 4.3 MEDIUM· v2 The function `OCSP_basic_verify` verifies the signer certificate on an OCSP response. In the case where the (non-default) flag OCSP_NOCHECKS is used then the response will be positive (meaning a successful verification)...Show more |
6Debian FedoraprojectNetapp+3 more35A250 Firmware A700s FirmwareActive Iq Unified Manager+32 moreJun 17, 2026 May 3, 2022 N/A· v4 7.3 HIGH· v3 10.0 HIGH· v2 The c_rehash script does not properly sanitise shell metacharacters to prevent command injection. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating sys...Show more |
5Debian FedoraprojectNetapp+2 more19Active Iq Unified Manager Clustered Data OntapClustered Data Ontap Antivirus Connector+16 moreJun 17, 2026 May 3, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In libxml2 before 2.9.14, several buffer handling functions in buf.c (xmlBuf*) and tree.c (xmlBuffer*) don't check for integer overflows. This can result in out-of-bounds memory writes. Exploitation requires a victim to...Show more |
3Fedoraproject LinuxNetapp8Fedora H300s FirmwareH410c Firmware+5 moreJun 17, 2026 May 2, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 An issue was discovered in the Linux kernel through 5.17.5. io_rw_init_file in fs/io_uring.c lacks initialization of kiocb->private. |
3Angularjs FedoraprojectNetapp3Angularjs FedoraOntap Select Deploy Administration UtilityJun 17, 2026 May 1, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The package angular after 1.7.0 are vulnerable to Regular Expression Denial of Service (ReDoS) by providing a custom locale rule that makes it possible to assign the parameter in posPre: ' '.repeat() of NUMBER_FORMATS.PA...Show more |
4Debian GoogleNetapp+1 more6Active Iq Unified Manager Debian LinuxFinancial Services Crime And Compliance Management Studio+3 moreJun 17, 2026 May 1, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal classes, which may lead to DoS attacks. |
4Debian LinuxNetapp+1 more11Debian Linux Enterprise LinuxH300e Firmware+8 moreJun 17, 2026 Apr 29, 2022 N/A· v4 7.1 HIGH· v3 3.6 LOW· v2 A vulnerability was found in the pfkey_register function in net/key/af_key.c in the Linux kernel. This flaw allows a local, unprivileged user to gain access to kernel memory, leading to a system crash or a leak of intern...Show more |
4Debian LinuxNetapp+1 more11Debian Linux Enterprise LinuxH300e Firmware+8 moreJun 17, 2026 Apr 29, 2022 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 A use-after-free flaw was found in the Linux kernel’s sound subsystem in the way a user triggers concurrent calls of PCM hw_params. The hw_free ioctls or similar race condition happens inside ALSA PCM for other ioctls. T...Show more |