Netapp
netapp
2,510 CVEs • 373 products
Products (373)
Click to collapseToggle
Products (373)
Click to collapse
CVEs (2,510)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Debian Libexpat ProjectNetapp+2 more8Active Iq Unified Manager Debian LinuxHci Baseboard Management Controller+5 moreJun 17, 2026 Jan 1, 2022 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 In Expat (aka libexpat) before 2.4.3, a left shift by 29 (or more) places in the storeAtts function in xmlparse.c can lead to realloc misbehavior (e.g., allocating too few bytes, or only freeing memory). |
3Debian GolangNetapp3Cloud Insights Telegraf Debian LinuxGoJun 17, 2026 Jan 1, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 net/http in Go before 1.16.12 and 1.17.x before 1.17.5 allows uncontrolled memory consumption in the header canonicalization cache via HTTP/2 requests. |
3Linux NetappOracle26Aff A400 Firmware All Flash Fabric Attached Storage 8300 FirmwareAll Flash Fabric Attached Storage 8700 Firmware+23 moreJun 17, 2026 Dec 25, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In the IPv6 implementation in the Linux kernel before 5.13.3, net/ipv6/output_core.c has an information leak because of certain use of a hash table which, although big, doesn't properly consider that IPv6-based attackers...Show more |
1Netapp 1Virtual Desktop Service Jun 17, 2026 Dec 23, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 NetApp Virtual Desktop Service (VDS) when used with an HTML5 gateway is susceptible to a vulnerability which when successfully exploited could allow an unauthenticated attacker to takeover a Remote Desktop Session. |
StorageGRID (formerly StorageGRID Webscale) versions 11.5 prior to 11.5.0.5 are susceptible to a vulnerability which may allow an administrative user to escalate their privileges and modify settings in SANtricity System...Show more |
4Debian FedoraprojectLinux+1 more11Debian Linux FedoraH300e Firmware+8 moreJun 17, 2026 Dec 23, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 In __f2fs_setxattr in fs/f2fs/xattr.c in the Linux kernel through 5.15.11, there is an out-of-bounds memory access when an inode has an invalid last xattr entry. |
5Debian FedoraprojectLinux+2 more12Debian Linux Enterprise LinuxFedora+9 moreJun 17, 2026 Dec 22, 2021 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 A use-after-free exists in drivers/tee/tee_shm.c in the TEE subsystem in the Linux kernel through 5.15.11. This occurs because of a race condition in tee_shm_get_from_id during an attempt to free a shared memory object. |
7Apache AppleDebian+4 more14Cloud Backup Communications Element ManagerCommunications Operations Monitor+11 moreJun 17, 2026 Dec 20, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache httpd team is not aware of an exploit for the vulnerabilty though it might...Show more |
5Apache DebianNetapp+2 more1166bk1602 0aa12 0tp0 Firmware 6bk1602 0aa22 0tp0 Firmware6bk1602 0aa32 0tp0 Firmware+113 moreJun 17, 2026 Dec 18, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data t...Show more |
4Netapp QosRedhat+1 more6Cloud Manager LogbackSatellite+3 moreJun 17, 2026 Dec 16, 2021 N/A· v4 6.6 MEDIUM· v3 8.5 HIGH· v2 In logback version 1.2.7 and prior versions, an attacker with the required privileges to edit configurations files could craft a malicious configuration allowing to execute arbitrary code loaded from LDAP servers. |
2Ksmbd Project Netapp9H300e Firmware H300s FirmwareH410c Firmware+6 moreJun 17, 2026 Dec 16, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The ksmbd server through 3.4.2, as used in the Linux kernel through 5.15.8, sometimes communicates in cleartext even though encryption has been enabled. This occurs because it sets the SMB2_GLOBAL_CAP_ENCRYPTION flag whe...Show more |
5Debian FedoraprojectGnu+2 more5Binutils Debian LinuxEnterprise Linux+2 moreJun 17, 2026 Dec 15, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 stab_xcoff_builtin_type in stabs.c in GNU Binutils through 2.37 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact, as demonstrated by an out-of-bounds wr...Show more |
3Netapp NodejsOpenssl16500f Firmware A250 FirmwareCloud Backup+13 moreJun 17, 2026 Dec 14, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Internally libssl in OpenSSL calls X509_verify_cert() on the client side to verify a certificate supplied by a server. That function may return a negative return value to indicate an internal error (for example out of me...Show more |
5Debian FedoraprojectLxml+2 more11Communications Cloud Native Core Binding Support Function Communications Cloud Native Core Network Exposure FunctionCommunications Cloud Native Core Policy+8 moreJun 17, 2026 Dec 13, 2021 N/A· v4 7.1 HIGH· v3 6.8 MEDIUM· v2 lxml is a library for processing XML and HTML in the Python language. Prior to version 4.6.5, the HTML Cleaner in lxml.html lets certain crafted script content pass through, as well as script content in SVG files embedde...Show more |
12Apache AppleBentley+9 more1436bk1602 0aa12 0tp0 Firmware 6bk1602 0aa22 0tp0 Firmware6bk1602 0aa32 0tp0 Firmware+140 moreJun 17, 2026 Dec 10, 2021 N/A· v4 10.0 CRITICAL· v3 9.3 HIGH· v2 Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other J...Show more |
5Debian NetappNetty+2 more18Banking Deposits And Lines Of Credit Servicing Banking Party ManagementBanking Platform+15 moreJun 17, 2026 Dec 9, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. Netty prior to version 4.1.71.Final skips control chars when they are...Show more |
2Ibm Netapp2Db2 Oncommand InsightJun 17, 2026 Dec 9, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. |
2Ibm Netapp2Db2 Oncommand InsightJun 17, 2026 Dec 9, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1, and 11.5 is vulnerable to an information disclosure as a result of a connected user having indirect read access to a table where they are not author...Show more |
2Ibm Netapp2Db2 Oncommand InsightJun 17, 2026 Dec 9, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local user to gain privileges due to allowing modification of columns of existing tasks. IBM X-Force ID: 210...Show more |
2Ibm Netapp2Db2 Oncommand InsightJun 17, 2026 Dec 9, 2021 N/A· v4 8.7 HIGH· v3 5.5 MEDIUM· v2 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a user with DBADM authority to access other databases and read or modify files. IBM X-Force ID: 199914. |