Netapp
netapp
2,510 CVEs • 373 products
Products (373)
Click to collapseToggle
Products (373)
Click to collapse
CVEs (2,510)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Mozilla NetappOracle+1 more10Cloud Backup Communications Cloud Native Core Binding Support FunctionCommunications Cloud Native Core Network Repository Function+7 moreJun 17, 2026 Dec 8, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures. Applications using NSS for handling signatures encoded within CM...Show more |
2Linux Netapp10Cloud Backup H300e FirmwareH300s Firmware+7 moreNov 21, 2024 Dec 8, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 The BPF subsystem in the Linux kernel before 4.17 mishandles situations with a long jump over an instruction sequence where inner instructions require substantial expansions into multiple BPF instructions, leading to an...Show more |
2Ibm Netapp2Cognos Analytics Oncommand InsightJun 17, 2026 Dec 3, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading...Show more |
2Ibm Netapp2Cognos Analytics Oncommand InsightJun 17, 2026 Dec 3, 2021 N/A· v4 5.4 MEDIUM· v3 5.5 MEDIUM· v2 IBM Cognos Analytics 11.1.7 and 11.2.0 could allow an authenticated to view or edit a Jupyter notebook that they should not have access to. IBM X-Force ID: 206212. |
2Ibm Netapp2Cognos Analytics Oncommand InsightJun 17, 2026 Dec 3, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to cross-site request forgery (CSRF) in the My Inbox page which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the...Show more |
2Ibm Netapp2Cognos Analytics Oncommand InsightJun 17, 2026 Dec 3, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 IBM Cognos Analytics 11.1.7 and 11.2.0 could be vulnerable to client side vulnerabilties due to a web response specifying an incorrect content type. IBM X-Force ID: 201091 |
2Ibm Netapp2Cognos Analytics Oncommand InsightJun 17, 2026 Dec 3, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 IBM Cognos Analytics 11.1.7 and 11.2.0 could allow a low level user to reas of the application that privileged user should only be allowed to view. IBM X-Force ID: 201087. |
2Ibm Netapp2Cognos Analytics Oncommand InsightJun 17, 2026 Dec 3, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading...Show more |
2Ibm Netapp2Cognos Analytics Oncommand InsightJun 17, 2026 Dec 3, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 IBM Cognos Analytics 11.1.7 and 11.2.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 196339. |
4Debian NetappPhp+1 more4Clustered Data Ontap Debian LinuxPhp+1 moreJun 17, 2026 Nov 29, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In PHP versions 7.3.x below 7.3.33, 7.4.x below 7.4.26 and 8.0.x below 8.0.13, certain XML parsing functions, like simplexml_load_file(), URL-decode the filename passed to them. If that filename contains URL-encoded NUL...Show more |
5Debian FedoraprojectLinux+2 more15Cloud Backup Communications Cloud Native Core Binding Support FunctionCommunications Cloud Native Core Network Exposure Function+12 moreJun 17, 2026 Nov 17, 2021 N/A· v4 4.6 MEDIUM· v3 2.1 LOW· v2 In the Linux kernel through 5.15.2, mwifiex_usb_recv in drivers/net/wireless/marvell/mwifiex/usb.c allows an attacker (who can connect a crafted USB device) to cause a denial of service (skb_over_panic). |
4Debian FedoraprojectLinux+1 more11Cloud Backup Debian LinuxFedora+8 moreJun 17, 2026 Nov 17, 2021 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 In the Linux kernel through 5.15.2, hw_atl_utils_fw_rpc_wait in drivers/net/ethernet/aquantia/atlantic/hw_atl/hw_atl_utils.c allows an attacker (who can introduce a crafted device) to trigger an out-of-bounds write via a...Show more |
3Busybox FedoraprojectNetapp12Busybox Cloud BackupFedora+9 moreJun 17, 2026 Nov 15, 2021 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 An attacker-controlled pointer free in Busybox's hush applet leads to denial of service and possible code execution when processing a crafted shell command, due to the shell mishandling the &&& string. This may be used f...Show more |
3Busybox FedoraprojectNetapp12Busybox Cloud BackupFedora+9 moreJun 17, 2026 Nov 15, 2021 N/A· v4 5.5 MEDIUM· v3 1.9 LOW· v2 A NULL pointer dereference in Busybox's hush applet leads to denial of service when processing a crafted shell command, due to missing validation after a \x03 delimiter character. This may be used for DoS under very rare...Show more |
3Busybox FedoraprojectNetapp12Busybox Cloud BackupFedora+9 moreJun 17, 2026 Nov 15, 2021 N/A· v4 5.5 MEDIUM· v3 1.9 LOW· v2 An incorrect handling of a special element in Busybox's ash applet leads to denial of service when processing a crafted shell command, due to the shell mistaking specific characters for reserved characters. This may be u...Show more |
3Busybox FedoraprojectNetapp12Busybox Cloud BackupFedora+9 moreJun 17, 2026 Nov 15, 2021 N/A· v4 5.3 MEDIUM· v3 3.3 LOW· v2 An out-of-bounds heap read in Busybox's unlzma applet leads to information leak and denial of service when crafted LZMA-compressed input is decompressed. This can be triggered by any applet/format that |
3Busybox FedoraprojectNetapp12Busybox Cloud BackupFedora+9 moreJun 17, 2026 Nov 15, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A NULL pointer dereference in Busybox's man applet leads to denial of service when a section name is supplied but no page argument is given |
3Debian GmplibNetapp8Active Iq Unified Manager Debian LinuxGmp+5 moreJun 17, 2026 Nov 15, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 GNU Multiple Precision Arithmetic Library (GMP) through 6.2.1 has an mpz/inp_raw.c integer overflow and resultant buffer overflow via crafted input, leading to a segmentation fault on 32-bit platforms. |
3Fedoraproject NetappNpmjs3Fedora Next Generation Application Programming InterfaceNpmJun 17, 2026 Nov 13, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The npm ci command in npm 7.x and 8.x through 8.1.3 proceeds with an installation even if dependency information in package-lock.json differs from package.json. This behavior is inconsistent with the documentation, and m...Show more |
3Fedoraproject LinuxNetapp9Fedora H300e FirmwareH300s Firmware+6 moreJun 17, 2026 Nov 2, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in net/tipc/crypto.c in the Linux kernel before 5.14.16. The Transparent Inter-Process Communication (TIPC) functionality allows remote attackers to exploit insufficient validation of user-supplie...Show more |