Home / Security / ONTAP CVE Index
ONTAP CVE Index
1669 CVEs referenced by NetApp ONTAP security advisories. CVSS detail is added automatically as NVD records are backfilled; KEV-flagged entries are marked.
Always verify. Severity and CVSS come from the NVD record; NetApp's advisory is authoritative for affected versions and fixes.
Showing 1669 of 1669
| CVE | Published | Severity | CVSS | Summary / Sources |
|---|---|---|---|---|
CVE-1999-0016 | — | — | — | NVD ↗ · NTAP-20170815-0001 |
CVE-2002-20001 | 2021-11-11 | HIGH | 7.5 | The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigge NVD ↗ · NTAP-20260227-0010 |
CVE-2003-0028 | — | — | — | NVD ↗ · NTAP-20150122-0002 |
CVE-2003-1418 | — | — | — | NVD ↗ · NTAP-20150209-0001 |
CVE-2004-1653 | — | — | — | NVD ↗ · NTAP-20191107-0001 |
CVE-2004-2131 | 2004-01-27 | — | — | Stack-based buffer overflow in ontape for IBM Informix Dynamic Server (IDS) 9.40.xC3 and earlier allows local users, with DSA privileges, to execute arbitrary c NVD ↗ · |
CVE-2004-2539 | 2004-12-31 | — | — | Unknown vulnerability in Network Appliance NetCache 5.2 and Data ONTAP 6.0 allows remote attackers to cause a denial of service (panic and reboot) and possibly NVD ↗ · |
CVE-2005-3327 | 2005-10-27 | — | — | Network Appliance Data ONTAP 7.0 and earlier allows iSCSI Initiators to bypass iSCSI authentication via a modified client that skips the Security (Start) mode, NVD ↗ · |
CVE-2006-3569 | 2006-07-13 | — | — | Unspecified vulnerability in NetApp Data ONTAP 7.0x through 7.0.4P8D9, 7.1x, 7.1.0.1x, and 7.2RC1, RC2, and RC3, as used in IBM N series Filers and other produc NVD ↗ · |
CVE-2008-0960 | 2008-06-10 | — | — | SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-SNMP; (3) eCos; (4) Juniper Session and R NVD ↗ · |
CVE-2008-3160 | 2008-07-14 | — | — | Multiple unspecified vulnerabilities in IBM Data ONTAP 7.1 before 7.1.3, as used by IBM System Storage N series Filer and IBM System Storage N series Gateway, h NVD ↗ · |
CVE-2008-3349 | 2008-07-28 | — | — | Multiple unspecified vulnerabilities in NetApp Data ONTAP, as used on NetApp and IBM eServer platforms, allow remote attackers to execute arbitrary commands, ca NVD ↗ · |
CVE-2009-5155 | — | — | — | NVD ↗ · NTAP-20190315-0002 |
CVE-2010-1871 | — | — | — | NVD ↗ · NTAP-20161017-0001 |
CVE-2010-3613 | — | — | — | NVD ↗ · NTAP-20141030-0002 |
CVE-2011-4461 | — | — | — | NVD ↗ · NTAP-20190307-0004 |
CVE-2012-1667 | — | — | — | NVD ↗ · NTAP-20141030-0003 |
CVE-2012-4244 | — | — | — | NVD ↗ · NTAP-20221209-0008 |
CVE-2012-5615 | — | — | — | NVD ↗ · NTAP-20141119-0001 |
CVE-2013-1620 | — | — | — | NVD ↗ · NTAP-20141028-0001 |
CVE-2013-1741 | — | — | — | NVD ↗ · NTAP-20141028-0001 |
CVE-2013-2566 | — | — | — | NVD ↗ · NTAP-20150122-0001 |
CVE-2013-5855 | — | — | — | NVD ↗ · NTAP-20141028-0001 |
CVE-2014-0076 | — | — | — | NVD ↗ · NTAP-20140609-0004 |
CVE-2014-0092 | — | — | — | NVD ↗ · NTAP-20141024-0001 |
CVE-2014-0160 | — | — | — | NVD ↗ · NTAP-20140410-0001 |
CVE-2014-0224 | — | — | — | NVD ↗ · NTAP-20141119-0001 |
CVE-2014-125087 | 2023-02-19 | MEDIUM | 5.5 | A vulnerability was found in java-xmlbuilder up to 1.1. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation NVD ↗ · NTAP-20240208-0009 |
CVE-2014-2479 | — | — | — | NVD ↗ · NTAP-20141028-0001 |
CVE-2014-2480 | — | — | — | NVD ↗ · NTAP-20141028-0001 |
CVE-2014-2481 | — | — | — | NVD ↗ · NTAP-20141028-0001 |
CVE-2014-2493 | — | — | — | NVD ↗ · NTAP-20141028-0001 |
CVE-2014-3470 | — | — | — | NVD ↗ · NTAP-20140609-0004 |
CVE-2014-3505 | — | — | — | NVD ↗ · NTAP-20141030-0001 |
CVE-2014-3506 | — | — | — | NVD ↗ · NTAP-20141030-0001 |
CVE-2014-3507 | — | — | — | NVD ↗ · NTAP-20141030-0001 |
CVE-2014-3508 | — | — | — | NVD ↗ · NTAP-20141030-0001 |
CVE-2014-3509 | — | — | — | NVD ↗ · NTAP-20141030-0001 |
CVE-2014-3510 | — | — | — | NVD ↗ · NTAP-20141030-0001 |
CVE-2014-3511 | — | — | — | NVD ↗ · NTAP-20141030-0001 |
CVE-2014-3512 | — | — | — | NVD ↗ · NTAP-20141030-0001 |
CVE-2014-3513 | — | — | — | NVD ↗ · NTAP-20141015-0002 |
CVE-2014-3566 | — | — | — | NVD ↗ · NTAP-20141015-0001 · NTAP-20150126-0001 |
CVE-2014-3567 | — | — | — | NVD ↗ · NTAP-20141015-0002 |
CVE-2014-3568 | — | — | — | NVD ↗ · NTAP-20141015-0002 |
CVE-2014-3569 | — | — | — | NVD ↗ · NTAP-20150417-0002 |
CVE-2014-4201 | — | — | — | NVD ↗ · NTAP-20141028-0001 |
CVE-2014-4202 | — | — | — | NVD ↗ · NTAP-20141028-0001 |
CVE-2014-4210 | — | — | — | NVD ↗ · NTAP-20141028-0001 |
CVE-2014-4211 | — | — | — | NVD ↗ · NTAP-20141028-0001 |
CVE-2014-4212 | — | — | — | NVD ↗ · NTAP-20141028-0001 |
CVE-2014-4217 | — | — | — | NVD ↗ · NTAP-20141028-0001 |
CVE-2014-4222 | — | — | — | NVD ↗ · NTAP-20141028-0001 |
CVE-2014-4241 | — | — | — | NVD ↗ · NTAP-20141028-0001 |
CVE-2014-4242 | — | — | — | NVD ↗ · NTAP-20141028-0001 |
CVE-2014-4249 | — | — | — | NVD ↗ · NTAP-20141028-0001 |
CVE-2014-4251 | — | — | — | NVD ↗ · NTAP-20141028-0001 |
CVE-2014-4253 | — | — | — | NVD ↗ · NTAP-20141028-0001 |
CVE-2014-4254 | — | — | — | NVD ↗ · NTAP-20141028-0001 |
CVE-2014-4255 | — | — | — | NVD ↗ · NTAP-20141028-0001 |
CVE-2014-4256 | — | — | — | NVD ↗ · NTAP-20141028-0001 |
CVE-2014-4257 | — | — | — | NVD ↗ · NTAP-20141028-0001 |
CVE-2014-4267 | — | — | — | NVD ↗ · NTAP-20141028-0001 |
CVE-2014-4274 | — | — | — | NVD ↗ · NTAP-20141119-0001 |
CVE-2014-4287 | — | — | — | NVD ↗ · NTAP-20141119-0001 |
CVE-2014-4288 | — | — | — | NVD ↗ · NTAP-20141023-0001 |
CVE-2014-4877 | — | — | — | NVD ↗ · NTAP-20150122-0003 |
CVE-2014-5139 | — | — | — | NVD ↗ · NTAP-20141030-0001 |
CVE-2014-6271 | — | — | — | NVD ↗ · NTAP-20140924-0001 |
CVE-2014-6277 | — | — | — | NVD ↗ · NTAP-20140924-0001 |
CVE-2014-6278 | — | — | — | NVD ↗ · NTAP-20140924-0001 |
CVE-2014-6456 | — | — | — | NVD ↗ · NTAP-20141023-0001 |
CVE-2014-6457 | — | — | — | NVD ↗ · NTAP-20141023-0001 |
CVE-2014-6458 | — | — | — | NVD ↗ · NTAP-20141023-0001 |
CVE-2014-6463 | — | — | — | NVD ↗ · NTAP-20141119-0001 |
CVE-2014-6464 | — | — | — | NVD ↗ · NTAP-20141119-0001 |
CVE-2014-6466 | — | — | — | NVD ↗ · NTAP-20141023-0001 |
CVE-2014-6468 | — | — | — | NVD ↗ · NTAP-20141023-0001 |
CVE-2014-6469 | — | — | — | NVD ↗ · NTAP-20141119-0001 |
CVE-2014-6474 | — | — | — | NVD ↗ · NTAP-20141119-0001 |
CVE-2014-6476 | — | — | — | NVD ↗ · NTAP-20141023-0001 |
CVE-2014-6478 | — | — | — | NVD ↗ · NTAP-20141119-0001 |
CVE-2014-6484 | — | — | — | NVD ↗ · NTAP-20141119-0001 |
CVE-2014-6485 | — | — | — | NVD ↗ · NTAP-20141023-0001 |
CVE-2014-6489 | — | — | — | NVD ↗ · NTAP-20141119-0001 |
CVE-2014-6491 | — | — | — | NVD ↗ · NTAP-20141119-0001 |
CVE-2014-6492 | — | — | — | NVD ↗ · NTAP-20141023-0001 |
CVE-2014-6493 | — | — | — | NVD ↗ · NTAP-20141023-0001 |
CVE-2014-6494 | — | — | — | NVD ↗ · NTAP-20141119-0001 |
CVE-2014-6495 | — | — | — | NVD ↗ · NTAP-20141119-0001 |
CVE-2014-6496 | — | — | — | NVD ↗ · NTAP-20141119-0001 |
CVE-2014-6500 | — | — | — | NVD ↗ · NTAP-20141119-0001 |
CVE-2014-6502 | — | — | — | NVD ↗ · NTAP-20141023-0001 |
CVE-2014-6503 | — | — | — | NVD ↗ · NTAP-20141023-0001 |
CVE-2014-6504 | — | — | — | NVD ↗ · NTAP-20141023-0001 |
CVE-2014-6505 | — | — | — | NVD ↗ · NTAP-20141119-0001 |
CVE-2014-6506 | — | — | — | NVD ↗ · NTAP-20141023-0001 |
CVE-2014-6507 | — | — | — | NVD ↗ · NTAP-20141119-0001 |
CVE-2014-6511 | — | — | — | NVD ↗ · NTAP-20141023-0001 |
CVE-2014-6512 | — | — | — | NVD ↗ · NTAP-20141023-0001 |
CVE-2014-6513 | — | — | — | NVD ↗ · NTAP-20141023-0001 |
CVE-2014-6515 | — | — | — | NVD ↗ · NTAP-20141023-0001 |
CVE-2014-6517 | — | — | — | NVD ↗ · NTAP-20141023-0001 |
CVE-2014-6519 | — | — | — | NVD ↗ · NTAP-20141023-0001 |
CVE-2014-6520 | — | — | — | NVD ↗ · NTAP-20141119-0001 |
CVE-2014-6527 | — | — | — | NVD ↗ · NTAP-20141023-0001 |
CVE-2014-6530 | — | — | — | NVD ↗ · NTAP-20141119-0001 |
CVE-2014-6531 | — | — | — | NVD ↗ · NTAP-20141023-0001 |
CVE-2014-6532 | — | — | — | NVD ↗ · NTAP-20141023-0001 |
CVE-2014-6549 | — | — | — | NVD ↗ · NTAP-20150126-0001 |
CVE-2014-6551 | — | — | — | NVD ↗ · NTAP-20141119-0001 |
CVE-2014-6555 | — | — | — | NVD ↗ · NTAP-20141119-0001 |
CVE-2014-6558 | — | — | — | NVD ↗ · NTAP-20141023-0001 |
CVE-2014-6559 | — | — | — | NVD ↗ · NTAP-20141119-0001 |
CVE-2014-6562 | — | — | — | NVD ↗ · NTAP-20141023-0001 |
CVE-2014-6564 | — | — | — | NVD ↗ · NTAP-20141119-0001 |
CVE-2014-6568 | — | — | — | NVD ↗ · NTAP-20150304-0001 |
CVE-2014-6585 | — | — | — | NVD ↗ · NTAP-20150126-0001 |
CVE-2014-6587 | — | — | — | NVD ↗ · NTAP-20150126-0001 |
CVE-2014-6591 | — | — | — | NVD ↗ · NTAP-20150126-0001 |
CVE-2014-6593 | — | — | — | NVD ↗ · NTAP-20150126-0001 |
CVE-2014-6601 | — | — | — | NVD ↗ · NTAP-20150126-0001 |
CVE-2014-7169 | — | — | — | NVD ↗ · NTAP-20140924-0001 |
CVE-2014-7186 | — | — | — | NVD ↗ · NTAP-20140924-0001 |
CVE-2014-7187 | — | — | — | NVD ↗ · NTAP-20140924-0001 |
CVE-2014-8176 | — | — | — | NVD ↗ · NTAP-20150616-0001 |
CVE-2015-0204 | — | — | — | NVD ↗ · NTAP-20150417-0001 |
CVE-2015-0207 | — | — | — | NVD ↗ · NTAP-20150323-0002 |
CVE-2015-0208 | — | — | — | NVD ↗ · NTAP-20150323-0002 |
CVE-2015-0209 | — | — | — | NVD ↗ · NTAP-20150323-0002 |
CVE-2015-0235 | — | — | — | NVD ↗ · NTAP-20150127-0001 |
CVE-2015-0285 | — | — | — | NVD ↗ · NTAP-20150323-0002 |
CVE-2015-0286 | — | — | — | NVD ↗ · NTAP-20150323-0002 |
CVE-2015-0287 | — | — | — | NVD ↗ · NTAP-20150323-0002 |
CVE-2015-0288 | — | — | — | NVD ↗ · NTAP-20150323-0002 |
CVE-2015-0289 | — | — | — | NVD ↗ · NTAP-20150323-0002 |
CVE-2015-0290 | — | — | — | NVD ↗ · NTAP-20150323-0002 |
CVE-2015-0291 | — | — | — | NVD ↗ · NTAP-20150323-0002 |
CVE-2015-0292 | — | — | — | NVD ↗ · NTAP-20150323-0002 |
CVE-2015-0293 | — | — | — | NVD ↗ · NTAP-20150323-0002 |
CVE-2015-0374 | — | — | — | NVD ↗ · NTAP-20150304-0001 |
CVE-2015-0381 | — | — | — | NVD ↗ · NTAP-20150304-0001 |
CVE-2015-0382 | — | — | — | NVD ↗ · NTAP-20150304-0001 |
CVE-2015-0383 | — | — | — | NVD ↗ · NTAP-20150126-0001 |
CVE-2015-0385 | — | — | — | NVD ↗ · NTAP-20150304-0001 |
CVE-2015-0391 | — | — | — | NVD ↗ · NTAP-20150304-0001 |
CVE-2015-0395 | — | — | — | NVD ↗ · NTAP-20150126-0001 |
CVE-2015-0400 | — | — | — | NVD ↗ · NTAP-20150126-0001 |
CVE-2015-0403 | — | — | — | NVD ↗ · NTAP-20150126-0001 |
CVE-2015-0405 | — | — | — | NVD ↗ · NTAP-20150417-0002 |
CVE-2015-0406 | — | — | — | NVD ↗ · NTAP-20150126-0001 |
CVE-2015-0407 | — | — | — | NVD ↗ · NTAP-20150126-0001 |
CVE-2015-0408 | — | — | — | NVD ↗ · NTAP-20150126-0001 |
CVE-2015-0409 | — | — | — | NVD ↗ · NTAP-20150304-0001 |
CVE-2015-0410 | — | — | — | NVD ↗ · NTAP-20150126-0001 |
CVE-2015-0411 | — | — | — | NVD ↗ · NTAP-20150304-0001 |
CVE-2015-0412 | — | — | — | NVD ↗ · NTAP-20150126-0001 |
CVE-2015-0413 | — | — | — | NVD ↗ · NTAP-20150126-0001 |
CVE-2015-0421 | — | — | — | NVD ↗ · NTAP-20150126-0001 |
CVE-2015-0423 | — | — | — | NVD ↗ · NTAP-20150417-0002 |
CVE-2015-0432 | — | — | — | NVD ↗ · NTAP-20150304-0001 |
CVE-2015-0433 | — | — | — | NVD ↗ · NTAP-20150417-0002 |
CVE-2015-0437 | — | — | — | NVD ↗ · NTAP-20150126-0001 |
CVE-2015-0438 | — | — | — | NVD ↗ · NTAP-20150417-0002 |
CVE-2015-0439 | — | — | — | NVD ↗ · NTAP-20150417-0002 |
CVE-2015-0441 | — | — | — | NVD ↗ · NTAP-20150417-0002 |
CVE-2015-0458 | — | — | — | NVD ↗ · NTAP-20150417-0001 |
CVE-2015-0459 | — | — | — | NVD ↗ · NTAP-20150417-0001 |
CVE-2015-0460 | — | — | — | NVD ↗ · NTAP-20150417-0001 |
CVE-2015-0469 | — | — | — | NVD ↗ · NTAP-20150417-0001 |
CVE-2015-0470 | — | — | — | NVD ↗ · NTAP-20150417-0001 |
CVE-2015-0477 | — | — | — | NVD ↗ · NTAP-20150417-0001 |
CVE-2015-0478 | — | — | — | NVD ↗ · NTAP-20150417-0001 |
CVE-2015-0480 | — | — | — | NVD ↗ · NTAP-20150417-0001 |
CVE-2015-0484 | — | — | — | NVD ↗ · NTAP-20150417-0001 |
CVE-2015-0486 | — | — | — | NVD ↗ · NTAP-20150417-0001 |
CVE-2015-0488 | — | — | — | NVD ↗ · NTAP-20150417-0001 |
CVE-2015-0491 | — | — | — | NVD ↗ · NTAP-20150417-0001 |
CVE-2015-0492 | — | — | — | NVD ↗ · NTAP-20150417-0001 |
CVE-2015-0498 | — | — | — | NVD ↗ · NTAP-20150417-0002 |
CVE-2015-0499 | — | — | — | NVD ↗ · NTAP-20150417-0002 |
CVE-2015-0500 | — | — | — | NVD ↗ · NTAP-20150417-0002 |
CVE-2015-0501 | — | — | — | NVD ↗ · NTAP-20150417-0002 |
CVE-2015-0503 | — | — | — | NVD ↗ · NTAP-20150417-0002 |
CVE-2015-0505 | — | — | — | NVD ↗ · NTAP-20150417-0002 |
CVE-2015-0506 | — | — | — | NVD ↗ · NTAP-20150417-0002 |
CVE-2015-0507 | — | — | — | NVD ↗ · NTAP-20150417-0002 |
CVE-2015-0508 | — | — | — | NVD ↗ · NTAP-20150417-0002 |
CVE-2015-0511 | — | — | — | NVD ↗ · NTAP-20150417-0002 |
CVE-2015-0973 | 2015-01-18 | HIGH | 8.8 | Buffer overflow in the png_read_IDAT_data function in pngrutil.c in libpng before 1.5.21 and 1.6.x before 1.6.16 allows context-dependent attackers to execute a NVD ↗ · NTAP-20240719-0005 |
CVE-2015-1787 | — | — | — | NVD ↗ · NTAP-20150323-0002 |
CVE-2015-1788 | — | — | — | NVD ↗ · NTAP-20150616-0001 |
CVE-2015-1789 | — | — | — | NVD ↗ · NTAP-20150616-0001 |
CVE-2015-1790 | — | — | — | NVD ↗ · NTAP-20150616-0001 |
CVE-2015-1791 | — | — | — | NVD ↗ · NTAP-20150616-0001 |
CVE-2015-1792 | — | — | — | NVD ↗ · NTAP-20150616-0001 |
CVE-2015-1793 | — | — | — | NVD ↗ · NTAP-20151030-0001 |
CVE-2015-1794 | — | — | — | NVD ↗ · NTAP-20151207-0001 |
CVE-2015-20107 | — | — | — | NVD ↗ · NTAP-20220616-0001 |
CVE-2015-2566 | — | — | — | NVD ↗ · NTAP-20150417-0002 |
CVE-2015-2567 | — | — | — | NVD ↗ · NTAP-20150417-0002 |
CVE-2015-2568 | — | — | — | NVD ↗ · NTAP-20150417-0002 |
CVE-2015-2571 | — | — | — | NVD ↗ · NTAP-20150417-0002 |
CVE-2015-2573 | — | — | — | NVD ↗ · NTAP-20150417-0002 |
CVE-2015-2575 | — | — | — | NVD ↗ · NTAP-20150417-0003 · NTAP-20150417-0003 |
CVE-2015-2582 | — | — | — | NVD ↗ · NTAP-20150716-0001 |
CVE-2015-2590 | — | — | — | NVD ↗ · NTAP-20150715-0001 |
CVE-2015-2596 | — | — | — | NVD ↗ · NTAP-20150715-0001 |
CVE-2015-2597 | — | — | — | NVD ↗ · NTAP-20150715-0001 |
CVE-2015-2601 | — | — | — | NVD ↗ · NTAP-20150715-0001 |
CVE-2015-2611 | — | — | — | NVD ↗ · NTAP-20150716-0001 |
CVE-2015-2613 | — | — | — | NVD ↗ · NTAP-20150715-0001 |
CVE-2015-2617 | — | — | — | NVD ↗ · NTAP-20150716-0001 |
CVE-2015-2619 | — | — | — | NVD ↗ · NTAP-20150715-0001 |
CVE-2015-2620 | — | — | — | NVD ↗ · NTAP-20150716-0001 |
CVE-2015-2621 | — | — | — | NVD ↗ · NTAP-20150715-0001 |
CVE-2015-2625 | — | — | — | NVD ↗ · NTAP-20150715-0001 |
CVE-2015-2627 | — | — | — | NVD ↗ · NTAP-20150715-0001 |
CVE-2015-2628 | — | — | — | NVD ↗ · NTAP-20150715-0001 |
CVE-2015-2632 | — | — | — | NVD ↗ · NTAP-20150715-0001 |
CVE-2015-2637 | — | — | — | NVD ↗ · NTAP-20150715-0001 |
CVE-2015-2638 | — | — | — | NVD ↗ · NTAP-20150715-0001 |
CVE-2015-2639 | — | — | — | NVD ↗ · NTAP-20150716-0001 |
CVE-2015-2641 | — | — | — | NVD ↗ · NTAP-20150716-0001 |
CVE-2015-2643 | — | — | — | NVD ↗ · NTAP-20150716-0001 |
CVE-2015-2648 | — | — | — | NVD ↗ · NTAP-20150716-0001 |
CVE-2015-2659 | — | — | — | NVD ↗ · NTAP-20150715-0001 |
CVE-2015-2661 | — | — | — | NVD ↗ · NTAP-20150716-0001 |
CVE-2015-2664 | — | — | — | NVD ↗ · NTAP-20150715-0001 |
CVE-2015-2808 | — | — | — | NVD ↗ · NTAP-20150122-0001 · NTAP-20150715-0001 |
CVE-2015-3193 | — | — | — | NVD ↗ · NTAP-20151207-0001 |
CVE-2015-3194 | — | — | — | NVD ↗ · NTAP-20151207-0001 · NTAP-20160421-0001 |
CVE-2015-3195 | — | — | — | NVD ↗ · NTAP-20151207-0001 |
CVE-2015-3196 | — | — | — | NVD ↗ · NTAP-20151207-0001 |
CVE-2015-3197 | — | — | — | NVD ↗ · NTAP-20160201-0001 |
CVE-2015-4000 | — | — | — | NVD ↗ · NTAP-20150619-0001 · NTAP-20150616-0001 +1 |
CVE-2015-4729 | — | — | — | NVD ↗ · NTAP-20150715-0001 |
CVE-2015-4730 | — | — | — | NVD ↗ · NTAP-20151030-0001 |
CVE-2015-4731 | — | — | — | NVD ↗ · NTAP-20150715-0001 |
CVE-2015-4732 | — | — | — | NVD ↗ · NTAP-20150715-0001 |
CVE-2015-4733 | — | — | — | NVD ↗ · NTAP-20150715-0001 |
CVE-2015-4734 | — | — | — | NVD ↗ · NTAP-20151028-0001 |
CVE-2015-4736 | — | — | — | NVD ↗ · NTAP-20150715-0001 |
CVE-2015-4737 | — | — | — | NVD ↗ · NTAP-20150716-0001 |
CVE-2015-4748 | — | — | — | NVD ↗ · NTAP-20150715-0001 |
CVE-2015-4749 | — | — | — | NVD ↗ · NTAP-20150715-0001 |
CVE-2015-4752 | — | — | — | NVD ↗ · NTAP-20150716-0001 |
CVE-2015-4756 | — | — | — | NVD ↗ · NTAP-20150716-0001 |
CVE-2015-4757 | — | — | — | NVD ↗ · NTAP-20150716-0001 |
CVE-2015-4760 | — | — | — | NVD ↗ · NTAP-20150715-0001 |
CVE-2015-4761 | — | — | — | NVD ↗ · NTAP-20150716-0001 |
CVE-2015-4766 | — | — | — | NVD ↗ · NTAP-20151030-0001 |
CVE-2015-4767 | — | — | — | NVD ↗ · NTAP-20150716-0001 |
CVE-2015-4769 | — | — | — | NVD ↗ · NTAP-20150716-0001 |
CVE-2015-4771 | — | — | — | NVD ↗ · NTAP-20150716-0001 |
CVE-2015-4772 | — | — | — | NVD ↗ · NTAP-20150716-0001 |
CVE-2015-4791 | — | — | — | NVD ↗ · NTAP-20151030-0001 |
CVE-2015-4792 | — | — | — | NVD ↗ · NTAP-20151030-0001 |
CVE-2015-4800 | — | — | — | NVD ↗ · NTAP-20151030-0001 |
CVE-2015-4802 | — | — | — | NVD ↗ · NTAP-20151030-0001 |
CVE-2015-4803 | — | — | — | NVD ↗ · NTAP-20151028-0001 |
CVE-2015-4805 | — | — | — | NVD ↗ · NTAP-20151028-0001 |
CVE-2015-4806 | — | — | — | NVD ↗ · NTAP-20151028-0001 |
CVE-2015-4807 | — | — | — | NVD ↗ · NTAP-20151030-0001 |
CVE-2015-4810 | — | — | — | NVD ↗ · NTAP-20151028-0001 |
CVE-2015-4815 | — | — | — | NVD ↗ · NTAP-20151030-0001 |
CVE-2015-4816 | — | — | — | NVD ↗ · NTAP-20151030-0001 |
CVE-2015-4819 | — | — | — | NVD ↗ · NTAP-20151030-0001 |
CVE-2015-4826 | — | — | — | NVD ↗ · NTAP-20151030-0001 |
CVE-2015-4830 | — | — | — | NVD ↗ · NTAP-20151030-0001 |
CVE-2015-4833 | — | — | — | NVD ↗ · NTAP-20151030-0001 |
CVE-2015-4835 | — | — | — | NVD ↗ · NTAP-20151028-0001 |
CVE-2015-4836 | — | — | — | NVD ↗ · NTAP-20151030-0001 |
CVE-2015-4840 | — | — | — | NVD ↗ · NTAP-20151028-0001 |
CVE-2015-4842 | — | — | — | NVD ↗ · NTAP-20151028-0001 |
CVE-2015-4843 | — | — | — | NVD ↗ · NTAP-20151028-0001 |
CVE-2015-4844 | — | — | — | NVD ↗ · NTAP-20151028-0001 |
CVE-2015-4852 | — | — | — | NVD ↗ · NTAP-20151123-0001 |
CVE-2015-4858 | — | — | — | NVD ↗ · NTAP-20151030-0001 |
CVE-2015-4860 | — | — | — | NVD ↗ · NTAP-20151028-0001 |
CVE-2015-4861 | — | — | — | NVD ↗ · NTAP-20151030-0001 |
CVE-2015-4862 | — | — | — | NVD ↗ · NTAP-20151030-0001 |
CVE-2015-4864 | — | — | — | NVD ↗ · NTAP-20151030-0001 |
CVE-2015-4866 | — | — | — | NVD ↗ · NTAP-20151030-0001 |
CVE-2015-4868 | — | — | — | NVD ↗ · NTAP-20151028-0001 |
CVE-2015-4870 | — | — | — | NVD ↗ · NTAP-20151030-0001 |
CVE-2015-4871 | — | — | — | NVD ↗ · NTAP-20151028-0001 |
CVE-2015-4872 | — | — | — | NVD ↗ · NTAP-20151028-0001 |
CVE-2015-4879 | — | — | — | NVD ↗ · NTAP-20151030-0001 |
CVE-2015-4881 | — | — | — | NVD ↗ · NTAP-20151028-0001 |
CVE-2015-4882 | — | — | — | NVD ↗ · NTAP-20151028-0001 |
CVE-2015-4883 | — | — | — | NVD ↗ · NTAP-20151028-0001 |
CVE-2015-4890 | — | — | — | NVD ↗ · NTAP-20151030-0001 |
CVE-2015-4893 | — | — | — | NVD ↗ · NTAP-20151028-0001 |
CVE-2015-4895 | — | — | — | NVD ↗ · NTAP-20151030-0001 |
CVE-2015-4901 | — | — | — | NVD ↗ · NTAP-20151028-0001 |
CVE-2015-4902 | — | — | — | NVD ↗ · NTAP-20151028-0001 |
CVE-2015-4903 | — | — | — | NVD ↗ · NTAP-20151028-0001 |
CVE-2015-4904 | — | — | — | NVD ↗ · NTAP-20151030-0001 |
CVE-2015-4905 | — | — | — | NVD ↗ · NTAP-20151030-0001 |
CVE-2015-4906 | — | — | — | NVD ↗ · NTAP-20151028-0001 |
CVE-2015-4908 | — | — | — | NVD ↗ · NTAP-20151028-0001 |
CVE-2015-4910 | — | — | — | NVD ↗ · NTAP-20151030-0001 |
CVE-2015-4911 | — | — | — | NVD ↗ · NTAP-20151028-0001 |
CVE-2015-4913 | — | — | — | NVD ↗ · NTAP-20151030-0001 |
CVE-2015-4916 | — | — | — | NVD ↗ · NTAP-20151028-0001 |
CVE-2015-5300 | — | — | — | NVD ↗ · NTAP-20171004-0001 |
CVE-2015-5352 | — | — | — | NVD ↗ · NTAP-20181023-0001 |
CVE-2015-5477 | — | — | — | NVD ↗ · NTAP-20160114-0001 |
CVE-2015-5600 | — | — | — | NVD ↗ · NTAP-20151106-0001 |
CVE-2015-6563 | — | — | — | NVD ↗ · NTAP-20180201-0002 |
CVE-2015-6564 | — | — | — | NVD ↗ · NTAP-20160330-0001 |
CVE-2015-6565 | — | — | — | NVD ↗ · NTAP-20160330-0001 |
CVE-2015-7547 | — | — | — | NVD ↗ · NTAP-20160217-0002 |
CVE-2015-7575 | — | — | — | NVD ↗ · NTAP-20160225-0001 · NTAP-20160121-0001 |
CVE-2015-7691 | — | — | — | NVD ↗ · NTAP-20171004-0001 |
CVE-2015-7692 | — | — | — | NVD ↗ · NTAP-20171004-0001 |
CVE-2015-7701 | — | — | — | NVD ↗ · NTAP-20171004-0001 |
CVE-2015-7702 | — | — | — | NVD ↗ · NTAP-20171004-0001 |
CVE-2015-7703 | — | — | — | NVD ↗ · NTAP-20171004-0001 |
CVE-2015-7704 | — | — | — | NVD ↗ · NTAP-20171004-0002 · NTAP-20171004-0001 |
CVE-2015-7705 | — | — | — | NVD ↗ · NTAP-20171004-0001 |
CVE-2015-7744 | — | — | — | NVD ↗ · NTAP-20160121-0002 |
CVE-2015-7746 | 2017-09-01 | CRITICAL | 9.8 | NetApp Data ONTAP before 8.2.4, when operating in 7-Mode, allows remote attackers to bypass authentication and (1) obtain sensitive information from or (2) modi NVD ↗ · NTAP-20151112-0001 |
CVE-2015-7848 | — | — | — | NVD ↗ · NTAP-20171004-0001 |
CVE-2015-7849 | — | — | — | NVD ↗ · NTAP-20171004-0001 |
CVE-2015-7850 | — | — | — | NVD ↗ · NTAP-20171004-0001 |
CVE-2015-7851 | — | — | — | NVD ↗ · NTAP-20171004-0001 |
CVE-2015-7852 | — | — | — | NVD ↗ · NTAP-20171004-0001 |
CVE-2015-7853 | — | — | — | NVD ↗ · NTAP-20171004-0001 |
CVE-2015-7854 | — | — | — | NVD ↗ · NTAP-20171004-0001 |
CVE-2015-7855 | — | — | — | NVD ↗ · NTAP-20171004-0001 |
CVE-2015-7871 | — | — | — | NVD ↗ · NTAP-20171004-0001 |
CVE-2015-7886 | 2016-01-18 | LOW | 3.7 | NetApp Data ONTAP before 8.2.4P1, when 7-Mode and HTTP access are enabled, allows remote attackers to obtain sensitive volume information via unspecified vector NVD ↗ · NTAP-20160114-0002 |
CVE-2015-7973 | — | — | — | NVD ↗ · NTAP-20171031-0001 |
CVE-2015-7974 | — | — | — | NVD ↗ · NTAP-20171031-0001 |
CVE-2015-7975 | — | — | — | NVD ↗ · NTAP-20171031-0001 |
CVE-2015-7976 | — | — | — | NVD ↗ · NTAP-20171031-0001 |
CVE-2015-7977 | — | — | — | NVD ↗ · NTAP-20171031-0001 |
CVE-2015-7978 | — | — | — | NVD ↗ · NTAP-20171031-0001 |
CVE-2015-7979 | — | — | — | NVD ↗ · NTAP-20171031-0001 |
CVE-2015-8000 | — | — | — | NVD ↗ · NTAP-20160317-0001 |
CVE-2015-8020 | 2017-01-11 | LOW | 3.7 | Clustered Data ONTAP versions 8.0, 8.3.1, and 8.3.2 contain a default privileged account which under certain conditions can be used for unauthorized information NVD ↗ · NTAP-20160802-0001 |
CVE-2015-8126 | — | — | — | NVD ↗ · NTAP-20160121-0001 |
CVE-2015-8138 | — | — | — | NVD ↗ · NTAP-20171004-0002 · NTAP-20171031-0001 |
CVE-2015-8158 | — | — | — | NVD ↗ · NTAP-20171031-0001 |
CVE-2015-8325 | — | — | — | NVD ↗ · NTAP-20180628-0001 |
CVE-2015-8461 | — | — | — | NVD ↗ · NTAP-20160317-0001 |
CVE-2015-8545 | — | — | — | NVD ↗ · NTAP-20151123-0001 |
CVE-2015-8704 | — | — | — | NVD ↗ · NTAP-20160322-0001 |
CVE-2015-8705 | — | — | — | NVD ↗ · NTAP-20160322-0001 |
CVE-2015-8960 | — | — | — | NVD ↗ · NTAP-20180626-0002 |
CVE-2016-0402 | — | — | — | NVD ↗ · NTAP-20160121-0001 |
CVE-2016-0448 | — | — | — | NVD ↗ · NTAP-20160121-0001 |
CVE-2016-0466 | — | — | — | NVD ↗ · NTAP-20160121-0001 |
CVE-2016-0475 | — | — | — | NVD ↗ · NTAP-20160121-0001 |
CVE-2016-0483 | — | — | — | NVD ↗ · NTAP-20160121-0001 |
CVE-2016-0494 | — | — | — | NVD ↗ · NTAP-20160121-0001 |
CVE-2016-0502 | — | — | — | NVD ↗ · NTAP-20160121-0002 |
CVE-2016-0503 | — | — | — | NVD ↗ · NTAP-20160121-0002 |
CVE-2016-0504 | — | — | — | NVD ↗ · NTAP-20160121-0002 |
CVE-2016-0505 | — | — | — | NVD ↗ · NTAP-20160121-0002 |
CVE-2016-0546 | — | — | — | NVD ↗ · NTAP-20160121-0002 |
CVE-2016-0594 | — | — | — | NVD ↗ · NTAP-20160121-0002 |
CVE-2016-0595 | — | — | — | NVD ↗ · NTAP-20160121-0002 |
CVE-2016-0596 | — | — | — | NVD ↗ · NTAP-20160121-0002 |
CVE-2016-0597 | — | — | — | NVD ↗ · NTAP-20160121-0002 |
CVE-2016-0598 | — | — | — | NVD ↗ · NTAP-20160121-0002 |
CVE-2016-0599 | — | — | — | NVD ↗ · NTAP-20160121-0002 |
CVE-2016-0600 | — | — | — | NVD ↗ · NTAP-20160121-0002 |
CVE-2016-0601 | — | — | — | NVD ↗ · NTAP-20160121-0002 |
CVE-2016-0603 | — | — | — | NVD ↗ · NTAP-20160217-0001 |
CVE-2016-0605 | — | — | — | NVD ↗ · NTAP-20160121-0002 |
CVE-2016-0606 | — | — | — | NVD ↗ · NTAP-20160121-0002 |
CVE-2016-0607 | — | — | — | NVD ↗ · NTAP-20160121-0002 |
CVE-2016-0608 | — | — | — | NVD ↗ · NTAP-20160121-0002 |
CVE-2016-0609 | — | — | — | NVD ↗ · NTAP-20160121-0002 |
CVE-2016-0610 | — | — | — | NVD ↗ · NTAP-20160121-0002 |
CVE-2016-0611 | — | — | — | NVD ↗ · NTAP-20160121-0002 |
CVE-2016-0616 | — | — | — | NVD ↗ · NTAP-20160121-0002 |
CVE-2016-0636 | — | — | — | NVD ↗ · NTAP-20160328-0001 |
CVE-2016-0639 | — | — | — | NVD ↗ · NTAP-20160421-0001 |
CVE-2016-0640 | — | — | — | NVD ↗ · NTAP-20160421-0001 |
CVE-2016-0641 | — | — | — | NVD ↗ · NTAP-20160421-0001 |
CVE-2016-0642 | — | — | — | NVD ↗ · NTAP-20160421-0001 |
CVE-2016-0643 | — | — | — | NVD ↗ · NTAP-20160421-0001 |
CVE-2016-0644 | — | — | — | NVD ↗ · NTAP-20160421-0001 |
CVE-2016-0646 | — | — | — | NVD ↗ · NTAP-20160421-0001 |
CVE-2016-0647 | — | — | — | NVD ↗ · NTAP-20160421-0001 |
CVE-2016-0648 | — | — | — | NVD ↗ · NTAP-20160421-0001 |
CVE-2016-0649 | — | — | — | NVD ↗ · NTAP-20160421-0001 |
CVE-2016-0650 | — | — | — | NVD ↗ · NTAP-20160421-0001 |
CVE-2016-0651 | — | — | — | NVD ↗ · NTAP-20160421-0001 |
CVE-2016-0652 | — | — | — | NVD ↗ · NTAP-20160421-0001 |
CVE-2016-0653 | — | — | — | NVD ↗ · NTAP-20160421-0001 |
CVE-2016-0654 | — | — | — | NVD ↗ · NTAP-20160421-0001 |
CVE-2016-0655 | — | — | — | NVD ↗ · NTAP-20160421-0001 |
CVE-2016-0656 | — | — | — | NVD ↗ · NTAP-20160421-0001 |
CVE-2016-0657 | — | — | — | NVD ↗ · NTAP-20160421-0001 |
CVE-2016-0658 | — | — | — | NVD ↗ · NTAP-20160421-0001 |
CVE-2016-0659 | — | — | — | NVD ↗ · NTAP-20160421-0001 |
CVE-2016-0661 | — | — | — | NVD ↗ · NTAP-20160421-0001 |
CVE-2016-0662 | — | — | — | NVD ↗ · NTAP-20160421-0001 |
CVE-2016-0663 | — | — | — | NVD ↗ · NTAP-20160421-0001 |
CVE-2016-0665 | — | — | — | NVD ↗ · NTAP-20160421-0001 |
CVE-2016-0666 | — | — | — | NVD ↗ · NTAP-20160421-0001 |
CVE-2016-0667 | — | — | — | NVD ↗ · NTAP-20160421-0001 |
CVE-2016-0668 | — | — | — | NVD ↗ · NTAP-20160421-0001 |
CVE-2016-0686 | — | — | — | NVD ↗ · NTAP-20160420-0001 |
CVE-2016-0687 | — | — | — | NVD ↗ · NTAP-20160420-0001 |
CVE-2016-0695 | — | — | — | NVD ↗ · NTAP-20160420-0001 |
CVE-2016-0701 | — | — | — | NVD ↗ · NTAP-20160201-0001 |
CVE-2016-0702 | — | — | — | NVD ↗ · NTAP-20160303-0001 |
CVE-2016-0703 | — | — | — | NVD ↗ · NTAP-20160303-0001 |
CVE-2016-0704 | — | — | — | NVD ↗ · NTAP-20160303-0001 |
CVE-2016-0705 | — | — | — | NVD ↗ · NTAP-20160303-0001 · NTAP-20160421-0001 |
CVE-2016-0728 | — | — | — | NVD ↗ · NTAP-20160211-0001 |
CVE-2016-0736 | — | — | — | NVD ↗ · NTAP-20180423-0001 |
CVE-2016-0777 | — | — | — | NVD ↗ · NTAP-20160126-0001 |
CVE-2016-0778 | — | — | — | NVD ↗ · NTAP-20160126-0001 |
CVE-2016-0797 | — | — | — | NVD ↗ · NTAP-20160303-0001 |
CVE-2016-0798 | — | — | — | NVD ↗ · NTAP-20160303-0001 |
CVE-2016-0799 | — | — | — | NVD ↗ · NTAP-20160303-0001 |
CVE-2016-0800 | — | — | — | NVD ↗ · NTAP-20160301-0001 |
CVE-2016-10009 | — | — | — | NVD ↗ · NTAP-20171130-0002 |
CVE-2016-10010 | — | — | — | NVD ↗ · NTAP-20171130-0002 |
CVE-2016-10011 | — | — | — | NVD ↗ · NTAP-20171130-0002 |
CVE-2016-10012 | — | — | — | NVD ↗ · NTAP-20171130-0002 |
CVE-2016-10158 | — | — | — | NVD ↗ · NTAP-20180112-0001 |
CVE-2016-10159 | — | — | — | NVD ↗ · NTAP-20180112-0001 |
CVE-2016-10160 | — | — | — | NVD ↗ · NTAP-20180112-0001 |
CVE-2016-10161 | — | — | — | NVD ↗ · NTAP-20180112-0001 |
CVE-2016-10165 | — | — | — | NVD ↗ · NTAP-20171019-0001 |
CVE-2016-10229 | 2017-04-04 | CRITICAL | 9.8 | udp.c in the Linux kernel before 4.5 allows remote attackers to execute arbitrary code via UDP traffic that triggers an unsafe second checksum calculation durin NVD ↗ · NTAP-20250103-0008 · NTAP-20250103-0008 |
CVE-2016-10397 | — | — | — | NVD ↗ · NTAP-20180112-0001 |
CVE-2016-10708 | — | — | — | NVD ↗ · NTAP-20180423-0003 |
CVE-2016-1285 | — | — | — | NVD ↗ · NTAP-20160322-0002 |
CVE-2016-1286 | — | — | — | NVD ↗ · NTAP-20160322-0002 |
CVE-2016-1547 | — | — | — | NVD ↗ · NTAP-20171004-0002 |
CVE-2016-1548 | — | — | — | NVD ↗ · NTAP-20171004-0002 |
CVE-2016-1549 | — | — | — | NVD ↗ · NTAP-20171004-0002 |
CVE-2016-1550 | — | — | — | NVD ↗ · NTAP-20171004-0002 |
CVE-2016-1551 | — | — | — | NVD ↗ · NTAP-20171004-0002 |
CVE-2016-1563 | 2016-04-07 | MEDIUM | 6.8 | NetApp Clustered Data ONTAP 8.3.1 does not properly verify X.509 certificates from TLS servers, which allows man-in-the-middle attackers to spoof servers and ob NVD ↗ · NTAP-20160310-0002 |
CVE-2016-1895 | 2017-09-01 | MEDIUM | 6.5 | NetApp Data ONTAP before 8.2.5 and 8.3.x before 8.3.2P12 allow remote authenticated users to cause a denial of service via vectors related to unsafe user input NVD ↗ · NTAP-20170831-0003 |
CVE-2016-1907 | — | — | — | NVD ↗ · NTAP-20160519-0001 |
CVE-2016-1908 | — | — | — | NVD ↗ · NTAP-20160519-0001 |
CVE-2016-2047 | — | — | — | NVD ↗ · NTAP-20160421-0001 |
CVE-2016-2088 | — | — | — | NVD ↗ · NTAP-20160322-0002 |
CVE-2016-2105 | — | — | — | NVD ↗ · NTAP-20160504-0001 · NTAP-20160721-0002 |
CVE-2016-2106 | — | — | — | NVD ↗ · NTAP-20160504-0001 |
CVE-2016-2107 | — | — | — | NVD ↗ · NTAP-20160504-0001 |
CVE-2016-2108 | — | — | — | NVD ↗ · NTAP-20160504-0001 |
CVE-2016-2109 | — | — | — | NVD ↗ · NTAP-20160504-0001 |
CVE-2016-2118 | — | — | — | NVD ↗ · NTAP-20160412-0001 |
CVE-2016-2161 | — | — | — | NVD ↗ · NTAP-20180423-0001 |
CVE-2016-2176 | — | — | — | NVD ↗ · NTAP-20160504-0001 |
CVE-2016-2177 | — | — | — | NVD ↗ · NTAP-20160928-0001 |
CVE-2016-2178 | — | — | — | NVD ↗ · NTAP-20160928-0001 |
CVE-2016-2179 | — | — | — | NVD ↗ · NTAP-20160928-0001 |
CVE-2016-2180 | — | — | — | NVD ↗ · NTAP-20160928-0001 |
CVE-2016-2181 | — | — | — | NVD ↗ · NTAP-20160928-0001 |
CVE-2016-2182 | — | — | — | NVD ↗ · NTAP-20160928-0001 |
CVE-2016-2183 | — | — | — | NVD ↗ · NTAP-20160915-0001 · NTAP-20160928-0001 +1 |
CVE-2016-2516 | — | — | — | NVD ↗ · NTAP-20171004-0002 |
CVE-2016-2517 | — | — | — | NVD ↗ · NTAP-20171004-0002 |
CVE-2016-2518 | — | — | — | NVD ↗ · NTAP-20171004-0002 |
CVE-2016-2519 | — | — | — | NVD ↗ · NTAP-20171004-0002 |
CVE-2016-2776 | — | — | — | NVD ↗ · NTAP-20160930-0001 |
CVE-2016-2842 | — | — | — | NVD ↗ · NTAP-20160321-0001 |
CVE-2016-2848 | — | — | — | NVD ↗ · NTAP-20180926-0005 · NTAP-20180926-0002 |
CVE-2016-3064 | 2016-09-01 | MEDIUM | 6.5 | NetApp Clustered Data ONTAP before 8.2.4P4 and 8.3.x before 8.3.2P2 allows remote authenticated users to obtain sensitive cluster and tenant information via uns NVD ↗ · NTAP-20160830-0002 |
CVE-2016-3115 | — | — | — | NVD ↗ · NTAP-20160519-0001 |
CVE-2016-3400 | 2017-07-03 | HIGH | 7.5 | NetApp Data ONTAP 8.1 and 8.2, when operating in 7-Mode, allows man-in-the-middle attackers to obtain sensitive information, gain privileges, or cause a denial NVD ↗ · NTAP-20160412-0001 |
CVE-2016-3422 | — | — | — | NVD ↗ · NTAP-20160420-0001 |
CVE-2016-3424 | — | — | — | NVD ↗ · NTAP-20160721-0002 |
CVE-2016-3425 | — | — | — | NVD ↗ · NTAP-20160420-0001 |
CVE-2016-3426 | — | — | — | NVD ↗ · NTAP-20160420-0001 |
CVE-2016-3427 | — | — | — | NVD ↗ · NTAP-20160420-0001 |
CVE-2016-3440 | — | — | — | NVD ↗ · NTAP-20160721-0002 |
CVE-2016-3443 | — | — | — | NVD ↗ · NTAP-20160420-0001 |
CVE-2016-3449 | — | — | — | NVD ↗ · NTAP-20160420-0001 |
CVE-2016-3452 | — | — | — | NVD ↗ · NTAP-20160721-0002 |
CVE-2016-3458 | — | — | — | NVD ↗ · NTAP-20160721-0001 |
CVE-2016-3459 | — | — | — | NVD ↗ · NTAP-20160721-0002 |
CVE-2016-3471 | — | — | — | NVD ↗ · NTAP-20160721-0002 |
CVE-2016-3477 | — | — | — | NVD ↗ · NTAP-20160721-0002 |
CVE-2016-3485 | — | — | — | NVD ↗ · NTAP-20160721-0001 |
CVE-2016-3486 | — | — | — | NVD ↗ · NTAP-20160721-0002 |
CVE-2016-3492 | — | — | — | NVD ↗ · NTAP-20161019-0002 |
CVE-2016-3495 | — | — | — | NVD ↗ · NTAP-20161019-0002 |
CVE-2016-3498 | — | — | — | NVD ↗ · NTAP-20160721-0001 |
CVE-2016-3500 | — | — | — | NVD ↗ · NTAP-20160721-0001 |
CVE-2016-3501 | — | — | — | NVD ↗ · NTAP-20160721-0002 |
CVE-2016-3503 | — | — | — | NVD ↗ · NTAP-20160721-0001 |
CVE-2016-3508 | — | — | — | NVD ↗ · NTAP-20160721-0001 |
CVE-2016-3511 | — | — | — | NVD ↗ · NTAP-20160721-0001 |
CVE-2016-3518 | — | — | — | NVD ↗ · NTAP-20160721-0002 |
CVE-2016-3521 | — | — | — | NVD ↗ · NTAP-20160721-0002 |
CVE-2016-3550 | — | — | — | NVD ↗ · NTAP-20160721-0001 |
CVE-2016-3552 | — | — | — | NVD ↗ · NTAP-20160721-0001 |
CVE-2016-3587 | — | — | — | NVD ↗ · NTAP-20160721-0001 |
CVE-2016-3588 | — | — | — | NVD ↗ · NTAP-20160721-0002 |
CVE-2016-3598 | — | — | — | NVD ↗ · NTAP-20160721-0001 |
CVE-2016-3606 | — | — | — | NVD ↗ · NTAP-20160721-0001 |
CVE-2016-3610 | — | — | — | NVD ↗ · NTAP-20160721-0001 |
CVE-2016-3614 | — | — | — | NVD ↗ · NTAP-20160721-0002 |
CVE-2016-3615 | — | — | — | NVD ↗ · NTAP-20160721-0002 |
CVE-2016-3997 | 2017-07-03 | HIGH | 7.5 | NetApp Clustered Data ONTAP allows man-in-the-middle attackers to obtain sensitive information, gain privileges, or cause a denial of service by leveraging fail NVD ↗ · NTAP-20160412-0001 |
CVE-2016-3998 | — | — | — | NVD ↗ · NTAP-20160412-0001 |
CVE-2016-4341 | 2017-02-07 | HIGH | 7.5 | NetApp Clustered Data ONTAP before 8.3.2P7 allows remote attackers to obtain SMB share information via unspecified vectors. NVD ↗ · NTAP-20161028-0001 |
CVE-2016-4953 | — | — | — | NVD ↗ · NTAP-20160722-0001 |
CVE-2016-4954 | — | — | — | NVD ↗ · NTAP-20160722-0001 |
CVE-2016-4955 | — | — | — | NVD ↗ · NTAP-20160722-0001 |
CVE-2016-4956 | — | — | — | NVD ↗ · NTAP-20160722-0001 |
CVE-2016-4957 | — | — | — | NVD ↗ · NTAP-20160722-0001 |
CVE-2016-5195 | — | — | — | NVD ↗ · NTAP-20161025-0001 |
CVE-2016-5374 | 2017-03-01 | HIGH | 8.8 | NetApp Data ONTAP 9.0 and 9.1 before 9.1P1 allows remote authenticated users that own SMB-hosted data to bypass intended sharing restrictions by leveraging impr NVD ↗ · NTAP-20170228-0002 |
CVE-2016-5399 | — | — | — | NVD ↗ · NTAP-20180112-0001 |
CVE-2016-5436 | — | — | — | NVD ↗ · NTAP-20160721-0002 |
CVE-2016-5437 | — | — | — | NVD ↗ · NTAP-20160721-0002 |
CVE-2016-5439 | — | — | — | NVD ↗ · NTAP-20160721-0002 |
CVE-2016-5440 | — | — | — | NVD ↗ · NTAP-20160721-0002 |
CVE-2016-5441 | — | — | — | NVD ↗ · NTAP-20160721-0002 |
CVE-2016-5442 | — | — | — | NVD ↗ · NTAP-20160721-0002 |
CVE-2016-5443 | — | — | — | NVD ↗ · NTAP-20160721-0002 |
CVE-2016-5444 | — | — | — | NVD ↗ · NTAP-20160721-0002 |
CVE-2016-5507 | — | — | — | NVD ↗ · NTAP-20161019-0002 |
CVE-2016-5541 | — | — | — | NVD ↗ · NTAP-20170119-0002 |
CVE-2016-5542 | — | — | — | NVD ↗ · NTAP-20161019-0001 |
CVE-2016-5546 | — | — | — | NVD ↗ · NTAP-20170119-0001 |
CVE-2016-5547 | — | — | — | NVD ↗ · NTAP-20170119-0001 |
CVE-2016-5548 | — | — | — | NVD ↗ · NTAP-20170119-0001 |
CVE-2016-5549 | — | — | — | NVD ↗ · NTAP-20170119-0001 |
CVE-2016-5552 | — | — | — | NVD ↗ · NTAP-20170119-0001 |
CVE-2016-5554 | — | — | — | NVD ↗ · NTAP-20161019-0001 |
CVE-2016-5556 | — | — | — | NVD ↗ · NTAP-20161019-0001 |
CVE-2016-5568 | — | — | — | NVD ↗ · NTAP-20161019-0001 |
CVE-2016-5573 | — | — | — | NVD ↗ · NTAP-20161019-0001 |
CVE-2016-5582 | — | — | — | NVD ↗ · NTAP-20161019-0001 |
CVE-2016-5584 | — | — | — | NVD ↗ · NTAP-20161019-0002 |
CVE-2016-5597 | — | — | — | NVD ↗ · NTAP-20161019-0001 |
CVE-2016-5609 | — | — | — | NVD ↗ · NTAP-20161019-0002 |
CVE-2016-5612 | — | — | — | NVD ↗ · NTAP-20161019-0002 |
CVE-2016-5616 | — | — | — | NVD ↗ · NTAP-20161019-0002 |
CVE-2016-5617 | — | — | — | NVD ↗ · NTAP-20161019-0002 |
CVE-2016-5624 | — | — | — | NVD ↗ · NTAP-20161019-0002 |
CVE-2016-5625 | — | — | — | NVD ↗ · NTAP-20161019-0002 |
CVE-2016-5626 | — | — | — | NVD ↗ · NTAP-20161019-0002 |
CVE-2016-5627 | — | — | — | NVD ↗ · NTAP-20161019-0002 |
CVE-2016-5628 | — | — | — | NVD ↗ · NTAP-20161019-0002 |
CVE-2016-5629 | — | — | — | NVD ↗ · NTAP-20161019-0002 |
CVE-2016-5630 | — | — | — | NVD ↗ · NTAP-20161019-0002 |
CVE-2016-5631 | — | — | — | NVD ↗ · NTAP-20161019-0002 |
CVE-2016-5632 | — | — | — | NVD ↗ · NTAP-20161019-0002 |
CVE-2016-5633 | — | — | — | NVD ↗ · NTAP-20161019-0002 |
CVE-2016-5634 | — | — | — | NVD ↗ · NTAP-20161019-0002 |
CVE-2016-5635 | — | — | — | NVD ↗ · NTAP-20161019-0002 |
CVE-2016-5873 | — | — | — | NVD ↗ · NTAP-20180112-0001 |
CVE-2016-6210 | — | — | — | NVD ↗ · NTAP-20190206-0001 |
CVE-2016-6302 | — | — | — | NVD ↗ · NTAP-20160928-0001 |
CVE-2016-6303 | — | — | — | NVD ↗ · NTAP-20160928-0001 |
CVE-2016-6304 | — | — | — | NVD ↗ · NTAP-20160928-0001 · NTAP-20161019-0002 |
CVE-2016-6305 | — | — | — | NVD ↗ · NTAP-20160928-0001 |
CVE-2016-6306 | — | — | — | NVD ↗ · NTAP-20160928-0001 |
CVE-2016-6307 | — | — | — | NVD ↗ · NTAP-20160928-0001 |
CVE-2016-6308 | — | — | — | NVD ↗ · NTAP-20160928-0001 |
CVE-2016-6495 | 2017-02-07 | MEDIUM | 5.9 | NetApp Data ONTAP before 8.2.4P5, when operating in 7-Mode, allows remote attackers to obtain information about the volumes configured for HTTP access. NVD ↗ · |
CVE-2016-6515: OpenSSH vulnerability | — | — | — | NVD ↗ · NTAP-20171130-0003 |
CVE-2016-6662 | — | — | — | NVD ↗ · NTAP-20161019-0002 |
CVE-2016-6667 | 2017-02-07 | CRITICAL | 9.8 | NetApp OnCommand Unified Manager for Clustered Data ONTAP 6.3 through 6.4P1 contain a default privileged account, which allows remote attackers to execute arbit NVD ↗ · NTAP-20161017-0002 |
CVE-2016-6820 | 2017-01-11 | HIGH | 7.5 | MetroCluster Tiebreaker for clustered Data ONTAP in versions before 1.2 discloses sensitive information in cleartext which may be viewed by an unauthenticated u NVD ↗ · NTAP-20160816-0001 |
CVE-2016-6904 | 2017-12-11 | HIGH | 8.1 | Versions of VASA Provider for Clustered Data ONTAP prior to 7.0P1 contain a web server that accepts plain text authentication. This could allow an unauthenticat NVD ↗ · NTAP-20171208-0002 |
CVE-2016-7055 | — | — | — | NVD ↗ · NTAP-20170127-0001 |
CVE-2016-7076 | — | — | — | NVD ↗ · NTAP-20181127-0002 |
CVE-2016-7426 | — | — | — | NVD ↗ · NTAP-20170310-0002 |
CVE-2016-7427 | — | — | — | NVD ↗ · NTAP-20170310-0002 |
CVE-2016-7428 | — | — | — | NVD ↗ · NTAP-20170310-0002 |
CVE-2016-7429 | — | — | — | NVD ↗ · NTAP-20170310-0002 |
CVE-2016-7431 | — | — | — | NVD ↗ · NTAP-20170310-0002 |
CVE-2016-7433 | — | — | — | NVD ↗ · NTAP-20170310-0002 |
CVE-2016-7434 | — | — | — | NVD ↗ · NTAP-20170310-0002 |
CVE-2016-7440 | — | — | — | NVD ↗ · NTAP-20161019-0002 |
CVE-2016-7478 | — | — | — | NVD ↗ · NTAP-20180112-0001 |
CVE-2016-7479 | — | — | — | NVD ↗ · NTAP-20180112-0001 |
CVE-2016-7480 | — | — | — | NVD ↗ · NTAP-20180112-0001 |
CVE-2016-8106 | — | — | — | NVD ↗ · NTAP-20190731-0001 |
CVE-2016-8283 | — | — | — | NVD ↗ · NTAP-20161019-0002 |
CVE-2016-8284 | — | — | — | NVD ↗ · NTAP-20161019-0002 |
CVE-2016-8286 | — | — | — | NVD ↗ · NTAP-20161019-0002 |
CVE-2016-8287 | — | — | — | NVD ↗ · NTAP-20161019-0002 |
CVE-2016-8288 | — | — | — | NVD ↗ · NTAP-20161019-0002 |
CVE-2016-8289 | — | — | — | NVD ↗ · NTAP-20161019-0002 |
CVE-2016-8290 | — | — | — | NVD ↗ · NTAP-20161019-0002 |
CVE-2016-8318 | — | — | — | NVD ↗ · NTAP-20170119-0002 |
CVE-2016-8327 | — | — | — | NVD ↗ · NTAP-20170119-0002 |
CVE-2016-8328 | — | — | — | NVD ↗ · NTAP-20170119-0001 |
CVE-2016-8610 | — | — | — | NVD ↗ · NTAP-20171130-0001 |
CVE-2016-8740 | — | — | — | NVD ↗ · NTAP-20180423-0001 |
CVE-2016-8743 | — | — | — | NVD ↗ · NTAP-20180423-0001 |
CVE-2016-8864 | — | — | — | NVD ↗ · NTAP-20180926-0005 |
CVE-2016-9131 | — | — | — | NVD ↗ · NTAP-20180926-0005 |
CVE-2016-9147 | — | — | — | NVD ↗ · NTAP-20180926-0005 |
CVE-2016-9310 | — | — | — | NVD ↗ · NTAP-20170310-0002 |
CVE-2016-9311 | — | — | — | NVD ↗ · NTAP-20170310-0002 |
CVE-2016-9312 | — | — | — | NVD ↗ · NTAP-20170310-0002 |
CVE-2016-9444 | — | — | — | NVD ↗ · NTAP-20180926-0005 |
CVE-2016-9778 | — | — | — | NVD ↗ · NTAP-20180926-0005 |
CVE-2016-9841 | — | — | — | NVD ↗ · NTAP-20171019-0001 |
CVE-2017-1000253 | 2017-10-05 | HIGH | 7.8 | Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (committed on April NVD ↗ · NTAP-20260522-0015 |
CVE-2017-1000364 | — | — | — | NVD ↗ · NTAP-20170808-0001 |
CVE-2017-1000365 | — | — | — | NVD ↗ · NTAP-20170808-0001 |
CVE-2017-1000366 | — | — | — | NVD ↗ · NTAP-20170808-0001 |
CVE-2017-1000367 | — | — | — | NVD ↗ · NTAP-20170803-0001 |
CVE-2017-1000368 | — | — | — | NVD ↗ · NTAP-20170803-0001 |
CVE-2017-1000405 | 2017-11-30 | HIGH | 7.0 | The Linux Kernel versions 2.6.38 through 4.14 have a problematic use of pmd_mkdirty() in the touch_pmd() function inside the THP implementation. touch_pmd() can NVD ↗ · NTAP-20260527-0014 |
CVE-2017-1000408 | — | — | — | NVD ↗ · NTAP-20190404-0003 |
CVE-2017-1000409 | — | — | — | NVD ↗ · NTAP-20190404-0003 |
CVE-2017-10053 | — | — | — | NVD ↗ · NTAP-20170720-0001 |
CVE-2017-10067 | — | — | — | NVD ↗ · NTAP-20170720-0001 |
CVE-2017-10074 | — | — | — | NVD ↗ · NTAP-20170720-0001 |
CVE-2017-10078 | — | — | — | NVD ↗ · NTAP-20170720-0001 |
CVE-2017-10081 | — | — | — | NVD ↗ · NTAP-20170720-0001 |
CVE-2017-10086 | — | — | — | NVD ↗ · NTAP-20170720-0001 |
CVE-2017-10087 | — | — | — | NVD ↗ · NTAP-20170720-0001 |
CVE-2017-10089 | — | — | — | NVD ↗ · NTAP-20170720-0001 |
CVE-2017-10090 | — | — | — | NVD ↗ · NTAP-20170720-0001 |
CVE-2017-10096 | — | — | — | NVD ↗ · NTAP-20170720-0001 |
CVE-2017-10101 | — | — | — | NVD ↗ · NTAP-20170720-0001 |
CVE-2017-10102 | — | — | — | NVD ↗ · NTAP-20170720-0001 |
CVE-2017-10104 | — | — | — | NVD ↗ · NTAP-20170720-0001 |
CVE-2017-10105 | — | — | — | NVD ↗ · NTAP-20170720-0001 |
CVE-2017-10107 | — | — | — | NVD ↗ · NTAP-20170720-0001 |
CVE-2017-10108 | — | — | — | NVD ↗ · NTAP-20170720-0001 |
CVE-2017-10109 | — | — | — | NVD ↗ · NTAP-20170720-0001 |
CVE-2017-10110 | — | — | — | NVD ↗ · NTAP-20170720-0001 |
CVE-2017-10111 | — | — | — | NVD ↗ · NTAP-20170720-0001 |
CVE-2017-10114 | — | — | — | NVD ↗ · NTAP-20170720-0001 |
CVE-2017-10115 | — | — | — | NVD ↗ · NTAP-20170720-0001 |
CVE-2017-10116 | — | — | — | NVD ↗ · NTAP-20170720-0001 |
CVE-2017-10117 | — | — | — | NVD ↗ · NTAP-20170720-0001 |
CVE-2017-10118 | — | — | — | NVD ↗ · NTAP-20170720-0001 |
CVE-2017-10121 | — | — | — | NVD ↗ · NTAP-20170720-0001 |
CVE-2017-10125 | — | — | — | NVD ↗ · NTAP-20170720-0001 |
CVE-2017-10135 | — | — | — | NVD ↗ · NTAP-20170720-0001 |
CVE-2017-10145 | — | — | — | NVD ↗ · NTAP-20170720-0001 |
CVE-2017-10176 | — | — | — | NVD ↗ · NTAP-20170720-0001 |
CVE-2017-10193 | — | — | — | NVD ↗ · NTAP-20170720-0001 |
CVE-2017-10198 | — | — | — | NVD ↗ · NTAP-20170720-0001 |
CVE-2017-10243 | — | — | — | NVD ↗ · NTAP-20170720-0001 |
CVE-2017-10274 | — | — | — | NVD ↗ · NTAP-20171019-0001 |
CVE-2017-10281 | — | — | — | NVD ↗ · NTAP-20171019-0001 |
CVE-2017-10285 | — | — | — | NVD ↗ · NTAP-20171019-0001 |
CVE-2017-10293 | — | — | — | NVD ↗ · NTAP-20171019-0001 |
CVE-2017-10295 | — | — | — | NVD ↗ · NTAP-20171019-0001 |
CVE-2017-10309 | — | — | — | NVD ↗ · NTAP-20171019-0001 |
CVE-2017-10341 | — | — | — | NVD ↗ · NTAP-20171019-0001 |
CVE-2017-10342 | — | — | — | NVD ↗ · NTAP-20171019-0001 |
CVE-2017-10345 | — | — | — | NVD ↗ · NTAP-20171019-0001 |
CVE-2017-10346 | — | — | — | NVD ↗ · NTAP-20171019-0001 |
CVE-2017-10347 | — | — | — | NVD ↗ · NTAP-20171019-0001 |
CVE-2017-10348 | — | — | — | NVD ↗ · NTAP-20171019-0001 |
CVE-2017-10349 | — | — | — | NVD ↗ · NTAP-20171019-0001 |
CVE-2017-10350 | — | — | — | NVD ↗ · NTAP-20171019-0001 |
CVE-2017-10355 | — | — | — | NVD ↗ · NTAP-20171019-0001 |
CVE-2017-10356 | — | — | — | NVD ↗ · NTAP-20171019-0001 |
CVE-2017-10357 | — | — | — | NVD ↗ · NTAP-20171019-0001 |
CVE-2017-10380 | — | — | — | NVD ↗ · NTAP-20171019-0001 |
CVE-2017-10386 | — | — | — | NVD ↗ · NTAP-20171019-0001 |
CVE-2017-10388 | — | — | — | NVD ↗ · NTAP-20171019-0001 |
CVE-2017-11142 | — | — | — | NVD ↗ · NTAP-20180112-0001 |
CVE-2017-11143 | — | — | — | NVD ↗ · NTAP-20180112-0001 |
CVE-2017-11144 | — | — | — | NVD ↗ · NTAP-20180112-0001 |
CVE-2017-11145 | — | — | — | NVD ↗ · NTAP-20180112-0001 |
CVE-2017-11147 | — | — | — | NVD ↗ · NTAP-20180112-0001 |
CVE-2017-11362 | — | — | — | NVD ↗ · NTAP-20180112-0001 |
CVE-2017-11628 | — | — | — | NVD ↗ · NTAP-20180112-0001 |
CVE-2017-12420 | 2017-08-18 | HIGH | 8.8 | Heap-based buffer overflow in the SMB implementation in NetApp Clustered Data ONTAP before 8.3.2P8 and 9.0 before P2 allows remote authenticated users to cause NVD ↗ · NTAP-20170814-0001 |
CVE-2017-12421 | 2017-09-01 | HIGH | 8.8 | NetApp Clustered Data ONTAP 8.3.x before 8.3.2P12 allows remote authenticated users to execute arbitrary code on the storage controller via unspecified vectors. NVD ↗ · NTAP-20170831-0002 |
CVE-2017-12423 | 2017-09-01 | HIGH | 7.7 | NetApp Clustered Data ONTAP 8.3.x before 8.3.2P12 allows remote authenticated users to read data on other Storage Virtual Machines (SVMs) via unspecified vector NVD ↗ · NTAP-20170831-0002 |
CVE-2017-12588 | 2017-08-06 | CRITICAL | 9.8 | The zmq3 input and output modules in rsyslog before 8.28.0 interpreted description fields as format strings, possibly allowing a format string attack with unspe NVD ↗ · NTAP-20241227-0009 |
CVE-2017-12859 | 2017-08-18 | MEDIUM | 5.9 | NetApp Data ONTAP before 8.2.5, when operating in 7-Mode in NFS environments, allows remote attackers to cause a denial of service via unspecified vectors. NVD ↗ · NTAP-20170815-0002 |
CVE-2017-12932 | — | — | — | NVD ↗ · NTAP-20180112-0001 |
CVE-2017-14053 | 2017-09-01 | HIGH | 7.5 | NetApp OnCommand Unified Manager for Clustered Data ONTAP before 7.2P1 does not set the secure flag for an unspecified cookie in an HTTPS session, which makes i NVD ↗ · NTAP-20170831-0001 |
CVE-2017-14583 | 2017-12-18 | MEDIUM | 6.5 | NetApp Clustered Data ONTAP versions 9.x prior to 9.1P10 and 9.2P2 are susceptible to a vulnerability which allows an attacker to cause a Denial of Service (DoS NVD ↗ · NTAP-20171215-0001 |
CVE-2017-15710 | — | — | — | NVD ↗ · NTAP-20180601-0004 |
CVE-2017-15715 | — | — | — | NVD ↗ · NTAP-20180601-0004 |
CVE-2017-15906 | — | — | — | NVD ↗ · NTAP-20180423-0004 |
CVE-2017-16642 | — | — | — | NVD ↗ · NTAP-20181123-0001 |
CVE-2017-18017 | 2018-01-03 | CRITICAL | 9.8 | The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11, and 4.9.x before 4.9.36, allows remote attackers to cause a deni NVD ↗ · NTAP-20250103-0010 |
CVE-2017-18258 | — | — | — | NVD ↗ · NTAP-20190719-0001 |
CVE-2017-18269 | — | — | — | NVD ↗ · NTAP-20190401-0001 |
CVE-2017-3135 | — | — | — | NVD ↗ · NTAP-20180926-0005 |
CVE-2017-3136 | — | — | — | NVD ↗ · NTAP-20180802-0002 |
CVE-2017-3137 | — | — | — | NVD ↗ · NTAP-20180802-0002 |
CVE-2017-3138 | — | — | — | NVD ↗ · NTAP-20180802-0002 |
CVE-2017-3140 | — | — | — | NVD ↗ · NTAP-20180926-0001 |
CVE-2017-3141 | — | — | — | NVD ↗ · NTAP-20180926-0001 |
CVE-2017-3142 | — | — | — | NVD ↗ · NTAP-20190830-0003 |
CVE-2017-3143 | — | — | — | NVD ↗ · NTAP-20190830-0003 |
CVE-2017-3145 | — | — | — | NVD ↗ · NTAP-20180117-0003 |
CVE-2017-3167 | — | — | — | NVD ↗ · NTAP-20180601-0002 |
CVE-2017-3169 | — | — | — | NVD ↗ · NTAP-20180601-0002 |
CVE-2017-3231 | — | — | — | NVD ↗ · NTAP-20170119-0001 |
CVE-2017-3238 | — | — | — | NVD ↗ · NTAP-20170119-0002 |
CVE-2017-3241 | — | — | — | NVD ↗ · NTAP-20170119-0001 |
CVE-2017-3243 | — | — | — | NVD ↗ · NTAP-20170119-0002 |
CVE-2017-3244 | — | — | — | NVD ↗ · NTAP-20170119-0002 |
CVE-2017-3251 | — | — | — | NVD ↗ · NTAP-20170119-0002 |
CVE-2017-3252 | — | — | — | NVD ↗ · NTAP-20170119-0001 |
CVE-2017-3253 | — | — | — | NVD ↗ · NTAP-20170119-0001 |
CVE-2017-3256 | — | — | — | NVD ↗ · NTAP-20170119-0002 |
CVE-2017-3257 | — | — | — | NVD ↗ · NTAP-20170119-0002 |
CVE-2017-3258 | — | — | — | NVD ↗ · NTAP-20170119-0002 |
CVE-2017-3259 | — | — | — | NVD ↗ · NTAP-20170119-0001 |
CVE-2017-3260 | — | — | — | NVD ↗ · NTAP-20170119-0001 |
CVE-2017-3261 | — | — | — | NVD ↗ · NTAP-20170119-0001 |
CVE-2017-3262 | — | — | — | NVD ↗ · NTAP-20170119-0001 |
CVE-2017-3265 | — | — | — | NVD ↗ · NTAP-20170119-0002 |
CVE-2017-3272 | — | — | — | NVD ↗ · NTAP-20170119-0001 |
CVE-2017-3273 | — | — | — | NVD ↗ · NTAP-20170119-0002 |
CVE-2017-3289 | — | — | — | NVD ↗ · NTAP-20170119-0001 |
CVE-2017-3291 | — | — | — | NVD ↗ · NTAP-20170119-0002 |
CVE-2017-3302 | — | — | — | NVD ↗ · NTAP-20170420-0002 |
CVE-2017-3305 | — | — | — | NVD ↗ · NTAP-20170420-0002 |
CVE-2017-3308 | — | — | — | NVD ↗ · NTAP-20170420-0002 |
CVE-2017-3309 | — | — | — | NVD ↗ · NTAP-20170420-0002 |
CVE-2017-3312 | — | — | — | NVD ↗ · NTAP-20170119-0002 |
CVE-2017-3313 | — | — | — | NVD ↗ · NTAP-20170119-0002 |
CVE-2017-3317 | — | — | — | NVD ↗ · NTAP-20170119-0002 |
CVE-2017-3318 | — | — | — | NVD ↗ · NTAP-20170119-0002 |
CVE-2017-3319 | — | — | — | NVD ↗ · NTAP-20170119-0002 |
CVE-2017-3320 | — | — | — | NVD ↗ · NTAP-20170119-0002 |
CVE-2017-3321 | — | — | — | NVD ↗ · NTAP-20170119-0002 |
CVE-2017-3322 | — | — | — | NVD ↗ · NTAP-20170119-0002 |
CVE-2017-3323 | — | — | — | NVD ↗ · NTAP-20170119-0002 |
CVE-2017-3329 | — | — | — | NVD ↗ · NTAP-20170420-0002 |
CVE-2017-3331 | — | — | — | NVD ↗ · NTAP-20170420-0002 |
CVE-2017-3450 | — | — | — | NVD ↗ · NTAP-20170420-0002 |
CVE-2017-3452 | — | — | — | NVD ↗ · NTAP-20170420-0002 |
CVE-2017-3453 | — | — | — | NVD ↗ · NTAP-20170420-0002 |
CVE-2017-3454 | — | — | — | NVD ↗ · NTAP-20170420-0002 |
CVE-2017-3455 | — | — | — | NVD ↗ · NTAP-20170420-0002 |
CVE-2017-3456 | — | — | — | NVD ↗ · NTAP-20170420-0002 |
CVE-2017-3457 | — | — | — | NVD ↗ · NTAP-20170420-0002 |
CVE-2017-3458 | — | — | — | NVD ↗ · NTAP-20170420-0002 |
CVE-2017-3459 | — | — | — | NVD ↗ · NTAP-20170420-0002 |
CVE-2017-3460 | — | — | — | NVD ↗ · NTAP-20170420-0002 |
CVE-2017-3461 | — | — | — | NVD ↗ · NTAP-20170420-0002 |
CVE-2017-3462 | — | — | — | NVD ↗ · NTAP-20170420-0002 |
CVE-2017-3463 | — | — | — | NVD ↗ · NTAP-20170420-0002 |
CVE-2017-3464 | — | — | — | NVD ↗ · NTAP-20170420-0002 |
CVE-2017-3465 | — | — | — | NVD ↗ · NTAP-20170420-0002 |
CVE-2017-3467 | — | — | — | NVD ↗ · NTAP-20170420-0002 |
CVE-2017-3468 | — | — | — | NVD ↗ · NTAP-20170420-0002 |
CVE-2017-3509 | — | — | — | NVD ↗ · NTAP-20170420-0001 |
CVE-2017-3511 | — | — | — | NVD ↗ · NTAP-20170420-0001 |
CVE-2017-3512 | — | — | — | NVD ↗ · NTAP-20170420-0001 |
CVE-2017-3514 | — | — | — | NVD ↗ · NTAP-20170420-0001 |
CVE-2017-3526 | — | — | — | NVD ↗ · NTAP-20170420-0001 |
CVE-2017-3533 | — | — | — | NVD ↗ · NTAP-20170420-0001 |
CVE-2017-3539 | — | — | — | NVD ↗ · NTAP-20170420-0001 |
CVE-2017-3544 | — | — | — | NVD ↗ · NTAP-20170420-0001 |
CVE-2017-3599 | — | — | — | NVD ↗ · NTAP-20170420-0002 |
CVE-2017-3600 | — | — | — | NVD ↗ · NTAP-20170420-0002 |
CVE-2017-3730 | — | — | — | NVD ↗ · NTAP-20170127-0001 |
CVE-2017-3731 | — | — | — | NVD ↗ · NTAP-20170127-0001 |
CVE-2017-3732 | — | — | — | NVD ↗ · NTAP-20170127-0001 |
CVE-2017-3735 | — | — | — | NVD ↗ · NTAP-20170927-0001 |
CVE-2017-3736 | — | — | — | NVD ↗ · NTAP-20171107-0002 |
CVE-2017-3737 | — | — | — | NVD ↗ · NTAP-20171208-0001 |
CVE-2017-3738 | — | — | — | NVD ↗ · NTAP-20171208-0001 |
CVE-2017-5130 | — | — | — | NVD ↗ · NTAP-20190719-0001 |
CVE-2017-5201 | 2017-11-10 | MEDIUM | 5.7 | NetApp Clustered Data ONTAP before 8.3.2P8 and 9.0 before P2 allow remote authenticated users to obtain sensitive cluster and tenant information via unspecified NVD ↗ · NTAP-20170809-0001 |
CVE-2017-5340 | — | — | — | NVD ↗ · NTAP-20180112-0001 |
CVE-2017-5988 | 2017-04-10 | HIGH | 7.5 | NetApp Clustered Data ONTAP 8.1 through 9.1P1, when NFS or SMB is enabled, allows remote attackers to cause a denial of service via unspecified vectors. NVD ↗ · NTAP-20170331-0001 |
CVE-2017-5995 | 2017-03-01 | HIGH | 7.5 | The NetApp ONTAP Select Deploy administration utility 2.0 through 2.2.1 might allow remote attackers to obtain sensitive information via unspecified vectors. NVD ↗ · NTAP-20170228-0001 |
CVE-2017-7272 | — | — | — | NVD ↗ · NTAP-20180112-0001 |
CVE-2017-7345 | 2017-04-10 | MEDIUM | 5.3 | NetApp OnCommand Performance Manager and OnCommand Unified Manager for Clustered Data ONTAP before 7.1P1 improperly bind the Java Management Extension Remote Me NVD ↗ · NTAP-20170331-0002 |
CVE-2017-7659 | — | — | — | NVD ↗ · NTAP-20180601-0002 |
CVE-2017-7668 | — | — | — | NVD ↗ · NTAP-20180601-0002 |
CVE-2017-7679 | — | — | — | NVD ↗ · NTAP-20180601-0002 |
CVE-2017-7890 | — | — | — | NVD ↗ · NTAP-20180112-0001 |
CVE-2017-7947 | 2017-07-17 | MEDIUM | 6.5 | NetApp Clustered Data ONTAP before 8.3.2P11, 9.0 before P4, and 9.1 before P5 allow attackers to obtain sensitive password information by leveraging logging of NVD ↗ · NTAP-20170630-0001 |
CVE-2017-8779 | — | — | — | NVD ↗ · NTAP-20180109-0001 |
CVE-2017-8923 | 2017-05-12 | CRITICAL | 9.8 | The zend_string_extend function in Zend/zend_string.h in PHP through 7.1.5 does not prevent changes to string objects that result in a negative length, which al NVD ↗ · NTAP-20241227-0007 |
CVE-2017-9119 | — | — | — | NVD ↗ · NTAP-20180112-0001 |
CVE-2017-9217 | 2017-05-24 | HIGH | 7.5 | systemd-resolved through 233 allows remote attackers to cause a denial of service (daemon crash) via a crafted DNS response with an empty question section. NVD ↗ · NTAP-20241213-0003 |
CVE-2018-0732 | — | — | — | NVD ↗ · NTAP-20181105-0001 |
CVE-2018-0733 | — | — | — | NVD ↗ · NTAP-20180330-0002 |
CVE-2018-0734 | — | — | — | NVD ↗ · NTAP-20181105-0002 |
CVE-2018-0735 | — | — | — | NVD ↗ · NTAP-20181105-0002 |
CVE-2018-0737 | — | — | — | NVD ↗ · NTAP-20180726-0003 |
CVE-2018-0739 | — | — | — | NVD ↗ · NTAP-20180330-0002 |
CVE-2018-1000001 | — | — | — | NVD ↗ · NTAP-20190404-0003 |
CVE-2018-1000656 | — | — | — | NVD ↗ · NTAP-20190221-0001 |
CVE-2018-11236 | — | — | — | NVD ↗ · NTAP-20190401-0001 |
CVE-2018-11237 | — | — | — | NVD ↗ · NTAP-20190401-0001 |
CVE-2018-12015 | — | — | — | NVD ↗ · NTAP-20180927-0001 |
CVE-2018-1283 | — | — | — | NVD ↗ · NTAP-20180601-0004 |
CVE-2018-1301 | — | — | — | NVD ↗ · NTAP-20180601-0004 |
CVE-2018-1302 | — | — | — | NVD ↗ · NTAP-20180601-0004 |
CVE-2018-1303 | — | — | — | NVD ↗ · NTAP-20180601-0004 |
CVE-2018-1312 | — | — | — | NVD ↗ · NTAP-20180601-0004 |
CVE-2018-14404 | — | — | — | NVD ↗ · NTAP-20190719-0002 |
CVE-2018-15473 | — | — | — | NVD ↗ · NTAP-20181101-0001 |
CVE-2018-15919 | — | — | — | NVD ↗ · NTAP-20181221-0001 |
CVE-2018-16890 | — | — | — | NVD ↗ · NTAP-20190315-0001 |
CVE-2018-18065 | — | — | — | NVD ↗ · NTAP-20181107-0001 |
CVE-2018-18066 | — | — | — | NVD ↗ · NTAP-20181107-0001 |
CVE-2018-19591 | — | — | — | NVD ↗ · NTAP-20190321-0003 |
CVE-2018-19931 | — | — | — | NVD ↗ · NTAP-20190221-0004 |
CVE-2018-19932 | — | — | — | NVD ↗ · NTAP-20190221-0004 |
CVE-2018-20002 | — | — | — | NVD ↗ · NTAP-20190221-0004 |
CVE-2018-20685 | — | — | — | NVD ↗ · NTAP-20190215-0001 |
CVE-2018-20796 | — | — | — | NVD ↗ · NTAP-20190315-0002 |
CVE-2018-20836 | — | — | — | NVD ↗ · NTAP-20190719-0003 |
CVE-2018-20843 | — | — | — | NVD ↗ · NTAP-20190703-0001 |
CVE-2018-25009 | — | — | — | NVD ↗ · NTAP-20211104-0004 |
CVE-2018-25010 | — | — | — | NVD ↗ · NTAP-20211112-0001 |
CVE-2018-25011 | — | — | — | NVD ↗ · NTAP-20211104-0004 |
CVE-2018-25012 | — | — | — | NVD ↗ · NTAP-20211112-0001 |
CVE-2018-25013 | — | — | — | NVD ↗ · NTAP-20211112-0001 |
CVE-2018-25014 | — | — | — | NVD ↗ · NTAP-20211104-0004 |
CVE-2018-25032 | — | — | — | NVD ↗ · NTAP-20220526-0009 |
CVE-2018-2579 | — | — | — | NVD ↗ · NTAP-20180117-0001 |
CVE-2018-2581 | — | — | — | NVD ↗ · NTAP-20180117-0001 |
CVE-2018-2582 | — | — | — | NVD ↗ · NTAP-20180117-0001 |
CVE-2018-2588 | — | — | — | NVD ↗ · NTAP-20180117-0001 |
CVE-2018-2599 | — | — | — | NVD ↗ · NTAP-20180117-0001 |
CVE-2018-2602 | — | — | — | NVD ↗ · NTAP-20180117-0001 |
CVE-2018-2603 | — | — | — | NVD ↗ · NTAP-20180117-0001 |
CVE-2018-2618 | — | — | — | NVD ↗ · NTAP-20180117-0001 |
CVE-2018-2627 | — | — | — | NVD ↗ · NTAP-20180117-0001 |
CVE-2018-2629 | — | — | — | NVD ↗ · NTAP-20180117-0001 |
CVE-2018-2633 | — | — | — | NVD ↗ · NTAP-20180117-0001 |
CVE-2018-2634 | — | — | — | NVD ↗ · NTAP-20180117-0001 |
CVE-2018-2637 | — | — | — | NVD ↗ · NTAP-20180117-0001 |
CVE-2018-2638 | — | — | — | NVD ↗ · NTAP-20180117-0001 |
CVE-2018-2639 | — | — | — | NVD ↗ · NTAP-20180117-0001 |
CVE-2018-2641 | — | — | — | NVD ↗ · NTAP-20180117-0001 |
CVE-2018-2657 | — | — | — | NVD ↗ · NTAP-20180117-0001 |
CVE-2018-2663 | — | — | — | NVD ↗ · NTAP-20180117-0001 |
CVE-2018-2675 | — | — | — | NVD ↗ · NTAP-20180117-0001 |
CVE-2018-2677 | — | — | — | NVD ↗ · NTAP-20180117-0001 |
CVE-2018-2678 | — | — | — | NVD ↗ · NTAP-20180117-0001 |
CVE-2018-2783 | — | — | — | NVD ↗ · NTAP-20180419-0001 |
CVE-2018-2790 | — | — | — | NVD ↗ · NTAP-20180419-0001 |
CVE-2018-2794 | — | — | — | NVD ↗ · NTAP-20180419-0001 |
CVE-2018-2795 | — | — | — | NVD ↗ · NTAP-20180419-0001 |
CVE-2018-2796 | — | — | — | NVD ↗ · NTAP-20180419-0001 |
CVE-2018-2797 | — | — | — | NVD ↗ · NTAP-20180419-0001 |
CVE-2018-2798 | — | — | — | NVD ↗ · NTAP-20180419-0001 |
CVE-2018-2799 | — | — | — | NVD ↗ · NTAP-20180419-0001 |
CVE-2018-2800 | — | — | — | NVD ↗ · NTAP-20180419-0001 |
CVE-2018-2811 | — | — | — | NVD ↗ · NTAP-20180419-0001 |
CVE-2018-2814 | — | — | — | NVD ↗ · NTAP-20180419-0001 |
CVE-2018-2815 | — | — | — | NVD ↗ · NTAP-20180419-0001 |
CVE-2018-2825 | — | — | — | NVD ↗ · NTAP-20180419-0001 |
CVE-2018-2826 | — | — | — | NVD ↗ · NTAP-20180419-0001 |
CVE-2018-2938 | — | — | — | NVD ↗ · NTAP-20180726-0001 |
CVE-2018-2940 | — | — | — | NVD ↗ · NTAP-20180726-0001 |
CVE-2018-2941 | — | — | — | NVD ↗ · NTAP-20180726-0001 |
CVE-2018-2942 | — | — | — | NVD ↗ · NTAP-20180726-0001 |
CVE-2018-2952 | — | — | — | NVD ↗ · NTAP-20180726-0001 |
CVE-2018-2964 | — | — | — | NVD ↗ · NTAP-20180726-0001 |
CVE-2018-2972 | — | — | — | NVD ↗ · NTAP-20180726-0001 |
CVE-2018-2973 | — | — | — | NVD ↗ · NTAP-20180726-0001 |
CVE-2018-3665 | — | — | — | NVD ↗ · NTAP-20181016-0001 |
CVE-2018-5390 | — | — | — | NVD ↗ · NTAP-20180815-0003 |
CVE-2018-5391 | — | — | — | NVD ↗ · NTAP-20181003-0002 |
CVE-2018-5490 | 2018-08-03 | HIGH | 8.8 | Read-Only export policy rules are not correctly enforced in Clustered Data ONTAP 8.3 Release Candidate versions and therefore may allow more than "read-only" ac NVD ↗ · NTAP-20150324-0001 |
CVE-2018-5496 | 2018-12-04 | MEDIUM | 4.4 | Data ONTAP operating in 7-Mode versions prior to 8.2.5P2 are susceptible to a vulnerability which discloses sensitive information to an unauthorized user. NVD ↗ · NTAP-20181204-0001 |
CVE-2018-5497 | 2019-01-24 | MEDIUM | 4.4 | Clustered Data ONTAP versions prior to 9.1P16, 9.3P10 and 9.4P5 are susceptible to a vulnerability which discloses sensitive information to an unauthorized user NVD ↗ · NTAP-20190109-0001 |
CVE-2018-5498 | 2019-02-01 | MEDIUM | 4.4 | Clustered Data ONTAP versions 9.0 through 9.4 are susceptible to a vulnerability which allows remote authenticated attackers to cause a Denial of Service (DoS) NVD ↗ · NTAP-20190115-0001 |
CVE-2018-5734 | — | — | — | NVD ↗ · NTAP-20180926-0005 |
CVE-2018-5736 | — | — | — | NVD ↗ · NTAP-20180926-0004 |
CVE-2018-5737 | — | — | — | NVD ↗ · NTAP-20180926-0004 |
CVE-2018-5738 | — | — | — | NVD ↗ · NTAP-20190830-0002 |
CVE-2018-5740 | — | — | — | NVD ↗ · NTAP-20180926-0003 |
CVE-2018-6485 | — | — | — | NVD ↗ · NTAP-20190404-0003 |
CVE-2018-6551 | — | — | — | NVD ↗ · NTAP-20190404-0003 |
CVE-2018-6922 | — | — | — | NVD ↗ · NTAP-20180815-0002 |
CVE-2018-7738 | 2018-03-07 | HIGH | 7.8 | In util-linux before 2.32-rc1, bash-completion/umount allows local users to gain privileges by embedding shell commands in a mountpoint name, which is mishandle NVD ↗ · NTAP-20241213-0002 |
CVE-2019-0220 | — | — | — | NVD ↗ · NTAP-20190625-0007 |
CVE-2019-10081 | — | — | — | NVD ↗ · NTAP-20190905-0003 |
CVE-2019-10082 | — | — | — | NVD ↗ · NTAP-20190905-0003 |
CVE-2019-10092 | — | — | — | NVD ↗ · NTAP-20190905-0003 |
CVE-2019-10097 | — | — | — | NVD ↗ · NTAP-20190905-0003 |
CVE-2019-10098 | — | — | — | NVD ↗ · NTAP-20190905-0003 |
CVE-2019-10241 | — | — | — | NVD ↗ · NTAP-20190509-0003 |
CVE-2019-10246 | — | — | — | NVD ↗ · NTAP-20190509-0003 |
CVE-2019-10247 | — | — | — | NVD ↗ · NTAP-20190509-0003 |
CVE-2019-1125 | — | — | — | NVD ↗ · NTAP-20190809-0002 |
CVE-2019-11477 | — | — | — | NVD ↗ · NTAP-20190625-0001 |
CVE-2019-11478 | — | — | — | NVD ↗ · NTAP-20190625-0001 |
CVE-2019-11479 | — | — | — | NVD ↗ · NTAP-20190625-0001 |
CVE-2019-11486 | — | — | — | NVD ↗ · NTAP-20190517-0005 |
CVE-2019-11487 | — | — | — | NVD ↗ · NTAP-20190517-0005 |
CVE-2019-11810 | — | — | — | NVD ↗ · NTAP-20190719-0003 |
CVE-2019-11811 | — | — | — | NVD ↗ · NTAP-20190719-0003 |
CVE-2019-11815 | — | — | — | NVD ↗ · NTAP-20190719-0003 |
CVE-2019-13012 | — | — | — | NVD ↗ · NTAP-20190806-0003 |
CVE-2019-13115 | — | — | — | NVD ↗ · NTAP-20190806-0002 |
CVE-2019-13117 | — | — | — | NVD ↗ · NTAP-20190806-0004 |
CVE-2019-13118 | — | — | — | NVD ↗ · NTAP-20190806-0004 |
CVE-2019-14870 | 2019-12-10 | MEDIUM | 5.4 | All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the S4U (MS-SFU) Kerberos delegation model includes NVD ↗ · NTAP-20230216-0008 |
CVE-2019-1547 | — | — | — | NVD ↗ · NTAP-20190919-0002 |
CVE-2019-1549 | — | — | — | NVD ↗ · NTAP-20190919-0002 |
CVE-2019-1551 | — | — | — | NVD ↗ · NTAP-20191210-0001 |
CVE-2019-1552 | — | — | — | NVD ↗ · NTAP-20190823-0006 |
CVE-2019-1559 | — | — | — | NVD ↗ · NTAP-20190301-0001 |
CVE-2019-1563 | — | — | — | NVD ↗ · NTAP-20190919-0002 |
CVE-2019-15874 | — | — | — | NVD ↗ · NTAP-20200511-0002 |
CVE-2019-15876 | — | — | — | NVD ↗ · NTAP-20200413-0001 |
CVE-2019-15877 | — | — | — | NVD ↗ · NTAP-20200413-0001 |
CVE-2019-15903 | — | — | — | NVD ↗ · NTAP-20190926-0004 |
CVE-2019-16168 | — | — | — | NVD ↗ · NTAP-20190926-0003 |
CVE-2019-17272 | 2019-11-21 | HIGH | 7.2 | All versions of ONTAP Select Deploy administration utility are susceptible to a vulnerability which when successfully exploited could allow an administrative us NVD ↗ · NTAP-20191121-0002 |
CVE-2019-17274 | — | — | — | NVD ↗ · NTAP-20200226-0001 |
CVE-2019-17498 | — | — | — | NVD ↗ · NTAP-20220909-0004 |
CVE-2019-17546 | 2019-10-14 | HIGH | 8.8 | tif_getimage.c in LibTIFF through 4.0.10, as used in GDAL through 3.0.1 and other products, has an integer overflow that potentially causes a heap-based buffer NVD ↗ · NTAP-20241220-0007 |
CVE-2019-18197 | — | — | — | NVD ↗ · NTAP-20191031-0004 |
CVE-2019-19317 | — | — | — | NVD ↗ · NTAP-20191223-0001 |
CVE-2019-19603 | — | — | — | NVD ↗ · NTAP-20191223-0001 |
CVE-2019-19645 | — | — | — | NVD ↗ · NTAP-20191223-0001 |
CVE-2019-19646 | — | — | — | NVD ↗ · NTAP-20191223-0001 |
CVE-2019-19956 | — | — | — | NVD ↗ · NTAP-20200114-0002 |
CVE-2019-20388 | — | — | — | NVD ↗ · NTAP-20200702-0005 |
CVE-2019-20907 | — | — | — | NVD ↗ · NTAP-20200731-0002 |
CVE-2019-25013 | — | — | — | NVD ↗ · NTAP-20210205-0004 |
CVE-2019-3822 | — | — | — | NVD ↗ · NTAP-20190315-0001 |
CVE-2019-3823 | — | — | — | NVD ↗ · NTAP-20190315-0001 |
CVE-2019-3829 | — | — | — | NVD ↗ · NTAP-20190619-0004 |
CVE-2019-3855 | — | — | — | NVD ↗ · NTAP-20190327-0005 |
CVE-2019-3856 | — | — | — | NVD ↗ · NTAP-20190327-0005 |
CVE-2019-3857 | — | — | — | NVD ↗ · NTAP-20190327-0005 |
CVE-2019-3858 | — | — | — | NVD ↗ · NTAP-20190327-0005 |
CVE-2019-3859 | — | — | — | NVD ↗ · NTAP-20190327-0005 |
CVE-2019-3860 | — | — | — | NVD ↗ · NTAP-20190327-0005 |
CVE-2019-3861 | — | — | — | NVD ↗ · NTAP-20190327-0005 |
CVE-2019-3862 | — | — | — | NVD ↗ · NTAP-20190327-0005 |
CVE-2019-3863 | — | — | — | NVD ↗ · NTAP-20190327-0005 |
CVE-2019-3882 | — | — | — | NVD ↗ · NTAP-20190517-0005 |
CVE-2019-3900 | — | — | — | NVD ↗ · NTAP-20190517-0005 |
CVE-2019-3901 | — | — | — | NVD ↗ · NTAP-20190517-0005 |
CVE-2019-5490 | — | — | — | NVD ↗ · NTAP-20190305-0001 |
CVE-2019-5491 | 2019-02-27 | HIGH | 7.5 | Clustered Data ONTAP versions prior to 9.1P15 and 9.3 prior to 9.3P7 are susceptible to a vulnerability which discloses sensitive information to an unauthentica NVD ↗ · NTAP-20190227-0001 |
CVE-2019-5493 | 2019-08-02 | HIGH | 7.5 | Data ONTAP operating in 7-Mode versions prior to 8.2.5P3 are susceptible to a vulnerability which discloses information to an unauthenticated attacker. A succes NVD ↗ · NTAP-20190801-0002 |
CVE-2019-5497 | — | — | — | NVD ↗ · NTAP-20190627-0001 |
CVE-2019-5501 | 2019-08-02 | HIGH | 7.5 | Data ONTAP operating in 7-Mode versions prior to 8.2.5P3 may disclose sensitive LDAP account information to unauthenticated remote attackers. NVD ↗ · NTAP-20190801-0001 |
CVE-2019-5502 | 2019-08-05 | CRITICAL | 9.1 | SMB in Data ONTAP operating in 7-Mode versions prior to 8.2.5P3 has weak cryptography which when exploited could lead to information disclosure or addition or m NVD ↗ · NTAP-20190802-0002 |
CVE-2019-5504 | 2019-09-24 | CRITICAL | 9.8 | ONTAP Select Deploy administration utility versions 2.12 & 2.12.1 ship with an HTTP service bound to the network allowing unauthenticated remote attackers to pe NVD ↗ · NTAP-20190923-0001 |
CVE-2019-5505 | 2019-09-24 | CRITICAL | 9.8 | ONTAP Select Deploy administration utility versions 2.2 through 2.12.1 transmit credentials in plaintext. NVD ↗ · NTAP-20190923-0002 |
CVE-2019-5506 | 2019-10-09 | MEDIUM | 5.9 | Clustered Data ONTAP versions 9.0 and higher do not enforce hostname verification under certain circumstances making them susceptible to impersonation via man-i NVD ↗ · NTAP-20191009-0003 |
CVE-2019-5508 | 2019-10-25 | HIGH | 7.5 | Clustered Data ONTAP versions 9.2 through 9.4 are susceptible to a vulnerability which allows an attacker to use l2ping to cause a Denial of Service (DoS). NVD ↗ · NTAP-20191024-0001 |
CVE-2019-5509 | 2019-11-21 | CRITICAL | 9.8 | ONTAP Select Deploy administration utility versions 2.11.2 through 2.12.2 are susceptible to a code injection vulnerability which when successfully exploited co NVD ↗ · NTAP-20191121-0001 |
CVE-2019-5608 | — | — | — | NVD ↗ · NTAP-20190910-0002 |
CVE-2019-5609 | — | — | — | NVD ↗ · NTAP-20190910-0002 |
CVE-2019-5610 | — | — | — | NVD ↗ · NTAP-20190910-0002 |
CVE-2019-5611 | — | — | — | NVD ↗ · NTAP-20190910-0002 |
CVE-2019-5612 | — | — | — | NVD ↗ · NTAP-20190910-0002 |
CVE-2019-5614 | — | — | — | NVD ↗ · NTAP-20200511-0002 |
CVE-2019-5953 | — | — | — | NVD ↗ · NTAP-20190509-0001 |
CVE-2019-6109 | — | — | — | NVD ↗ · NTAP-20190213-0001 |
CVE-2019-6110 | — | — | — | NVD ↗ · NTAP-20190213-0001 |
CVE-2019-6111 | — | — | — | NVD ↗ · NTAP-20190213-0001 |
CVE-2019-8460 | — | — | — | NVD ↗ · NTAP-20190905-0001 |
CVE-2019-8936 | — | — | — | NVD ↗ · NTAP-20190503-0001 |
CVE-2019-9169 | — | — | — | NVD ↗ · NTAP-20190315-0002 |
CVE-2020-0587 | — | — | — | NVD ↗ · NTAP-20201113-0001 |
CVE-2020-0588 | — | — | — | NVD ↗ · NTAP-20201113-0001 |
CVE-2020-0590 | — | — | — | NVD ↗ · NTAP-20201113-0001 |
CVE-2020-0591 | — | — | — | NVD ↗ · NTAP-20201113-0001 |
CVE-2020-0592 | — | — | — | NVD ↗ · NTAP-20201113-0001 |
CVE-2020-0593 | — | — | — | NVD ↗ · NTAP-20201113-0001 |
CVE-2020-11655 | — | — | — | NVD ↗ · NTAP-20200416-0001 |
CVE-2020-11656 | — | — | — | NVD ↗ · NTAP-20200416-0001 |
CVE-2020-11868 | — | — | — | NVD ↗ · NTAP-20200424-0002 |
CVE-2020-13434 | — | — | — | NVD ↗ · NTAP-20200528-0004 |
CVE-2020-13435 | — | — | — | NVD ↗ · NTAP-20200528-0004 |
CVE-2020-13817 | — | — | — | NVD ↗ · NTAP-20200625-0004 |
CVE-2020-13871 | — | — | — | NVD ↗ · NTAP-20200619-0002 |
CVE-2020-13954 | — | — | — | NVD ↗ · NTAP-20210513-0010 |
CVE-2020-14145 | — | — | — | NVD ↗ · NTAP-20200709-0004 |
CVE-2020-14155 | — | — | — | NVD ↗ · NTAP-20221028-0010 |
CVE-2020-14301 | — | — | — | NVD ↗ · NTAP-20210629-0007 |
CVE-2020-14372 | — | — | — | NVD ↗ · NTAP-20210416-0004 |
CVE-2020-15999 | 2020-11-03 | CRITICAL | 9.6 | Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pag NVD ↗ · NTAP-20240812-0001 |
CVE-2020-16166 | — | — | — | NVD ↗ · NTAP-20200814-0004 |
CVE-2020-16590 | — | — | — | NVD ↗ · NTAP-20210115-0003 |
CVE-2020-16591 | — | — | — | NVD ↗ · NTAP-20210115-0003 |
CVE-2020-16592 | — | — | — | NVD ↗ · NTAP-20210115-0003 |
CVE-2020-16593 | — | — | — | NVD ↗ · NTAP-20210122-0003 |
CVE-2020-16598 | — | — | — | NVD ↗ · NTAP-20210115-0003 |
CVE-2020-16599 | — | — | — | NVD ↗ · NTAP-20210122-0003 |
CVE-2020-19143 | — | — | — | NVD ↗ · NTAP-20211004-0005 |
CVE-2020-19144 | — | — | — | NVD ↗ · NTAP-20211004-0005 |
CVE-2020-1968 | — | — | — | NVD ↗ · NTAP-20200911-0004 |
CVE-2020-1971 | — | — | — | NVD ↗ · NTAP-20201218-0005 |
CVE-2020-21490 | 2023-08-22 | MEDIUM | 5.5 | An issue was discovered in GNU Binutils 2.34. It is a memory leak when process microblaze-dis.c. This one will consume memory on each insn disassembled. NVD ↗ · NTAP-20230929-0007 |
CVE-2020-24718 | — | — | — | NVD ↗ · NTAP-20201016-0002 |
CVE-2020-24977 | — | — | — | NVD ↗ · NTAP-20200924-0001 |
CVE-2020-25632 | — | — | — | NVD ↗ · NTAP-20220325-0001 |
CVE-2020-25647 | — | — | — | NVD ↗ · NTAP-20220325-0001 |
CVE-2020-27216 | — | — | — | NVD ↗ · NTAP-20201123-0005 |
CVE-2020-27618 | — | — | — | NVD ↗ · NTAP-20210401-0006 |
CVE-2020-27749 | — | — | — | NVD ↗ · NTAP-20220325-0001 |
CVE-2020-27779 | — | — | — | NVD ↗ · NTAP-20220325-0001 |
CVE-2020-35342 | 2023-08-22 | HIGH | 7.5 | GNU Binutils before 2.34 has an uninitialized-heap vulnerability in function tic4x_print_cond (file opcodes/tic4x-dis.c) which could allow attackers to make an NVD ↗ · NTAP-20231006-0009 |
CVE-2020-35448 | — | — | — | NVD ↗ · NTAP-20210129-0008 |
CVE-2020-35493 | — | — | — | NVD ↗ · NTAP-20210212-0007 |
CVE-2020-35494 | — | — | — | NVD ↗ · NTAP-20210212-0007 |
CVE-2020-35495 | — | — | — | NVD ↗ · NTAP-20210212-0007 |
CVE-2020-35496 | — | — | — | NVD ↗ · NTAP-20210212-0007 |
CVE-2020-35507 | — | — | — | NVD ↗ · NTAP-20210212-0007 |
CVE-2020-35521 | — | — | — | NVD ↗ · NTAP-20210521-0009 |
CVE-2020-35522 | — | — | — | NVD ↗ · NTAP-20210521-0009 |
CVE-2020-35523 | — | — | — | NVD ↗ · NTAP-20210521-0009 |
CVE-2020-35524 | — | — | — | NVD ↗ · NTAP-20210521-0009 |
CVE-2020-35525 | 2022-09-01 | HIGH | 7.5 | In SQlite 3.31.1, a potential null pointer derreference was found in the INTERSEC query processing. NVD ↗ · NTAP-20230706-0007 |
CVE-2020-35527 | — | — | — | NVD ↗ · NTAP-20221111-0007 |
CVE-2020-36328 | — | — | — | NVD ↗ · NTAP-20211112-0001 |
CVE-2020-36329 | — | — | — | NVD ↗ · NTAP-20211112-0001 |
CVE-2020-36330 | — | — | — | NVD ↗ · NTAP-20211104-0004 |
CVE-2020-36331 | — | — | — | NVD ↗ · NTAP-20211112-0001 |
CVE-2020-36332 | — | — | — | NVD ↗ · NTAP-20211104-0004 |
CVE-2020-36516 | — | — | — | NVD ↗ · NTAP-20220331-0003 |
CVE-2020-7071 | — | — | — | NVD ↗ · NTAP-20210312-0005 |
CVE-2020-7451 | — | — | — | NVD ↗ · NTAP-20200413-0001 |
CVE-2020-7452 | — | — | — | NVD ↗ · NTAP-20200413-0001 |
CVE-2020-7453 | — | — | — | NVD ↗ · NTAP-20200413-0001 |
CVE-2020-7456 | — | — | — | NVD ↗ · NTAP-20200625-0005 |
CVE-2020-7461 | — | — | — | NVD ↗ · NTAP-20201016-0002 |
CVE-2020-7462 | — | — | — | NVD ↗ · NTAP-20201016-0002 |
CVE-2020-7463 | — | — | — | NVD ↗ · NTAP-20201016-0002 |
CVE-2020-7464 | — | — | — | NVD ↗ · NTAP-20201016-0002 |
CVE-2020-7467 | — | — | — | NVD ↗ · NTAP-20201016-0002 |
CVE-2020-7468 | — | — | — | NVD ↗ · NTAP-20201016-0002 |
CVE-2020-7469 | — | — | — | NVD ↗ · NTAP-20210720-0001 |
CVE-2020-7595 | — | — | — | NVD ↗ · NTAP-20200702-0005 |
CVE-2020-8169 | — | — | — | NVD ↗ · NTAP-20200911-0002 |
CVE-2020-8231 | — | — | — | NVD ↗ · NTAP-20200911-0003 |
CVE-2020-8284 | — | — | — | NVD ↗ · NTAP-20210122-0007 |
CVE-2020-8285 | — | — | — | NVD ↗ · NTAP-20210122-0007 |
CVE-2020-8286 | — | — | — | NVD ↗ · NTAP-20210122-0007 |
CVE-2020-8492 | — | — | — | NVD ↗ · NTAP-20200221-0001 |
CVE-2020-8576 | 2020-09-02 | MEDIUM | 5.4 | Clustered Data ONTAP versions prior to 9.3P19, 9.5P14, 9.6P9 and 9.7 are susceptible to a vulnerability which when successfully exploited could lead to addition NVD ↗ · NTAP-20200902-0001 |
CVE-2020-8578 | 2021-02-08 | LOW | 3.3 | Clustered Data ONTAP versions prior to 9.3P20 are susceptible to a vulnerability which could allow an attacker to discover node names via AutoSupport bundles ev NVD ↗ · NTAP-20210208-0002 · NTAP-20210208-0003 |
CVE-2020-8579 | 2020-10-27 | HIGH | 7.5 | Clustered Data ONTAP versions 9.7 through 9.7P7 are susceptible to a vulnerability which allows an attacker with access to an intercluster LIF to cause a Denial NVD ↗ · NTAP-20201026-0001 |
CVE-2020-8581 | 2021-01-19 | MEDIUM | 6.5 | Clustered Data ONTAP versions prior to 9.3P20 and 9.5 are susceptible to a vulnerability which could allow an authenticated but unauthorized attacker to overwri NVD ↗ · NTAP-20210119-0001 |
CVE-2020-8588 | 2021-02-03 | LOW | 3.5 | Clustered Data ONTAP versions prior to 9.3P20 and 9.5P15 are susceptible to a vulnerability which could allow unauthorized tenant users to discover the existenc NVD ↗ · NTAP-20210201-0001 |
CVE-2020-8589 | 2021-02-03 | LOW | 3.5 | Clustered Data ONTAP versions prior to 9.3P20 and 9.5P15 are susceptible to a vulnerability which could allow unauthorized tenant users to discover the names of NVD ↗ · NTAP-20210201-0002 |
CVE-2020-8590 | 2021-02-08 | LOW | 3.3 | Clustered Data ONTAP versions prior to 9.1P18 and 9.3P12 are susceptible to a vulnerability which could allow an attacker to discover node names via AutoSupport NVD ↗ · |
CVE-2020-8616 | — | — | — | NVD ↗ · NTAP-20200522-0002 |
CVE-2020-8617 | — | — | — | NVD ↗ · NTAP-20200522-0002 |
CVE-2020-8696 | — | — | — | NVD ↗ · NTAP-20201113-0006 |
CVE-2020-8698 | — | — | — | NVD ↗ · NTAP-20201113-0006 |
CVE-2020-8705 | — | — | — | NVD ↗ · NTAP-20201113-0004 |
CVE-2020-8744 | — | — | — | NVD ↗ · NTAP-20201113-0004 |
CVE-2020-8755 | — | — | — | NVD ↗ · NTAP-20201113-0004 |
CVE-2021-20197 | — | — | — | NVD ↗ · NTAP-20210528-0009 |
CVE-2021-20225 | — | — | — | NVD ↗ · NTAP-20220325-0001 |
CVE-2021-20233 | — | — | — | NVD ↗ · NTAP-20220325-0001 |
CVE-2021-20284 | — | — | — | NVD ↗ · NTAP-20210521-0010 |
CVE-2021-20305 | — | — | — | NVD ↗ · NTAP-20211022-0002 |
CVE-2021-21702 | — | — | — | NVD ↗ · NTAP-20210312-0005 |
CVE-2021-21703 | — | — | — | NVD ↗ · NTAP-20211118-0003 |
CVE-2021-21704 | — | — | — | NVD ↗ · NTAP-20211029-0006 |
CVE-2021-21705 | — | — | — | NVD ↗ · NTAP-20211029-0006 |
CVE-2021-21707 | — | — | — | NVD ↗ · NTAP-20211223-0005 |
CVE-2021-22060 | — | — | — | NVD ↗ · NTAP-20220131-0001 |
CVE-2021-22096 | — | — | — | NVD ↗ · NTAP-20211125-0005 |
CVE-2021-22922 | — | — | — | NVD ↗ · NTAP-20210902-0003 |
CVE-2021-22923 | — | — | — | NVD ↗ · NTAP-20210902-0003 |
CVE-2021-22924 | — | — | — | NVD ↗ · NTAP-20210902-0003 |
CVE-2021-22925 | — | — | — | NVD ↗ · NTAP-20210902-0003 |
CVE-2021-22926 | — | — | — | NVD ↗ · NTAP-20210902-0003 |
CVE-2021-22945 | — | — | — | NVD ↗ · NTAP-20211029-0003 |
CVE-2021-22946 | — | — | — | NVD ↗ · NTAP-20211029-0003 |
CVE-2021-22947 | — | — | — | NVD ↗ · NTAP-20211029-0003 |
CVE-2021-23017 | — | — | — | NVD ↗ · NTAP-20210708-0006 |
CVE-2021-23336 | — | — | — | NVD ↗ · NTAP-20210326-0004 |
CVE-2021-23839 | — | — | — | NVD ↗ · NTAP-20210219-0009 |
CVE-2021-23840 | — | — | — | NVD ↗ · NTAP-20210219-0009 |
CVE-2021-23841 | — | — | — | NVD ↗ · NTAP-20210219-0009 |
CVE-2021-25217 | — | — | — | NVD ↗ · NTAP-20220325-0011 |
CVE-2021-26988 | 2021-03-04 | LOW | 3.5 | Clustered Data ONTAP versions prior to 9.3P21, 9.5P16, 9.6P12, 9.7P8 and 9.8 are susceptible to a vulnerability which could allow unauthorized tenant users to d NVD ↗ · NTAP-20210303-0001 |
CVE-2021-26989 | 2021-03-04 | MEDIUM | 6.5 | Clustered Data ONTAP versions prior to 9.3P21, 9.5P16, 9.6P12, 9.7P9 and 9.8 are susceptible to a vulnerability which could allow a remote authenticated attacke NVD ↗ · NTAP-20210303-0002 |
CVE-2021-26994 | 2021-06-04 | MEDIUM | 6.5 | Clustered Data ONTAP versions prior to 9.7P13 and 9.8P3 are susceptible to a vulnerability which could allow single workloads to cause a Denial of Service (DoS) NVD ↗ · NTAP-20210601-0001 |
CVE-2021-27001 | 2021-10-19 | MEDIUM | 5.5 | Clustered Data ONTAP versions 9.x prior to 9.5P18, 9.6P16, 9.7P16, 9.8P7 and 9.9.1P2 are susceptible to a vulnerability which could allow an authenticated privi NVD ↗ · NTAP-20211018-0001 |
CVE-2021-27003 | 2021-10-12 | MEDIUM | 4.7 | Clustered Data ONTAP versions prior to 9.5P18, 9.6P15, 9.7P14, 9.8P5 and 9.9.1 are missing an X-Frame-Options header which could allow a clickjacking attack. NVD ↗ · NTAP-20211012-0001 |
CVE-2021-27005 | 2021-11-01 | HIGH | 7.5 | Clustered Data ONTAP versions 9.6 and higher prior to 9.6P16, 9.7P16, 9.8P7 and 9.9.1P3 are susceptible to a vulnerability which could allow a remote attacker t NVD ↗ · NTAP-20211029-0002 |
CVE-2021-28163 | — | — | — | NVD ↗ · NTAP-20210611-0006 |
CVE-2021-28164 | — | — | — | NVD ↗ · NTAP-20210611-0006 |
CVE-2021-28165 | — | — | — | NVD ↗ · NTAP-20210611-0006 |
CVE-2021-29921 | — | — | — | NVD ↗ · NTAP-20210622-0003 |
CVE-2021-3156 | — | — | — | NVD ↗ · NTAP-20210128-0002 |
CVE-2021-3177 | — | — | — | NVD ↗ · NTAP-20210226-0003 |
CVE-2021-31879 | — | — | — | NVD ↗ · NTAP-20210618-0002 |
CVE-2021-3326 | — | — | — | NVD ↗ · NTAP-20210304-0007 |
CVE-2021-3426 | — | — | — | NVD ↗ · NTAP-20210629-0003 |
CVE-2021-3449 | — | — | — | NVD ↗ · NTAP-20210326-0006 |
CVE-2021-3450 | — | — | — | NVD ↗ · NTAP-20210326-0006 |
CVE-2021-34798 | — | — | — | NVD ↗ · NTAP-20211008-0004 |
CVE-2021-3516 | — | — | — | NVD ↗ · NTAP-20210716-0005 |
CVE-2021-3517 | — | — | — | NVD ↗ · NTAP-20210625-0002 |
CVE-2021-3518 | — | — | — | NVD ↗ · NTAP-20210625-0002 |
CVE-2021-3520 | — | — | — | NVD ↗ · NTAP-20211104-0005 |
CVE-2021-3530 | — | — | — | NVD ↗ · NTAP-20210716-0006 |
CVE-2021-3537 | — | — | — | NVD ↗ · NTAP-20210625-0002 |
CVE-2021-3541 | — | — | — | NVD ↗ · NTAP-20210805-0007 |
CVE-2021-3549 | 2021-05-26 | HIGH | 7.1 | An out of bounds flaw was found in GNU binutils objdump utility version 2.36. An attacker could use this flaw and pass a large section to avr_elf32_load_records NVD ↗ · NTAP-20250228-0005 |
CVE-2021-3559 | — | — | — | NVD ↗ · NTAP-20210706-0006 |
CVE-2021-3580 | — | — | — | NVD ↗ · NTAP-20211104-0006 |
CVE-2021-35942 | — | — | — | NVD ↗ · NTAP-20210827-0005 |
CVE-2021-36160 | — | — | — | NVD ↗ · NTAP-20211008-0004 |
CVE-2021-3631 | — | — | — | NVD ↗ · NTAP-20220331-0010 |
CVE-2021-3667 | — | — | — | NVD ↗ · NTAP-20220331-0005 |
CVE-2021-3671 | 2021-10-12 | MEDIUM | 6.5 | A null pointer de-reference was found in the way samba kerberos server handled missing sname in TGS-REQ (Ticket Granting Server - Request). An authenticated use NVD ↗ · NTAP-20230216-0008 |
CVE-2021-36770 | — | — | — | NVD ↗ · NTAP-20210909-0003 |
CVE-2021-3711 | — | — | — | NVD ↗ · NTAP-20210827-0010 |
CVE-2021-3712 | — | — | — | NVD ↗ · NTAP-20210827-0010 |
CVE-2021-3733 | — | — | — | NVD ↗ · NTAP-20220407-0001 |
CVE-2021-3737 | — | — | — | NVD ↗ · NTAP-20220407-0009 |
CVE-2021-37600 | — | — | — | NVD ↗ · NTAP-20210902-0002 |
CVE-2021-3770 | — | — | — | NVD ↗ · NTAP-20221124-0003 |
CVE-2021-3778 | — | — | — | NVD ↗ · NTAP-20221118-0003 |
CVE-2021-3796 | — | — | — | NVD ↗ · NTAP-20221118-0004 |
CVE-2021-39275 | — | — | — | NVD ↗ · NTAP-20211008-0004 |
CVE-2021-3975 | — | — | — | NVD ↗ · NTAP-20221201-0002 |
CVE-2021-3998 | — | — | — | NVD ↗ · NTAP-20221020-0003 |
CVE-2021-3999 | — | — | — | NVD ↗ · NTAP-20221104-0001 |
CVE-2021-40438 | — | — | — | NVD ↗ · NTAP-20211008-0004 |
CVE-2021-4044 | — | — | — | NVD ↗ · NTAP-20211229-0003 |
CVE-2021-4147 | — | — | — | NVD ↗ · NTAP-20220513-0004 |
CVE-2021-4160 | — | — | — | NVD ↗ · NTAP-20220204-0005 |
CVE-2021-41617 | — | — | — | NVD ↗ · NTAP-20211014-0004 |
CVE-2021-4189 | — | — | — | NVD ↗ · NTAP-20221104-0004 |
CVE-2021-44228 | — | — | — | NVD ↗ · NTAP-20211210-0007 |
CVE-2021-44758 | 2022-12-26 | HIGH | 7.5 | Heimdal before 7.7.1 allows attackers to cause a NULL pointer dereference in a SPNEGO acceptor via a preferred_mech_type of GSS_C_NO_OID and a nonzero initial_r NVD ↗ · NTAP-20230216-0008 |
CVE-2021-45046 | — | — | — | NVD ↗ · NTAP-20211215-0001 |
CVE-2021-45078 | — | — | — | NVD ↗ · NTAP-20220107-0002 |
CVE-2021-45105 | — | — | — | NVD ↗ · NTAP-20211218-0001 |
CVE-2021-45346 | — | — | — | NVD ↗ · NTAP-20220303-0001 |
CVE-2021-46143 | — | — | — | NVD ↗ · NTAP-20220121-0006 |
CVE-2021-47179 | 2024-03-25 | HIGH | 7.5 | In the Linux kernel, the following vulnerability has been resolved: NFSv4: Fix a NULL pointer dereference in pnfs_mark_matching_lsegs_return() Commit de144ff423 NVD ↗ · |
CVE-2022-0391 | — | — | — | NVD ↗ · NTAP-20220225-0009 |
CVE-2022-0561 | — | — | — | NVD ↗ · NTAP-20220318-0001 |
CVE-2022-0562 | — | — | — | NVD ↗ · NTAP-20220318-0001 |
CVE-2022-0563 | — | — | — | NVD ↗ · NTAP-20220331-0002 |
CVE-2022-0778 | — | — | — | NVD ↗ · NTAP-20220321-0002 |
CVE-2022-0897 | — | — | — | NVD ↗ · NTAP-20220519-0002 |
CVE-2022-0907 | — | — | — | NVD ↗ · NTAP-20220506-0002 |
CVE-2022-0908 | — | — | — | NVD ↗ · NTAP-20220506-0002 |
CVE-2022-0909 | — | — | — | NVD ↗ · NTAP-20220506-0002 |
CVE-2022-0924 | — | — | — | NVD ↗ · NTAP-20220506-0002 |
CVE-2022-1210 | — | — | — | NVD ↗ · NTAP-20220513-0005 |
CVE-2022-1292 | — | — | — | NVD ↗ · NTAP-20220602-0009 |
CVE-2022-1304 | 2022-04-14 | HIGH | 7.8 | An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and possibly arbitrary code execution via a sp NVD ↗ · NTAP-20241122-0010 |
CVE-2022-1343 | — | — | — | NVD ↗ · NTAP-20220602-0009 |
CVE-2022-1354 | — | — | — | NVD ↗ · NTAP-20221014-0007 |
CVE-2022-1355 | — | — | — | NVD ↗ · NTAP-20221014-0007 |
CVE-2022-1434 | — | — | — | NVD ↗ · NTAP-20220602-0009 |
CVE-2022-1473 | — | — | — | NVD ↗ · NTAP-20220602-0009 |
CVE-2022-1622 | — | — | — | NVD ↗ · NTAP-20220616-0005 |
CVE-2022-1623 | — | — | — | NVD ↗ · NTAP-20220616-0005 |
CVE-2022-1664 | — | — | — | NVD ↗ · NTAP-20221007-0002 |
CVE-2022-1678 | — | — | — | NVD ↗ · NTAP-20220715-0001 |
CVE-2022-2068 | — | — | — | NVD ↗ · NTAP-20220707-0008 |
CVE-2022-2097 | — | — | — | NVD ↗ · NTAP-20220715-0011 |
CVE-2022-22576 | — | — | — | NVD ↗ · NTAP-20220609-0008 |
CVE-2022-22822 | — | — | — | NVD ↗ · NTAP-20220131-0004 |
CVE-2022-22823 | — | — | — | NVD ↗ · NTAP-20220131-0004 |
CVE-2022-22824 | — | — | — | NVD ↗ · NTAP-20220131-0004 |
CVE-2022-22825 | — | — | — | NVD ↗ · NTAP-20220131-0004 |
CVE-2022-22826 | — | — | — | NVD ↗ · NTAP-20220131-0004 |
CVE-2022-22827 | — | — | — | NVD ↗ · NTAP-20220131-0004 |
CVE-2022-22844 | — | — | — | NVD ↗ · NTAP-20220311-0002 |
CVE-2022-22950 | — | — | — | NVD ↗ · NTAP-20220401-0001 |
CVE-2022-22968 | — | — | — | NVD ↗ · NTAP-20220602-0004 |
CVE-2022-23093 | — | — | — | NVD ↗ · NTAP-20221209-0009 |
CVE-2022-23241 | 2022-10-19 | HIGH | 8.1 | Clustered Data ONTAP versions 9.11.1 through 9.11.1P2 with SnapLock configured FlexGroups are susceptible to a vulnerability which could allow an authenticated NVD ↗ · NTAP-20221017-0001 |
CVE-2022-23308 | — | — | — | NVD ↗ · NTAP-20220331-0008 |
CVE-2022-23852 | — | — | — | NVD ↗ · NTAP-20220217-0001 |
CVE-2022-23990 | — | — | — | NVD ↗ · NTAP-20220204-0006 |
CVE-2022-24407 | — | — | — | NVD ↗ · NTAP-20221007-0003 |
CVE-2022-24963 | 2023-01-31 | CRITICAL | 9.8 | Integer Overflow or Wraparound vulnerability in apr_encode functions of Apache Portable Runtime (APR) allows an attacker to write beyond bounds of a buffer. Thi NVD ↗ · NTAP-20230908-0008 |
CVE-2022-25147 | 2023-01-31 | MEDIUM | 6.5 | Integer Overflow or Wraparound vulnerability in apr_base64 functions of Apache Portable Runtime Utility (APR-util) allows an attacker to write beyond bounds of NVD ↗ · NTAP-20240315-0001 |
CVE-2022-25235 | — | — | — | NVD ↗ · NTAP-20220303-0008 |
CVE-2022-25236 | — | — | — | NVD ↗ · NTAP-20220303-0008 |
CVE-2022-25313 | — | — | — | NVD ↗ · NTAP-20220303-0008 |
CVE-2022-25314 | — | — | — | NVD ↗ · NTAP-20220303-0008 |
CVE-2022-25315 | — | — | — | NVD ↗ · NTAP-20220303-0008 |
CVE-2022-25844 | — | — | — | NVD ↗ · NTAP-20220629-0009 |
CVE-2022-26377 | — | — | — | NVD ↗ · NTAP-20220624-0005 |
CVE-2022-26488 | — | — | — | NVD ↗ · NTAP-20220419-0005 |
CVE-2022-27774 | — | — | — | NVD ↗ · NTAP-20220609-0008 |
CVE-2022-27775 | — | — | — | NVD ↗ · NTAP-20220609-0008 |
CVE-2022-27776 | — | — | — | NVD ↗ · NTAP-20220609-0008 |
CVE-2022-27778 | — | — | — | NVD ↗ · NTAP-20220609-0009 |
CVE-2022-27779 | — | — | — | NVD ↗ · NTAP-20220609-0009 |
CVE-2022-27780 | — | — | — | NVD ↗ · NTAP-20220609-0009 |
CVE-2022-27781 | — | — | — | NVD ↗ · NTAP-20220609-0009 |
CVE-2022-27782 | — | — | — | NVD ↗ · NTAP-20220609-0009 |
CVE-2022-28330 | — | — | — | NVD ↗ · NTAP-20220624-0005 |
CVE-2022-28614 | — | — | — | NVD ↗ · NTAP-20220624-0005 |
CVE-2022-28615 | — | — | — | NVD ↗ · NTAP-20220624-0005 |
CVE-2022-29404 | — | — | — | NVD ↗ · NTAP-20220624-0005 |
CVE-2022-2953 | — | — | — | NVD ↗ · NTAP-20221014-0008 |
CVE-2022-29824 | — | — | — | NVD ↗ · NTAP-20220715-0006 |
CVE-2022-29901 | — | — | — | NVD ↗ · NTAP-20221007-0007 |
CVE-2022-30115 | — | — | — | NVD ↗ · NTAP-20220609-0009 |
CVE-2022-30522 | — | — | — | NVD ↗ · NTAP-20220624-0005 |
CVE-2022-30556 | — | — | — | NVD ↗ · NTAP-20220624-0005 |
CVE-2022-3080 | 2022-09-21 | HIGH | 7.5 | By sending specific queries to the resolver, an attacker can cause named to crash. NVD ↗ · NTAP-20240621-0002 |
CVE-2022-31676 | — | — | — | NVD ↗ · NTAP-20221017-0003 |
CVE-2022-31813 | — | — | — | NVD ↗ · NTAP-20220624-0005 |
CVE-2022-3219 | 2023-02-23 | LOW | 3.3 | GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a fe NVD ↗ · NTAP-20230324-0001 |
CVE-2022-32205 | — | — | — | NVD ↗ · NTAP-20220915-0003 |
CVE-2022-32206 | — | — | — | NVD ↗ · NTAP-20220915-0003 |
CVE-2022-32207 | — | — | — | NVD ↗ · NTAP-20220915-0003 |
CVE-2022-32208 | — | — | — | NVD ↗ · NTAP-20220915-0003 |
CVE-2022-32221 | 2022-12-05 | CRITICAL | 9.8 | When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELD NVD ↗ · NTAP-20230110-0006 |
CVE-2022-3437 | 2023-01-12 | MEDIUM | 6.5 | A heap-based buffer overflow vulnerability was found in Samba within the GSSAPI unwrap_des() and unwrap_des3() routines of Heimdal. The DES and Triple-DES decry NVD ↗ · NTAP-20230216-0008 |
CVE-2022-34526 | — | — | — | NVD ↗ · NTAP-20220930-0002 |
CVE-2022-34903 | — | — | — | NVD ↗ · NTAP-20220826-0005 |
CVE-2022-3520 | 2022-12-02 | CRITICAL | 9.8 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0765. NVD ↗ · NTAP-20241115-0010 |
CVE-2022-35205 | 2023-08-22 | MEDIUM | 5.5 | An issue was discovered in Binutils readelf 2.38.50, reachable assertion failure in function display_debug_names allows attackers to cause a denial of service. NVD ↗ · NTAP-20231006-0010 |
CVE-2022-35252 | — | — | — | NVD ↗ · NTAP-20220930-0005 |
CVE-2022-35260 | 2022-12-05 | MEDIUM | 6.5 | curl can be told to parse a `.netrc` file for credentials. If that file endsin a line with 4095 consecutive non-white space letters and no newline, curlwould fi NVD ↗ · NTAP-20230110-0006 |
CVE-2022-35737 | — | — | — | NVD ↗ · NTAP-20220915-0009 |
CVE-2022-3602 | — | — | — | NVD ↗ · NTAP-20221102-0001 |
CVE-2022-37434 | — | — | — | NVD ↗ · NTAP-20220901-0005 |
CVE-2022-3786 | — | — | — | NVD ↗ · NTAP-20221102-0001 |
CVE-2022-39046 | — | — | — | NVD ↗ · NTAP-20221104-0002 · NTAP-20221104-0002 |
CVE-2022-3996 | 2022-12-13 | HIGH | 7.5 | If an X.509 certificate contains a malformed policy constraint and policy processing is enabled, then a write lock will be taken twice recursively. On some oper NVD ↗ · NTAP-20230203-0003 |
CVE-2022-40303 | — | — | — | NVD ↗ · NTAP-20221209-0003 |
CVE-2022-40304 | — | — | — | NVD ↗ · NTAP-20221209-0003 |
CVE-2022-40674 | — | — | — | NVD ↗ · NTAP-20221028-0008 |
CVE-2022-40735 | 2022-11-14 | HIGH | 7.5 | The Diffie-Hellman Key Agreement Protocol allows use of long exponents that arguably make certain calculations unnecessarily expensive, because the 1996 van Oor NVD ↗ · NTAP-20260227-0008 |
CVE-2022-40897 | 2022-12-23 | MEDIUM | 5.9 | Python Packaging Authority (PyPA) setuptools before 65.5.1 allows remote attackers to cause a denial of service via HTML in a crafted package or custom PackageI NVD ↗ · NTAP-20230214-0001 |
CVE-2022-41409 | 2023-07-18 | HIGH | 7.5 | Integer overflow vulnerability in pcre2test before 10.41 allows attackers to cause a denial of service or other unspecified impacts via negative input. NVD ↗ · NTAP-20260320-0014 |
CVE-2022-41916 | 2022-11-15 | MEDIUM | 5.9 | Heimdal is an implementation of ASN.1/DER, PKIX, and Kerberos. Versions prior to 7.7.1 are vulnerable to a denial of service vulnerability in Heimdal's PKI cert NVD ↗ · NTAP-20230216-0008 |
CVE-2022-4203 | 2023-02-24 | MEDIUM | 4.9 | A read buffer overrun can be triggered in X.509 certificate verification, specifically in name constraint checking. Note that this occurs after certificate chai NVD ↗ · NTAP-20230214-0011 · NTAP-20230214-0011 |
CVE-2022-42898 | 2022-12-25 | HIGH | 8.8 | PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to remote code execution (in KDC, kadmind, o NVD ↗ · NTAP-20230223-0001 · NTAP-20230216-0008 |
CVE-2022-42915 | — | — | — | NVD ↗ · NTAP-20221209-0010 |
CVE-2022-42916 | — | — | — | NVD ↗ · NTAP-20221209-0010 |
CVE-2022-4292 | 2022-12-05 | HIGH | 7.8 | Use After Free in GitHub repository vim/vim prior to 9.0.0882. NVD ↗ · NTAP-20230113-0005 |
CVE-2022-4304 | 2023-02-08 | MEDIUM | 5.9 | A timing based side channel exists in the OpenSSL RSA Decryption implementation which could be sufficient to recover a plaintext across a network in a Bleichenb NVD ↗ · NTAP-20230214-0011 · NTAP-20230214-0011 |
CVE-2022-43551 | 2022-12-23 | HIGH | 7.5 | A vulnerability exists in curl <7.87.0 HSTS check that could be bypassed to trick it to keep using HTTP. Using its HSTS support, curl can be instructed to use H NVD ↗ · NTAP-20230214-0002 |
CVE-2022-43552 | 2023-02-09 | MEDIUM | 5.9 | A use after free vulnerability exists in curl <7.87.0. Curl can be asked to *tunnel* virtually all protocols it supports through an HTTP proxy. HTTP proxies can NVD ↗ · NTAP-20230214-0002 |
CVE-2022-43680 | — | — | — | NVD ↗ · NTAP-20221118-0007 |
CVE-2022-4415 | 2023-01-11 | MEDIUM | 5.5 | A vulnerability was found in systemd. This security flaw can cause a local information leak due to systemd-coredump not respecting the fs.suid_dumpable kernel s NVD ↗ · NTAP-20230216-0010 |
CVE-2022-4450 | 2023-02-08 | HIGH | 7.5 | The function PEM_read_bio_ex() reads a PEM file from a BIO and parses and decodes the "name" (e.g. "CERTIFICATE"), any header data and the payload data. If the NVD ↗ · NTAP-20230214-0011 · NTAP-20230214-0011 |
CVE-2022-44640 | 2022-12-25 | CRITICAL | 9.8 | Heimdal before 7.7.1 allows remote attackers to execute arbitrary code because of an invalid free in the ASN.1 codec used by the Key Distribution Center (KDC). NVD ↗ · NTAP-20230216-0008 |
CVE-2022-45061 | — | — | — | NVD ↗ · NTAP-20221209-0007 |
CVE-2022-45703 | 2023-08-22 | HIGH | 7.8 | Heap buffer overflow vulnerability in binutils readelf before 2.40 via function display_debug_section in file readelf.c. NVD ↗ · NTAP-20231006-0003 |
CVE-2022-48063 | 2023-08-22 | MEDIUM | 5.5 | GNU Binutils before 2.40 was discovered to contain an excessive memory consumption vulnerability via the function load_separate_debug_files at dwarf2.c. The att NVD ↗ · NTAP-20231006-0008 |
CVE-2022-48064 | 2023-08-22 | MEDIUM | 5.5 | GNU Binutils before 2.40 was discovered to contain an excessive memory consumption vulnerability via the function bfd_dwarf2_find_nearest_line_with_alt at dwarf NVD ↗ · NTAP-20231006-0008 |
CVE-2022-48065 | 2023-08-22 | MEDIUM | 5.5 | GNU Binutils before 2.40 was discovered to contain a memory leak vulnerability var the function find_abstract_instance in dwarf2.c. NVD ↗ · NTAP-20231006-0008 |
CVE-2022-48560 | 2023-08-22 | HIGH | 7.5 | A use-after-free exists in Python through 3.9 via heappushpop in heapq. NVD ↗ · NTAP-20230929-0008 |
CVE-2023-0215 | 2023-02-08 | HIGH | 7.5 | The public API function BIO_new_NDEF is a helper function used for streaming ASN.1 data via a BIO. It is primarily used internally to OpenSSL to support the SMI NVD ↗ · NTAP-20230214-0011 · NTAP-20230214-0011 |
CVE-2023-0216 | 2023-02-08 | HIGH | 7.5 | An invalid pointer dereference on read can be triggered when an application tries to load malformed PKCS7 data with the d2i_PKCS7(), d2i_PKCS7_bio() or d2i_PKCS NVD ↗ · NTAP-20230214-0011 · NTAP-20230214-0011 |
CVE-2023-0217 | 2023-02-08 | HIGH | 7.5 | An invalid pointer dereference on read can be triggered when an application tries to check a malformed DSA public key by the EVP_PKEY_public_check() function. T NVD ↗ · NTAP-20230214-0011 · NTAP-20230214-0011 |
CVE-2023-0286 | 2023-02-08 | HIGH | 7.4 | There is a type confusion vulnerability relating to X.400 address processing inside an X.509 GeneralName. X.400 addresses were parsed as an ASN1_STRING but the NVD ↗ · NTAP-20230214-0011 · NTAP-20230214-0011 |
CVE-2023-0361 | 2023-02-15 | HIGH | 7.4 | A timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS. This side-channel can be sufficient to recover the key encrypt NVD ↗ · NTAP-20230324-0005 |
CVE-2023-0401 | 2023-02-08 | HIGH | 7.5 | A NULL pointer can be dereferenced when signatures are being verified on PKCS7 signed or signedAndEnveloped data. In case the hash algorithm used for the signat NVD ↗ · NTAP-20230214-0011 · NTAP-20230214-0011 |
CVE-2023-0464 | 2023-03-22 | HIGH | 7.5 | A security vulnerability has been identified in all supported versions of OpenSSL related to the verification of X.509 certificate chains that include policy co NVD ↗ · NTAP-20230406-0006 |
CVE-2023-0465 | 2023-03-28 | MEDIUM | 5.3 | Applications that use a non-default option when verifying certificates may be vulnerable to an attack from a malicious CA to circumvent certain checks. Invalid NVD ↗ · NTAP-20230414-0001 |
CVE-2023-0466 | 2023-03-28 | MEDIUM | 5.3 | The function X509_VERIFY_PARAM_add0_policy() is documented to implicitly enable the certificate policy check when doing certificate verification. However the im NVD ↗ · NTAP-20230414-0001 |
CVE-2023-0568 | 2023-02-16 | HIGH | 7.5 | In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, core path resolution function allocate buffer one byte too small. When resolving paths w NVD ↗ · NTAP-20230517-0001 |
CVE-2023-0662 | 2023-02-16 | HIGH | 7.5 | In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, excessive number of parts in HTTP form upload can cause high resource consumption and ex NVD ↗ · NTAP-20230517-0001 |
CVE-2023-1192 | 2023-11-01 | MEDIUM | 6.5 | A use-after-free flaw was found in smb2_is_status_io_timeout() in CIFS in the Linux Kernel. After CIFS transfers response data to a system call, there are still NVD ↗ · NTAP-20250613-0012 |
CVE-2023-2002 | 2023-05-26 | MEDIUM | 6.8 | A vulnerability was found in the HCI sockets implementation due to a missing capability check in net/bluetooth/hci_sock.c in the Linux Kernel. This flaw allows NVD ↗ · NTAP-20240202-0004 |
CVE-2023-20900 | 2023-08-31 | HIGH | 7.1 | A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-6A952214-0E5E-4CCF-9D2A-9 NVD ↗ · NTAP-20231013-0002 |
CVE-2023-23914 | 2023-02-23 | CRITICAL | 9.1 | A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality fail when multiple URLs are requeste NVD ↗ · NTAP-20230309-0006 |
CVE-2023-23915 | 2023-02-23 | MEDIUM | 6.5 | A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality to behave incorrectly when multiple NVD ↗ · NTAP-20230309-0006 |
CVE-2023-23916 | 2023-02-23 | MEDIUM | 6.5 | An allocation of resources without limits or throttling vulnerability exists in curl <v7.88.0 based on the "chained" HTTP compression algorithms, meaning that a NVD ↗ · NTAP-20230309-0006 |
CVE-2023-25136 | 2023-02-03 | MEDIUM | 6.5 | OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling. This is fixed in OpenSSH 9.2. The double free can be le NVD ↗ · NTAP-20230309-0003 |
CVE-2023-25584 | 2023-09-14 | MEDIUM | 6.3 | An out-of-bounds read flaw was found in the parse_module function in bfd/vms-alpha.c in Binutils. NVD ↗ · NTAP-20231103-0002 |
CVE-2023-25585 | 2023-09-14 | MEDIUM | 4.7 | A flaw was found in Binutils. The use of an uninitialized field in the struct module *module may lead to application crash and local denial of service. NVD ↗ · NTAP-20231103-0003 |
CVE-2023-25586 | 2023-09-14 | MEDIUM | 4.7 | A flaw was found in Binutils. A logic fail in the bfd_init_section_decompress_status function may lead to the use of an uninitialized variable that can cause a NVD ↗ · NTAP-20231103-0003 |
CVE-2023-25588 | 2023-09-14 | MEDIUM | 4.7 | A flaw was found in Binutils. The field `the_bfd` of `asymbol`struct is uninitialized in the `bfd_mach_o_get_synthetic_symtab` function, which may lead to an ap NVD ↗ · NTAP-20231103-0003 |
CVE-2023-25690 | 2023-03-07 | CRITICAL | 9.8 | Some mod_proxy configurations on Apache HTTP Server versions 2.4.0 through 2.4.55 allow a HTTP Request Smuggling attack. Configurations are affected when mod_pr NVD ↗ · NTAP-20230316-0007 |
CVE-2023-2650 | 2023-05-30 | MEDIUM | 6.5 | Issue summary: Processing some specially crafted ASN.1 object identifiers or data containing them may be very slow. Impact summary: Applications that use OBJ_ob NVD ↗ · NTAP-20230703-0001 · NTAP-20230703-0001 |
CVE-2023-26604 | 2023-03-03 | HIGH | 7.8 | systemd before 247 does not adequately block local privilege escalation for some Sudo configurations, e.g., plausible sudoers files in which the "systemctl stat NVD ↗ · NTAP-20230505-0009 |
CVE-2023-26965 | 2023-06-14 | MEDIUM | 5.5 | loadImage() in tools/tiffcrop.c in LibTIFF through 4.5.0 has a heap-based use after free via a crafted TIFF image. NVD ↗ · NTAP-20230706-0009 |
CVE-2023-2700 | 2023-05-15 | MEDIUM | 5.5 | A vulnerability was found in libvirt. This security flaw ouccers due to repeatedly querying an SR-IOV PCI device's capabilities that exposes a memory leak cause NVD ↗ · NTAP-20230706-0001 |
CVE-2023-27043 | 2023-04-19 | MEDIUM | 5.3 | The email module of Python through 3.11.3 incorrectly parses e-mail addresses that contain a special character. The wrong portion of an RFC2822 header is identi NVD ↗ · NTAP-20230601-0003 |
CVE-2023-27314 | 2023-10-12 | HIGH | 7.5 | ONTAP 9 versions prior to 9.8P19, 9.9.1P16, 9.10.1P12, 9.11.1P8, 9.12.1P2 and 9.13.1 are susceptible to a vulnerability which could allow a remote unauthenticat NVD ↗ · NTAP-20231009-0001 |
CVE-2023-27317 | 2023-12-15 | MEDIUM | 4.3 | ONTAP 9 versions 9.12.1P8, 9.13.1P4, and 9.13.1P5 are susceptible to a vulnerability which will cause all SAS-attached FIPS 140-2 drives to become unlocked afte NVD ↗ · NTAP-20231215-0001 |
CVE-2023-27319 | 2023-12-21 | MEDIUM | 5.3 | ONTAP Mediator versions prior to 1.7 are susceptible to a vulnerability that can allow an unauthenticated attacker to enumerate URLs via REST API. NVD ↗ · NTAP-20231221-0011 |
CVE-2023-27522 | 2023-03-07 | HIGH | 7.5 | HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.55. Special char NVD ↗ · NTAP-20230316-0007 |
CVE-2023-27533 | 2023-03-30 | HIGH | 8.8 | A vulnerability in input validation exists in curl <8.0 during communication using the TELNET protocol may allow an attacker to pass on maliciously crafted user NVD ↗ · NTAP-20230420-0011 |
CVE-2023-27535 | 2023-03-30 | MEDIUM | 5.9 | An authentication bypass vulnerability exists in libcurl <8.0.0 in the FTP connection reuse feature that can result in wrong credentials being used during subse NVD ↗ · NTAP-20230420-0010 |
CVE-2023-27536 | 2023-03-30 | MEDIUM | 5.9 | An authentication bypass vulnerability exists libcurl <8.0.0 in the connection reuse feature which can reuse previously established connections with incorrect u NVD ↗ · NTAP-20230420-0010 |
CVE-2023-27537 | 2023-03-30 | MEDIUM | 5.9 | A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS data between separate "handles". This sharing was introduced without considerations for d NVD ↗ · NTAP-20230420-0010 |
CVE-2023-27538 | 2023-03-30 | MEDIUM | 5.5 | An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH op NVD ↗ · NTAP-20230420-0010 |
CVE-2023-28319 | 2023-05-26 | HIGH | 7.5 | A use after free vulnerability exists in curl <v8.1.0 in the way libcurl offers a feature to verify an SSH server's public key using a SHA 256 hash. When this c NVD ↗ · NTAP-20230609-0009 |
CVE-2023-28320 | 2023-05-26 | MEDIUM | 5.9 | A denial of service vulnerability exists in curl <v8.1.0 in the way libcurl provides several different backends for resolving host names, selected at build time NVD ↗ · NTAP-20230609-0009 |
CVE-2023-28321 | 2023-05-26 | MEDIUM | 5.9 | An improper certificate validation vulnerability exists in curl <v8.1.0 in the way it supports matching of wildcard patterns when listed as "Subject Alternative NVD ↗ · NTAP-20230609-0009 |
CVE-2023-28322 | 2023-05-26 | LOW | 3.7 | An information disclosure vulnerability exists in curl <v8.1.0 when doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCT NVD ↗ · NTAP-20230609-0009 |
CVE-2023-28484 | 2023-04-24 | MEDIUM | 6.5 | In libxml2 before 2.10.4, parsing of certain invalid XSD schemas can lead to a NULL pointer dereference and subsequently a segfault. This occurs in xmlSchemaFix NVD ↗ · NTAP-20230601-0006 |
CVE-2023-28656 | 2023-05-03 | HIGH | 8.1 | NGINX Management Suite may allow an authenticated attacker to gain access to configuration objects outside of their assigned environment. Note: Software version NVD ↗ · NTAP-20230609-0006 |
CVE-2023-28724 | 2023-05-03 | HIGH | 7.1 | NGINX Management Suite default file permissions are set such that an authenticated attacker may be able to modify sensitive files on NGINX Instance Manager and NVD ↗ · NTAP-20230609-0006 |
CVE-2023-28840 | 2023-04-04 | HIGH | 7.5 | Moby is an open source container framework developed by Docker Inc. that is distributed as Docker, Mirantis Container Runtime, and various other downstream proj NVD ↗ · NTAP-20260410-0004 |
CVE-2023-2908 | 2023-06-30 | MEDIUM | 5.5 | A null pointer dereference issue was found in Libtiff's tif_dir.c file. This issue may allow an attacker to pass a crafted TIFF image file to the tiffcp utility NVD ↗ · NTAP-20230731-0004 |
CVE-2023-29469 | 2023-04-24 | MEDIUM | 6.5 | An issue was discovered in libxml2 before 2.10.4. When hashing empty dict strings in a crafted XML document, xmlDictComputeFastKey in dict.c can produce non-det NVD ↗ · NTAP-20230601-0006 |
CVE-2023-2953 | 2023-05-30 | HIGH | 7.5 | A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function. NVD ↗ · NTAP-20230703-0005 |
CVE-2023-2975 | 2023-07-14 | MEDIUM | 5.3 | Issue summary: The AES-SIV cipher implementation contains a bug that causes it to ignore empty associated data entries which are unauthenticated as a consequenc NVD ↗ · NTAP-20230725-0004 |
CVE-2023-30861 | 2023-05-02 | HIGH | 7.5 | Flask is a lightweight WSGI web application framework. When all of the following conditions are met, a response containing data intended for one client may be c NVD ↗ · NTAP-20230818-0006 |
CVE-2023-3107 | 2023-08-01 | HIGH | 7.5 | A set of carefully crafted ipv6 packets can trigger an integer overflow in the calculation of a fragment reassembled packet's payload length field. This allows NVD ↗ · NTAP-20230804-0001 |
CVE-2023-31486 | 2023-04-29 | HIGH | 8.1 | HTTP::Tiny before 0.083, a Perl core module since 5.13.9 and available standalone on CPAN, has an insecure default TLS configuration where users must opt in to NVD ↗ · NTAP-20241129-0011 |
CVE-2023-32067 | 2023-05-25 | HIGH | 7.5 | c-ares is an asynchronous resolver library. c-ares is vulnerable to denial of service. If a target resolver sends a query, the attacker forges a malformed UDP p NVD ↗ · NTAP-20240605-0004 |
CVE-2023-32253 | 2025-08-02 | MEDIUM | 5.9 | A flaw was found in the Linux kernel's ksmbd component. A deadlock is triggered by sending multiple concurrent session setup requests, possibly leading to a den NVD ↗ · NTAP-20260206-0002 · NTAP-20260206-0002 |
CVE-2023-3446 | 2023-07-19 | MEDIUM | 5.3 | Issue summary: Checking excessively long DH keys or parameters may be very slow. Impact summary: Applications that use the functions DH_check(), DH_check_ex() o NVD ↗ · NTAP-20230803-0011 |
CVE-2023-34969 | 2023-06-08 | MEDIUM | 6.5 | D-Bus before 1.15.6 sometimes allows unprivileged users to crash dbus-daemon. If a privileged user with control over the dbus-daemon is using the org.freedeskto NVD ↗ · NTAP-20231208-0007 |
CVE-2023-36054 | 2023-08-07 | MEDIUM | 6.5 | lib/kadm5/kadm_rpc_xdr.c in MIT Kerberos 5 (aka krb5) before 1.20.2 and 1.21.x before 1.21.1 frees an uninitialized pointer. A remote authenticated user can tri NVD ↗ · NTAP-20230908-0004 |
CVE-2023-37920 | 2023-07-25 | HIGH | 7.5 | Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi p NVD ↗ · NTAP-20240912-0002 |
CVE-2023-38039 | 2023-09-15 | HIGH | 7.5 | When curl retrieves an HTTP response, it stores the incoming headers so that they can be accessed later via the libcurl headers API. However, curl did not have NVD ↗ · NTAP-20231013-0005 |
CVE-2023-3817 | 2023-07-31 | MEDIUM | 5.3 | Issue summary: Checking excessively long DH keys or parameters may be very slow. Impact summary: Applications that use the functions DH_check(), DH_check_ex() o NVD ↗ · NTAP-20230818-0014 |
CVE-2023-38408 | 2023-07-20 | CRITICAL | 9.8 | The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if an agent is forwarde NVD ↗ · NTAP-20230803-0010 |
CVE-2023-38429 | 2023-07-18 | CRITICAL | 9.8 | An issue was discovered in the Linux kernel before 6.3.4. fs/ksmbd/connection.c in ksmbd has an off-by-one error in memory allocation (because of ksmbd_smb2_che NVD ↗ · NTAP-20250103-0009 · NTAP-20250103-0009 |
CVE-2023-38545 | 2023-10-18 | CRITICAL | 9.8 | This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy handshake. When curl is asked to pass along the host name to the SOCKS5 proxy to allow tha NVD ↗ · NTAP-20231011-0001 |
CVE-2023-38546 | 2023-10-18 | LOW | 3.7 | This flaw allows an attacker to insert cookies at will into a running program using libcurl, if the specific series of conditions are met. libcurl performs tran NVD ↗ · NTAP-20231011-0001 |
CVE-2023-38709 | 2024-04-04 | HIGH | 7.3 | Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses. This issue affects Apache HTTP NVD ↗ · NTAP-20240415-0013 |
CVE-2023-39615 | 2023-08-29 | MEDIUM | 6.5 | Xmlsoft Libxml2 v2.11.0 was discovered to contain an out-of-bounds read via the xmlSAX2StartElement() function at /libxml2/SAX2.c. This vulnerability allows att NVD ↗ · NTAP-20250801-0009 · NTAP-20250801-0009 |
CVE-2023-40217 | 2023-08-25 | MEDIUM | 5.3 | An issue was discovered in Python before 3.8.18, 3.9.x before 3.9.18, 3.10.x before 3.10.13, and 3.11.x before 3.11.5. It primarily affects servers (such as HTT NVD ↗ · NTAP-20231006-0014 |
CVE-2023-41080 | 2023-08-25 | MEDIUM | 6.1 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Tomcat.This issue affects Apache Tomcat: from 11.0.0-M1 NVD ↗ · NTAP-20230921-0006 · NTAP-20230921-0006 |
CVE-2023-4237 | 2023-10-04 | HIGH | 7.3 | A flaw was found in the Ansible Automation Platform. When creating a new keypair, the ec2_key module prints out the private key directly to the standard output. NVD ↗ · NTAP-20241025-0002 |
CVE-2023-42795 | 2023-10-10 | MEDIUM | 5.3 | Incomplete Cleanup vulnerability in Apache Tomcat.When recycling various internal objects in Apache Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 thr NVD ↗ · NTAP-20231103-0007 · NTAP-20231103-0007 |
CVE-2023-43804 | 2023-10-04 | MEDIUM | 5.9 | urllib3 is a user-friendly HTTP client library for Python. urllib3 doesn't treat the `Cookie` HTTP header special or provide any helpers for managing cookies ov NVD ↗ · NTAP-20241213-0007 |
CVE-2023-4408 | 2024-02-13 | HIGH | 7.5 | The DNS message parsing code in `named` includes a section whose computational complexity is overly high. It does not cause problems for typical DNS traffic, bu NVD ↗ · NTAP-20240426-0001 |
CVE-2023-44466 | 2023-09-29 | HIGH | 8.8 | An issue was discovered in net/ceph/messenger_v2.c in the Linux kernel before 6.4.5. There is an integer signedness error, leading to a buffer overflow and remo NVD ↗ · NTAP-20231116-0003 |
CVE-2023-45287 | 2023-12-05 | HIGH | 7.5 | Before Go 1.20, the RSA based TLS key exchanges used the math/big library, which is not constant time. RSA blinding was applied to prevent timing attacks, but a NVD ↗ · NTAP-20240112-0005 |
CVE-2023-45322 | 2023-10-06 | MEDIUM | 6.5 | libxml2 through 2.11.5 has a use-after-free that can only occur after a certain memory allocation fails. This occurs in xmlUnlinkNode in tree.c. NOTE: the vendo NVD ↗ · NTAP-20250919-0003 |
CVE-2023-45648 | 2023-10-10 | MEDIUM | 5.3 | Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.81 NVD ↗ · NTAP-20231103-0007 · NTAP-20231103-0007 |
CVE-2023-46218 | 2023-12-07 | MEDIUM | 6.5 | This flaw allows a malicious HTTP server to set "super cookies" in curl that are then passed back to more origins than what is otherwise allowed or possible. Th NVD ↗ · NTAP-20240125-0007 · NTAP-20240125-0007 |
CVE-2023-46219 | 2023-12-12 | MEDIUM | 5.3 | When saving HSTS data to an excessively long file name, curl could end up removing all contents, making subsequent requests using that file unaware of the HSTS NVD ↗ · NTAP-20240119-0007 |
CVE-2023-48795 | 2023-12-18 | MEDIUM | 5.9 | The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks s NVD ↗ · NTAP-20240105-0004 |
CVE-2023-51384 | 2023-12-18 | MEDIUM | 5.5 | In ssh-agent in OpenSSH before 9.6, certain destination constraints can be incompletely applied. When destination constraints are specified during addition of P NVD ↗ · NTAP-20240105-0005 |
CVE-2023-51385 | 2023-12-18 | MEDIUM | 6.5 | In ssh in OpenSSH before 9.6, OS command injection might occur if a user name or host name has shell metacharacters, and this name is referenced by an expansion NVD ↗ · NTAP-20240105-0005 |
CVE-2023-5156 | 2023-09-25 | HIGH | 7.5 | A flaw was found in the GNU C Library. A recent fix for CVE-2023-4806 introduced the potential for a memory leak, which may result in an application crash. NVD ↗ · NTAP-20251031-0009 |
CVE-2023-5178 | 2023-11-01 | HIGH | 8.8 | A use-after-free vulnerability was found in drivers/nvme/target/tcp.c` in `nvmet_tcp_free_crypto` due to a logical bug in the NVMe/TCP subsystem in the Linux ke NVD ↗ · NTAP-20231208-0004 |
CVE-2023-52340 | 2024-07-05 | HIGH | 7.5 | The IPv6 implementation in the Linux kernel before 6.3 has a net/ipv6/route.c max_size threshold that can be consumed easily, e.g., leading to a denial of servi NVD ↗ · NTAP-20240816-0005 |
CVE-2023-52425 | 2024-02-04 | HIGH | 7.5 | libexpat through 2.5.0 allows a denial of service (resource consumption) because many full reparsings are required in the case of a large token for which multip NVD ↗ · NTAP-20240614-0003 |
CVE-2023-52433 | 2024-02-20 | HIGH | 7.8 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_rbtree: skip sync GC for new elements in this transaction New elements in NVD ↗ · NTAP-20240828-0003 |
CVE-2023-52434 | 2024-02-20 | HIGH | 8.1 | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential OOBs in smb2_parse_contexts() Validate offsets and lengths before NVD ↗ · NTAP-20250117-0009 |
CVE-2023-52439 | 2024-02-20 | HIGH | 7.8 | In the Linux kernel, the following vulnerability has been resolved: uio: Fix use-after-free in uio_open core-1 core-2 ------------------------------------------ NVD ↗ · NTAP-20241227-0006 |
CVE-2023-52522 | 2024-03-02 | HIGH | 8.8 | In the Linux kernel, the following vulnerability has been resolved: net: fix possible store tearing in neigh_periodic_work() While looking at a related syzbot r NVD ↗ · NTAP-20251114-0011 |
CVE-2023-52623 | 2024-03-26 | HIGH | 7.8 | In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Fix a suspicious RCU usage warning I received the following warning while running ct NVD ↗ · |
CVE-2023-5678 | 2023-11-06 | MEDIUM | 5.3 | Issue summary: Generating excessively long X9.42 DH keys or checking excessively long X9.42 DH keys or parameters may be very slow. Impact summary: Applications NVD ↗ · NTAP-20231130-0010 · NTAP-20231130-0010 |
CVE-2023-5981 | 2023-11-28 | MEDIUM | 5.9 | A vulnerability was found that the response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from response times of ciphertexts with correct P NVD ↗ · NTAP-20251121-0004 |
CVE-2023-6237 | 2024-04-25 | MEDIUM | 5.9 | Issue summary: Checking excessively long invalid RSA public keys may take a long time. Impact summary: Applications that use the function EVP_PKEY_public_check( NVD ↗ · NTAP-20240531-0007 · NTAP-20240531-0007 |
CVE-2023-6240 | 2024-02-04 | MEDIUM | 6.5 | A Marvin vulnerability side-channel leakage was found in the RSA decryption operation in the Linux Kernel. This issue may allow a network attacker to decrypt ci NVD ↗ · NTAP-20240628-0002 |
CVE-2023-6356 | 2024-02-07 | MEDIUM | 6.5 | A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated malicious actor to send a set of crafted TCP packages when using NVM NVD ↗ · NTAP-20240415-0002 |
CVE-2023-6516 | 2024-02-13 | HIGH | 7.5 | To keep its cache database efficient, `named` running as a recursive resolver occasionally attempts to clean up the database. It uses several methods, including NVD ↗ · NTAP-20240503-0008 · NTAP-20240503-0008 |
CVE-2023-6535 | 2024-02-07 | MEDIUM | 6.5 | A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated malicious actor to send a set of crafted TCP packages when using NVM NVD ↗ · NTAP-20240415-0003 |
CVE-2023-7008 | 2023-12-23 | MEDIUM | 5.9 | A vulnerability was found in systemd-resolved. This issue may allow systemd-resolved to accept records of DNSSEC-signed domains even when they have no signature NVD ↗ · NTAP-20241122-0004 |
CVE-2024-0397 | 2024-06-17 | HIGH | 7.4 | A defect was discovered in the Python “ssl” module where there is a memory race condition with the ssl.SSLContext methods “cert_store_stats()” and “get_ca_certs NVD ↗ · NTAP-20250411-0006 |
CVE-2024-0450 | 2024-03-19 | MEDIUM | 6.2 | An issue was found in the CPython `zipfile` module affecting versions 3.12.1, 3.11.7, 3.10.13, 3.9.18, and 3.8.18 and prior. The zipfile module is vulnerable to NVD ↗ · NTAP-20250411-0005 |
CVE-2024-0565 | 2024-01-15 | MEDIUM | 6.8 | An out-of-bounds memory read flaw was found in receive_encrypted_standard in fs/smb/client/smb2ops.c in the SMB Client sub-component in the Linux Kernel. This i NVD ↗ · NTAP-20240223-0002 |
CVE-2024-0727 | 2024-01-26 | MEDIUM | 5.5 | Issue summary: Processing a maliciously formatted PKCS12 file may lead OpenSSL to crash leading to a potential Denial of Service attack Impact summary: Applicat NVD ↗ · NTAP-20240208-0006 |
CVE-2024-0760 | 2024-07-23 | HIGH | 7.5 | A malicious client can send many DNS messages over TCP, potentially causing the server to become unstable while the attack is in progress. The server may recove NVD ↗ · NTAP-20240731-0004 |
CVE-2024-0853 | 2024-02-03 | MEDIUM | 5.3 | curl inadvertently kept the SSL session ID for connections in its cache even when the verify status (*OCSP stapling*) test failed. A subsequent transfer to the NVD ↗ · NTAP-20240307-0004 |
CVE-2024-0985 | 2024-02-08 | HIGH | 8.0 | Late privilege drop in REFRESH MATERIALIZED VIEW CONCURRENTLY in PostgreSQL allows an object creator to execute arbitrary SQL functions as the command issuer. T NVD ↗ · NTAP-20241220-0005 |
CVE-2024-10979 | 2024-11-14 | HIGH | 8.8 | Incorrect control of environment variables in PostgreSQL PL/Perl allows an unprivileged database user to change sensitive process environment variables (e.g. PA NVD ↗ · NTAP-20250110-0003 |
CVE-2024-11053 | 2024-12-11 | LOW | 3.4 | When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to hos NVD ↗ · NTAP-20250131-0003 |
CVE-2024-11168 | 2024-11-12 | LOW | 3.7 | The urllib.parse.urlsplit() and urlparse() functions improperly validated bracketed hosts (`[]`), allowing hosts that weren't IPv6 or IPvFuture. This behavior w NVD ↗ · NTAP-20250411-0004 |
CVE-2024-11187 | 2025-01-29 | HIGH | 7.5 | It is possible to construct a zone such that some queries to it will generate responses containing numerous records in the Additional section. An attacker sendi NVD ↗ · NTAP-20250207-0002 |
CVE-2024-11233 | 2024-11-24 | MEDIUM | 4.8 | In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, due to an error in convert.quoted-printable-decode filter certain data can lead t NVD ↗ · NTAP-20241220-0008 |
CVE-2024-11234 | 2024-11-24 | MEDIUM | 4.8 | In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, when using streams with configured proxy and "request_fulluri" option, the URI is NVD ↗ · NTAP-20241220-0008 |
CVE-2024-11236 | 2024-11-24 | CRITICAL | 9.8 | In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, uncontrolled long string inputs to ldap_escape() function on 32-bit systems can c NVD ↗ · NTAP-20241220-0008 |
CVE-2024-11612 | 2024-11-22 | MEDIUM | 6.5 | 7-Zip CopyCoder Infinite Loop Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected in NVD ↗ · NTAP-20251010-0001 |
CVE-2024-12243 | 2025-02-10 | MEDIUM | 5.3 | A flaw was found in GnuTLS, which relies on libtasn1 for ASN.1 data processing. Due to an inefficient algorithm in libtasn1, decoding certain DER-encoded certif NVD ↗ · NTAP-20250523-0002 |
CVE-2024-12801 | 2024-12-19 | LOW | 2.4 | Server-Side Request Forgery (SSRF) in SaxEventRecorder by QOS.CH logback version 0.1 to 1.3.14 and 1.4.0 to 1.5.12 on the Java platform, allows an attacker to f NVD ↗ · NTAP-20250704-0001 |
CVE-2024-13176 | 2025-01-20 | MEDIUM | 4.1 | Issue summary: A timing side-channel which could potentially allow recovering the private key exists in the ECDSA signature computation. Impact summary: A timin NVD ↗ · NTAP-20250124-0005 |
CVE-2024-1737 | 2024-07-23 | HIGH | 7.5 | Resolver caches and authoritative zone databases that hold significant numbers of RRs for the same hostname (of any RTYPE) can suffer from degraded performance NVD ↗ · NTAP-20240731-0003 · NTAP-20240731-0003 |
CVE-2024-1975 | 2024-07-23 | HIGH | 7.5 | If a server hosts a zone containing a "KEY" Resource Record, or a resolver DNSSEC-validates a "KEY" Resource Record from a DNSSEC-signed domain in cache, a clie NVD ↗ · NTAP-20240731-0002 |
CVE-2024-2004 | 2024-03-27 | LOW | 3.5 | When a protocol selection parameter option disables all protocols without adding any then the default set of protocols would remain in the allowed set due to an NVD ↗ · NTAP-20240524-0006 |
CVE-2024-21982 | 2024-01-12 | MEDIUM | 4.8 | ONTAP versions 9.4 and higher are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information to unprivil NVD ↗ · NTAP-20240111-0001 |
CVE-2024-21985 | 2024-01-26 | HIGH | 7.6 | ONTAP 9 versions prior to 9.9.1P18, 9.10.1P16, 9.11.1P13, 9.12.1P10 and 9.13.1P4 are susceptible to a vulnerability which could allow an authenticated user with NVD ↗ · NTAP-20240126-0001 |
CVE-2024-21989 | 2024-04-17 | HIGH | 8.1 | ONTAP Select Deploy administration utility versions 9.12.1.x, 9.13.1.x and 9.14.1.x are susceptible to a vulnerability which when successfully exploited could a NVD ↗ · NTAP-20240411-0001 |
CVE-2024-21990 | 2024-04-17 | MEDIUM | 5.4 | ONTAP Select Deploy administration utility versions 9.12.1.x, 9.13.1.x and 9.14.1.x contain hard-coded credentials that could allow an attacker to view Deploy c NVD ↗ · NTAP-20240411-0002 |
CVE-2024-22257 | 2024-03-18 | HIGH | 8.2 | In Spring Security, versions 5.7.x prior to 5.7.12, 5.8.x prior to 5.8.11, versions 6.0.x prior to 6.0.9, versions 6.1.x prior to 6.1.8, versions 6.2.x prior to NVD ↗ · NTAP-20240419-0005 |
CVE-2024-2398 | 2024-03-27 | HIGH | 8.6 | When an application tells libcurl it wants to allow HTTP/2 server push, and the amount of received headers for the push surpasses the maximum allowed limit (100 NVD ↗ · NTAP-20240503-0009 |
CVE-2024-24795 | 2024-04-04 | MEDIUM | 6.3 | HTTP Response splitting in multiple modules in Apache HTTP Server allows an attacker that can inject malicious response headers into backend applications to cau NVD ↗ · NTAP-20240415-0013 |
CVE-2024-24806 | 2024-02-07 | HIGH | 7.3 | libuv is a multi-platform support library with a focus on asynchronous I/O. The `uv_getaddrinfo` function in `src/unix/getaddrinfo.c` (and its windows counterpa NVD ↗ · NTAP-20240605-0008 · NTAP-20240605-0008 |
CVE-2024-25062 | 2024-02-04 | HIGH | 7.5 | An issue was discovered in libxml2 before 2.11.7 and 2.12.x before 2.12.5. When using the XML Reader interface with DTD validation and XInclude expansion enable NVD ↗ · NTAP-20260116-0019 |
CVE-2024-2511 | 2024-04-08 | MEDIUM | 5.9 | Issue summary: Some non-default TLS server configurations can cause unbounded memory growth when processing TLSv1.3 sessions Impact summary: An attacker may exp NVD ↗ · NTAP-20240503-0013 · NTAP-20240503-0013 |
CVE-2024-26458 | 2024-02-29 | MEDIUM | 5.3 | Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c. NVD ↗ · NTAP-20240415-0010 |
CVE-2024-26461 | 2024-02-29 | HIGH | 7.5 | Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c. NVD ↗ · NTAP-20240415-0011 |
CVE-2024-26462 | 2024-02-29 | MEDIUM | 5.5 | Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/kdc/ndr.c. NVD ↗ · NTAP-20240415-0012 |
CVE-2024-26633 | 2024-03-18 | MEDIUM | 5.5 | In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: fix NEXTHDR_FRAGMENT handling in ip6_tnl_parse_tlv_enc_lim() syzbot pointed out NVD ↗ · NTAP-20241220-0001 |
CVE-2024-26641 | 2024-03-18 | HIGH | 8.6 | In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: make sure to pull inner header in __ip6_tnl_rcv() syzbot found __ip6_tnl_rcv() c NVD ↗ · NTAP-20241108-0008 |
CVE-2024-26882 | 2024-04-17 | HIGH | 7.3 | In the Linux kernel, the following vulnerability has been resolved: net: ip_tunnel: make sure to pull inner header in ip_tunnel_rcv() Apply the same fix than on NVD ↗ · NTAP-20241220-0002 |
CVE-2024-27280 | 2024-05-14 | CRITICAL | 9.8 | A buffer-overread issue was discovered in StringIO 3.0.1, as distributed in Ruby 3.0.x through 3.0.6 and 3.1.x through 3.1.4. The ungetbyte and ungetc methods o NVD ↗ · NTAP-20250502-0003 |
CVE-2024-27316 | 2024-04-04 | HIGH | 7.5 | HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a client does not stop NVD ↗ · NTAP-20240415-0013 |
CVE-2024-27398 | 2024-05-14 | HIGH | 8.0 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Fix use-after-free bugs caused by sco_sock_timeout When the sco connection is est NVD ↗ · NTAP-20240912-0012 |
CVE-2024-2756 | 2024-04-29 | MEDIUM | 6.5 | Due to an incomplete fix to CVE-2022-31629 https://github.com/advisories/GHSA-c43m-486j-j32p , network and same-site attackers can set a standard insecure cooki NVD ↗ · NTAP-20240510-0008 |
CVE-2024-28752 | 2024-03-15 | CRITICAL | 9.3 | A SSRF vulnerability using the Aegis DataBinding in versions of Apache CXF before 4.0.4, 3.6.3 and 3.5.8 allows an attacker to perform SSRF style attacks on web NVD ↗ · NTAP-20240517-0001 |
CVE-2024-28757 | 2024-03-10 | HIGH | 7.5 | libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityParserCreate). NVD ↗ · NTAP-20240322-0001 |
CVE-2024-28834 | 2024-03-21 | MEDIUM | 5.3 | A flaw was found in GnuTLS. The Minerva attack is a cryptographic vulnerability that exploits deterministic behavior in systems like GnuTLS, leading to side-cha NVD ↗ · NTAP-20240524-0004 · NTAP-20240524-0004 |
CVE-2024-29131 | 2024-03-21 | HIGH | 7.3 | Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: from 2.0 before 2.10.1. Users are recommended NVD ↗ · NTAP-20241213-0001 |
CVE-2024-29133 | 2024-03-21 | MEDIUM | 5.4 | Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: from 2.0 before 2.10.1. Users are recommended NVD ↗ · NTAP-20250605-0002 |
CVE-2024-2961 | 2024-04-17 | HIGH | 7.3 | The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the IS NVD ↗ · NTAP-20240531-0002 |
CVE-2024-29736 | 2024-07-19 | CRITICAL | 9.1 | A SSRF vulnerability in WADL service description in versions of Apache CXF before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform SSRF style attacks on RES NVD ↗ · NTAP-20241115-0003 |
CVE-2024-29857 | 2024-05-14 | HIGH | 7.5 | An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC Java) before 1.78, BC Java LTS before 2.73.6, BC-FJA before 1.0.2.5, and BC C# NVD ↗ · NTAP-20241206-0008 · NTAP-20241206-0008 |
CVE-2024-30171 | 2024-05-14 | MEDIUM | 5.9 | An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of exception NVD ↗ · NTAP-20240614-0008 |
CVE-2024-32007 | 2024-07-19 | HIGH | 7.5 | An improper input validation of the p2c parameter in the Apache CXF JOSE code before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform a denial of service at NVD ↗ · NTAP-20240808-0009 |
CVE-2024-34750 | 2024-07-03 | HIGH | 7.5 | Improper Handling of Exceptional Conditions, Uncontrolled Resource Consumption vulnerability in Apache Tomcat. When processing an HTTP/2 stream, Tomcat did not NVD ↗ · NTAP-20240816-0004 · NTAP-20240816-0004 |
CVE-2024-35890 | 2024-05-19 | HIGH | 7.8 | In the Linux kernel, the following vulnerability has been resolved: gro: fix ownership transfer If packets are GROed with fraglist they might be segmented later NVD ↗ · NTAP-20250509-0008 |
CVE-2024-35896 | 2024-05-19 | HIGH | 7.1 | In the Linux kernel, the following vulnerability has been resolved: netfilter: validate user input for expected length I got multiple syzbot reports showing old NVD ↗ · NTAP-20250321-0004 |
CVE-2024-36387 | 2024-07-01 | MEDIUM | 5.4 | Serving WebSocket protocol upgrades over a HTTP/2 connection could result in a Null Pointer dereference, leading to a crash of the server process, degrading per NVD ↗ · NTAP-20240712-0001 |
CVE-2024-36883 | 2024-05-30 | HIGH | 7.8 | In the Linux kernel, the following vulnerability has been resolved: net: fix out-of-bounds access in ops_init net_alloc_generic is called by net_alloc, which is NVD ↗ · NTAP-20241018-0001 |
CVE-2024-36886 | 2024-05-30 | CRITICAL | 9.8 | In the Linux kernel, the following vulnerability has been resolved: tipc: fix UAF in error path Sam Page (sam4k) working with Trend Micro Zero Day Initiative re NVD ↗ · NTAP-20241018-0002 |
CVE-2024-36905 | 2024-05-30 | MEDIUM | 5.5 | In the Linux kernel, the following vulnerability has been resolved: tcp: defer shutdown(SEND_SHUTDOWN) for TCP_SYN_RECV sockets TCP_SYN_RECV state is really spe NVD ↗ · NTAP-20240905-0005 |
CVE-2024-36929 | 2024-05-30 | HIGH | 7.5 | In the Linux kernel, the following vulnerability has been resolved: net: core: reject skb_copy(_expand) for fraglist GSO skbs SKB_GSO_FRAGLIST skbs must not be NVD ↗ · NTAP-20240905-0010 |
CVE-2024-36933 | 2024-05-30 | HIGH | 7.8 | In the Linux kernel, the following vulnerability has been resolved: nsh: Restore skb->{protocol,data,mac_header} for outer header in nsh_gso_segment(). syzbot t NVD ↗ · NTAP-20240912-0006 |
CVE-2024-36945 | 2024-05-30 | HIGH | 7.5 | In the Linux kernel, the following vulnerability has been resolved: net/smc: fix neighbour and rtable leak in smc_ib_find_route() In smc_ib_find_route(), the ne NVD ↗ · NTAP-20250404-0006 |
CVE-2024-37370 | 2024-06-28 | HIGH | 7.5 | In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can modify the plaintext Extra Count field of a confidential GSS krb5 wrap token, causing the unwrapped NVD ↗ · NTAP-20241108-0007 |
CVE-2024-37371 | 2024-06-28 | CRITICAL | 9.1 | In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can cause invalid memory reads during GSS message token handling by sending message tokens with invalid NVD ↗ · NTAP-20241108-0009 |
CVE-2024-38428 | 2024-06-16 | CRITICAL | 9.1 | url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be insecure behavior in which data that was sup NVD ↗ · NTAP-20241115-0005 · NTAP-20241115-0005 |
CVE-2024-38472 | 2024-07-01 | HIGH | 7.5 | SSRF in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or content Users are recommen NVD ↗ · NTAP-20240712-0001 |
CVE-2024-38473 | 2024-07-01 | HIGH | 8.1 | Encoding problem in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows request URLs with incorrect encoding to be sent to backend services, potentially b NVD ↗ · NTAP-20240712-0001 |
CVE-2024-38474 | 2024-07-01 | CRITICAL | 9.8 | Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in directories permitted by the configura NVD ↗ · NTAP-20240712-0001 |
CVE-2024-38475 | 2024-07-01 | CRITICAL | 9.1 | Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are permitted to NVD ↗ · NTAP-20240712-0001 |
CVE-2024-38476 | 2024-07-01 | CRITICAL | 9.8 | Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications NVD ↗ · NTAP-20240712-0001 |
CVE-2024-38477 | 2024-07-01 | HIGH | 7.5 | null pointer dereference in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows an attacker to crash the server via a malicious request. Users are recomme NVD ↗ · NTAP-20240712-0001 |
CVE-2024-38809 | 2024-09-27 | MEDIUM | 5.3 | Applications that parse ETags from "If-Match" or "If-None-Match" request headers are vulnerable to DoS attack. Users of affected versions should upgrade to the NVD ↗ · NTAP-20240920-0003 |
CVE-2024-38820 | 2024-10-18 | LOW | 3.1 | The fix for CVE-2022-22968 made disallowedFields patterns in DataBinder case insensitive. However, String.toLowerCase() has some Locale dependent exceptions tha NVD ↗ · NTAP-20241129-0003 |
CVE-2024-39573 | 2024-07-01 | HIGH | 7.5 | Potential SSRF in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to cause unsafe RewriteRules to unexpectedly setup URL's to be handled NVD ↗ · NTAP-20240712-0001 |
CVE-2024-39689 | 2024-07-05 | HIGH | 7.5 | Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi s NVD ↗ · NTAP-20241206-0001 |
CVE-2024-39884 | 2024-07-04 | MEDIUM | 6.2 | A regression in the core of Apache HTTP Server 2.4.60 ignores some use of the legacy content-type based configuration of handlers. "AddType" and similar configu NVD ↗ · NTAP-20240712-0002 |
CVE-2024-4032 | 2024-06-17 | HIGH | 7.5 | The “ipaddress” module contained incorrect information about whether certain IPv4 and IPv6 addresses were designated as “globally reachable” or “private”. This NVD ↗ · NTAP-20240726-0004 |
CVE-2024-40725 | 2024-07-18 | MEDIUM | 5.3 | A partial fix for CVE-2024-39884 in the core of Apache HTTP Server 2.4.61 ignores some use of the legacy content-type based configuration of handlers. "AddType" NVD ↗ · NTAP-20240808-0007 |
CVE-2024-4076 | 2024-07-23 | HIGH | 7.5 | Client queries that trigger serving stale data and that also require lookups in local authoritative zone data may result in an assertion failure. This issue aff NVD ↗ · NTAP-20240731-0001 |
CVE-2024-41996 | 2024-08-26 | HIGH | 7.5 | Validating the order of the public keys in the Diffie-Hellman Key Agreement Protocol, when an approved safe prime is used, allows remote attackers (from the cli NVD ↗ · NTAP-20260227-0009 |
CVE-2024-42154 | 2024-07-30 | MEDIUM | 4.4 | In the Linux kernel, the following vulnerability has been resolved: tcp_metrics: validate source addr length I don't see anything checking that TCP_METRICS_ATTR NVD ↗ · NTAP-20240828-0010 |
CVE-2024-42256 | 2024-08-08 | HIGH | 7.5 | In the Linux kernel, the following vulnerability has been resolved: cifs: Fix server re-repick on subrequest retry When a subrequest is marked for needing retry NVD ↗ · NTAP-20250627-0004 |
CVE-2024-42516 | 2025-07-10 | HIGH | 7.5 | HTTP response splitting in the core of Apache HTTP Server allows an attacker who can manipulate the Content-Type response headers of applications hosted or prox NVD ↗ · NTAP-20250718-0013 |
CVE-2024-43204 | 2025-07-10 | HIGH | 7.5 | SSRF in Apache HTTP Server with mod_proxy loaded allows an attacker to send outbound proxy requests to a URL controlled by the attacker. Requires an unlikely co NVD ↗ · NTAP-20250718-0013 |
CVE-2024-43394 | 2025-07-10 | HIGH | 7.5 | Server-Side Request Forgery (SSRF) in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via mod_rewrite or apache expre NVD ↗ · NTAP-20250718-0013 |
CVE-2024-45287 | 2024-09-05 | HIGH | 7.5 | A malicious value of size in a structure of packed libnv can cause an integer overflow, leading to the allocation of a smaller buffer than required for the pars NVD ↗ · NTAP-20240926-0010 |
CVE-2024-45288 | 2024-09-05 | HIGH | 8.4 | A missing null-termination character in the last element of an nvlist array string can lead to writing outside the allocated buffer. NVD ↗ · NTAP-20240920-0008 |
CVE-2024-45490 | 2024-08-30 | HIGH | 7.5 | An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a negative length for XML_ParseBuffer. NVD ↗ · NTAP-20241018-0004 |
CVE-2024-4603 | 2024-05-16 | MEDIUM | 5.3 | Issue summary: Checking excessively long DSA keys or parameters may be very slow. Impact summary: Applications that use the functions EVP_PKEY_param_check() or NVD ↗ · NTAP-20240621-0001 |
CVE-2024-47252 | 2025-07-10 | HIGH | 7.5 | Insufficient escaping of user-supplied data in mod_ssl in Apache HTTP Server 2.4.63 and earlier allows an untrusted SSL/TLS client to insert escape characters i NVD ↗ · NTAP-20250718-0013 |
CVE-2024-4741 | 2024-11-13 | HIGH | 7.5 | Issue summary: Calling the OpenSSL API function SSL_free_buffers may cause memory to be accessed that was previously freed in some situations Impact summary: A NVD ↗ · NTAP-20240621-0004 |
CVE-2024-47554 | 2024-10-03 | MEDIUM | 4.3 | Uncontrolled Resource Consumption vulnerability in Apache Commons IO. The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resource NVD ↗ · NTAP-20250131-0010 |
CVE-2024-47685 | 2024-10-21 | CRITICAL | 9.1 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_reject_ipv6: fix nf_reject_ip6_tcphdr_put() syzbot reported that nf_reject_ip6 NVD ↗ · NTAP-20250613-0011 |
CVE-2024-47693 | 2024-10-21 | MEDIUM | 6.5 | In the Linux kernel, the following vulnerability has been resolved: IB/core: Fix ib_cache_setup_one error flow cleanup When ib_cache_update return an error, we NVD ↗ · NTAP-20250627-0002 |
CVE-2024-47850 | 2024-10-04 | HIGH | 7.5 | CUPS cups-browsed before 2.5b1 will send an HTTP POST request to an arbitrary destination and port in response to a single IPP UDP packet requesting a printer t NVD ↗ · NTAP-20241011-0002 |
CVE-2024-49997 | 2024-10-21 | HIGH | 7.5 | In the Linux kernel, the following vulnerability has been resolved: net: ethernet: lantiq_etop: fix memory disclosure When applying padding, the buffer is not z NVD ↗ · NTAP-20250627-0005 |
CVE-2024-50083 | 2024-10-29 | HIGH | 7.5 | In the Linux kernel, the following vulnerability has been resolved: tcp: fix mptcp DSS corruption due to large pmtu xmit Syzkaller was able to trigger a DSS cor NVD ↗ · NTAP-20250523-0010 |
CVE-2024-52533 | 2024-11-11 | CRITICAL | 9.8 | gio/gsocks4aproxy.c in GNOME GLib before 2.82.1 has an off-by-one error and resultant buffer overflow because SOCKS4_CONN_MSG_LEN is not sufficient for a traili NVD ↗ · NTAP-20241206-0009 |
CVE-2024-53580 | 2024-12-18 | HIGH | 7.5 | iperf v3.17.1 was discovered to contain a segmentation violation via the iperf_exchange_parameters() function. NVD ↗ · NTAP-20250404-0009 |
CVE-2024-5458 | 2024-06-09 | MEDIUM | 5.3 | In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, due to a code logic error, filtering functions such as filter_var when validating NVD ↗ · NTAP-20240726-0001 |
CVE-2024-5535 | 2024-06-27 | CRITICAL | 9.1 | Issue summary: Calling the OpenSSL API function SSL_select_next_proto with an empty supported client protocols buffer may cause a crash or memory contents to be NVD ↗ · NTAP-20240712-0005 |
CVE-2024-56171 | 2025-02-18 | HIGH | 7.8 | libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlschemas.c. To exploit NVD ↗ · NTAP-20250328-0010 |
CVE-2024-6119 | 2024-09-03 | HIGH | 7.5 | Issue summary: Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address re NVD ↗ · NTAP-20240912-0001 |
CVE-2024-6232 | 2024-09-03 | HIGH | 7.5 | There is a MEDIUM severity vulnerability affecting CPython. Regular expressions that allowed excessive backtracking during tarfile.TarFile header parsing are vu NVD ↗ · NTAP-20241018-0007 |
CVE-2024-6387 | 2024-07-01 | HIGH | 8.1 | A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsa NVD ↗ · NTAP-20240701-0001 |
CVE-2024-6409 | 2024-07-08 | HIGH | 7.0 | A race condition vulnerability was discovered in how signals are handled by OpenSSH's server (sshd). If a remote attacker does not authenticate within a set tim NVD ↗ · NTAP-20240712-0003 |
CVE-2024-6763 | 2024-10-14 | LOW | 3.7 | Eclipse Jetty is a lightweight, highly scalable, Java-based web server and Servlet engine . It includes a utility class, HttpURI, for URI/URL parsing. The HttpU NVD ↗ · NTAP-20250306-0005 |
CVE-2024-6923 | 2024-08-01 | MEDIUM | 5.5 | There is a MEDIUM severity vulnerability affecting CPython. The email module didn’t properly quote newlines for email headers when serializing an email message NVD ↗ · NTAP-20240926-0003 |
CVE-2024-7006 | 2024-08-12 | HIGH | 7.5 | A null pointer dereference flaw was found in Libtiff via `tif_dirinfo.c`. This issue may allow an attacker to trigger memory allocation failures through certain NVD ↗ · NTAP-20240920-0001 |
CVE-2024-7254 | 2024-09-19 | HIGH | 7.5 | Any project that parses untrusted Protocol Buffers data containing an arbitrary number of nested groups / series of SGROUP tags can corrupted by exceeding the s NVD ↗ · NTAP-20241213-0010 |
CVE-2024-7264 | 2024-07-31 | MEDIUM | 6.5 | libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an ASN.1 Generalized Time field. If given an syntactically incorrect field, the pars NVD ↗ · NTAP-20240828-0008 |
CVE-2024-7592 | 2024-08-19 | HIGH | 7.5 | There is a LOW severity vulnerability affecting CPython, specifically the 'http.cookies' standard library module. When parsing cookies that contained backslashe NVD ↗ · NTAP-20241018-0006 |
CVE-2024-8088 | 2024-08-22 | HIGH | 8.7 | There is a HIGH severity vulnerability affecting the CPython "zipfile" module affecting "zipfile.Path". Note that the more common API "zipfile.ZipFile" class is NVD ↗ · NTAP-20241011-0010 |
CVE-2024-8096 | 2024-09-11 | MEDIUM | 6.5 | When curl is told to use the Certificate Status Request TLS extension, often referred to as OCSP stapling, to verify that the server certificate is valid, it mi NVD ↗ · NTAP-20241011-0005 |
CVE-2024-8176 | 2025-03-14 | HIGH | 7.5 | A stack overflow vulnerability exists in the libexpat library due to the way it handles recursive entity expansion in XML documents. When parsing an XML documen NVD ↗ · NTAP-20250328-0009 |
CVE-2024-8925 | 2024-10-08 | LOW | 3.1 | In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, erroneous parsing of multipart form data contained in an HTTP POST request could NVD ↗ · NTAP-20241101-0003 |
CVE-2024-8926 | 2024-10-08 | HIGH | 8.1 | In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, when using a certain non-standard configurations of Windows codepages, the fixes NVD ↗ · NTAP-20241101-0003 |
CVE-2024-8927 | 2024-10-08 | HIGH | 7.5 | In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, HTTP_REDIRECT_STATUS variable is used to check whether or not CGI binary is being NVD ↗ · NTAP-20241101-0003 |
CVE-2024-8932 | 2024-11-22 | CRITICAL | 9.8 | In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, uncontrolled long string inputs to ldap_escape() function on 32-bit systems can c NVD ↗ · NTAP-20250110-0009 |
CVE-2024-9026 | 2024-10-08 | LOW | 3.3 | In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, when using PHP-FPM SAPI and it is configured to catch workers output through catc NVD ↗ · NTAP-20241101-0003 |
CVE-2024-9143 | 2024-10-16 | MEDIUM | 4.3 | Issue summary: Use of the low-level GF(2^m) elliptic curve APIs with untrusted explicit values for the field polynomial can lead to out-of-bounds memory reads o NVD ↗ · NTAP-20241101-0001 |
CVE-2024-9287 | 2024-10-22 | HIGH | 7.8 | A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allo NVD ↗ · NTAP-20250425-0006 |
CVE-2024-9681 | 2024-11-06 | MEDIUM | 6.5 | When curl is asked to use HSTS, the expiry time for a subdomain might overwrite a parent domain's cache entry, making it end sooner or later than otherwise inte NVD ↗ · NTAP-20241213-0006 |
CVE-2025-0167 | 2025-02-05 | LOW | 3.4 | When asked to use a `.netrc` file for credentials **and** to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host NVD ↗ · NTAP-20250306-0008 |
CVE-2025-0938 | 2025-01-31 | MEDIUM | 6.3 | The Python standard library functions `urllib.parse.urlsplit` and `urlparse` accepted domain names that included square brackets which isn't valid according to NVD ↗ · NTAP-20250314-0002 |
CVE-2025-1094 | 2025-02-13 | HIGH | 8.1 | Improper neutralization of quoting syntax in PostgreSQL libpq functions PQescapeLiteral(), PQescapeIdentifier(), PQescapeString(), and PQescapeStringConn() allo NVD ↗ · NTAP-20250221-0010 |
CVE-2025-11187 | 2026-01-27 | MEDIUM | 6.1 | Issue summary: PBMAC1 parameters in PKCS#12 files are missing validation which can trigger a stack-based buffer overflow, invalid pointer or NULL pointer derefe NVD ↗ · NTAP-20260204-0012 |
CVE-2025-1180 | 2025-02-11 | LOW | 3.1 | A vulnerability classified as problematic has been found in GNU Binutils 2.43. This affects the function _bfd_elf_write_section_eh_frame of the file bfd/elf-eh- NVD ↗ · NTAP-20250814-0008 |
CVE-2025-1219 | 2025-03-30 | MEDIUM | 5.3 | In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when requesting a HTTP resource using the DOM or S NVD ↗ · NTAP-20250523-0007 |
CVE-2025-14524 | 2026-01-08 | MEDIUM | 5.3 | When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a cross-protocol redirect to a second URL that uses an IMAP, LDAP, POP3 NVD ↗ · NTAP-20260213-0015 |
CVE-2025-14847 | 2025-12-19 | HIGH | 7.5 | Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue affects all NVD ↗ · NTAP-20260102-0016 |
CVE-2025-15281 | 2026-01-20 | HIGH | 7.5 | Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cause the interface to return uninitialized NVD ↗ · NTAP-20260313-0001 |
CVE-2025-15467 | 2026-01-27 | HIGH | 8.8 | Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow. Impact summa NVD ↗ · NTAP-20260204-0011 |
CVE-2025-15468 | 2026-01-27 | MEDIUM | 5.9 | Issue summary: If an application using the SSL_CIPHER_find() function in a QUIC protocol client or server receives an unknown cipher suite from the peer, a NULL NVD ↗ · NTAP-20260204-0013 |
CVE-2025-1736 | 2025-03-30 | HIGH | 7.3 | In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when user-supplied headers are sent, the insuffici NVD ↗ · NTAP-20250523-0006 |
CVE-2025-21947 | 2025-04-01 | HIGH | 8.1 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix type confusion via race condition when using ipc_msg_send_request req->handle is NVD ↗ · NTAP-20260424-0018 |
CVE-2025-22040 | 2025-04-16 | HIGH | 8.8 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix session use-after-free in multichannel connection There is a race condition betwe NVD ↗ · NTAP-20260424-0017 |
CVE-2025-22041 | 2025-04-16 | HIGH | 8.8 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in ksmbd_sessions_deregister() In multichannel mode, UAF issue can NVD ↗ · NTAP-20260424-0016 |
CVE-2025-22871 | 2025-04-08 | CRITICAL | 9.1 | The net/http package improperly accepts a bare LF as a line terminator in chunked data chunk-size lines. This can permit request smuggling if a net/http server NVD ↗ · NTAP-20250530-0004 |
CVE-2025-23048 | 2025-07-10 | CRITICAL | 9.1 | In some mod_ssl configurations on Apache HTTP Server 2.4.35 through to 2.4.63, an access control bypass by trusted clients is possible using TLS 1.3 session res NVD ↗ · NTAP-20250718-0013 |
CVE-2025-23184 | 2025-01-21 | MEDIUM | 5.9 | A potential denial of service vulnerability is present in versions of Apache CXF before 3.5.10, 3.6.5 and 4.0.6. In some edge cases, the CachedOutputStream inst NVD ↗ · NTAP-20250214-0003 |
CVE-2025-2336 | 2025-06-04 | MEDIUM | 4.8 | Improper sanitization of the value of the 'href' and 'xlink:href' attributes in '<image>' SVG elements in AngularJS's 'ngSanitize' module allows attackers to by NVD ↗ · NTAP-20251128-0015 |
CVE-2025-24296 | 2025-08-12 | MEDIUM | 6.0 | Improper input validation in some firmware for the Intel(R) E810 Ethernet before version 4.6 may allow a privileged user to enable denial of service via local a NVD ↗ · NTAP-20260109-0004 |
CVE-2025-24851 | 2026-02-10 | MEDIUM | 6.0 | Uncaught exception in the firmware for some 100GbE Intel(R) Ethernet Controller E810 before version cvl fw 1.7.8.x within Ring 0: Bare Metal OS may allow a deni NVD ↗ · NTAP-20260313-0014 |
CVE-2025-24928 | 2025-02-18 | HIGH | 7.8 | libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a stack-based buffer overflow in xmlSnprintfElements in valid.c. To exploit this, DTD validation must occur NVD ↗ · NTAP-20250321-0006 |
CVE-2025-26465 | 2025-02-18 | MEDIUM | 6.8 | A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine imperso NVD ↗ · NTAP-20250228-0003 |
CVE-2025-26466 | 2025-02-28 | MEDIUM | 5.9 | A flaw was found in the OpenSSH package. For each ping packet the SSH server receives, a pong packet is allocated in a memory buffer and stored in a queue of pa NVD ↗ · NTAP-20250228-0002 |
CVE-2025-27113 | 2025-02-18 | LOW | 2.9 | libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a NULL pointer dereference in xmlPatMatch in pattern.c. NVD ↗ · NTAP-20250306-0004 |
CVE-2025-27243 | 2026-02-10 | MEDIUM | 6.0 | Out-of-bounds write in the firmware for some Intel(R) Ethernet Controller E810 before version cvl fw 1.7.8.x within Ring 0: Bare Metal OS may allow a denial of NVD ↗ · NTAP-20260313-0014 |
CVE-2025-27363 | 2025-03-11 | HIGH | 8.1 | An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when attempting to parse font subglyph struc NVD ↗ · NTAP-20250613-0008 |
CVE-2025-27535 | 2026-02-10 | MEDIUM | 5.3 | Exposed ioctl with insufficient access control in the firmware for some Intel(R) Ethernet Connection E825-C. before version NVM ver. 3.84 within Ring 0: Bare Me NVD ↗ · NTAP-20260313-0014 |
CVE-2025-27558 | 2025-05-21 | CRITICAL | 9.1 | IEEE P802.11-REVme D1.1 through D7.0 allows FragAttacks against mesh networks. In mesh networks using Wi-Fi Protected Access (WPA, WPA2, or WPA3) or Wired Equiv NVD ↗ · NTAP-20260116-0017 |
CVE-2025-27820 | 2025-04-24 | HIGH | 7.5 | A bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks, affecting cookie management and host name verification. Discovered by the Apach NVD ↗ · NTAP-20250516-0003 |
CVE-2025-2884 | 2025-06-10 | MEDIUM | 6.6 | TCG TPM2.0 Reference implementation's CryptHmacSign helper function is vulnerable to Out-of-Bounds read due to the lack of validation the signature scheme with NVD ↗ · NTAP-20250620-0007 |
CVE-2025-30211 | 2025-03-28 | HIGH | 7.5 | Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.1, 26.2.5.10, and 25.3.2.19, a maliciously formed KEX init mess NVD ↗ · NTAP-20250530-0006 |
CVE-2025-31115 | 2025-04-03 | HIGH | 8.7 | XZ Utils provide a general-purpose data-compression library plus command-line tools. In XZ Utils 5.3.3alpha to 5.8.0, the multithreaded .xz decoder in liblzma h NVD ↗ · NTAP-20250530-0001 |
CVE-2025-31133 | 2025-11-06 | HIGH | 7.8 | runc is a CLI tool for spawning and running containers according to the OCI specification. In versions 1.2.7 and below, 1.3.0-rc.1 through 1.3.1, 1.4.0-rc.1 and NVD ↗ · NTAP-20251121-0001 |
CVE-2025-32003 | 2026-02-10 | MEDIUM | 6.5 | Out-of-bounds read in the firmware for some 100GbE Intel(R) Ethernet Network Adapter E810 before version cvl fw 1.7.6, cpk 1.3.7 within Ring 0: Bare Metal OS ma NVD ↗ · NTAP-20260313-0014 |
CVE-2025-32415 | 2025-04-17 | LOW | 2.9 | In libxml2 before 2.13.8 and 2.14.x before 2.14.2, xmlSchemaIDCFillNodeTables in xmlschemas.c has a heap-based buffer under-read. To exploit this, a crafted XML NVD ↗ · NTAP-20250605-0003 · NTAP-20250605-0003 |
CVE-2025-32988 | 2025-07-10 | MEDIUM | 6.5 | A flaw was found in GnuTLS. A double-free vulnerability exists in GnuTLS due to incorrect ownership handling in the export logic of Subject Alternative Name (SA NVD ↗ · NTAP-20250725-0009 |
CVE-2025-37924 | 2025-05-20 | CRITICAL | 9.8 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in kerberos authentication Setting sess->user = NULL was introduce NVD ↗ · NTAP-20260424-0011 |
CVE-2025-37997 | 2025-05-29 | HIGH | 7.8 | In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: fix region locking in hash types Region locking introduced in v5.6-rc4 con NVD ↗ · NTAP-20251128-0011 |
CVE-2025-38732 | 2025-09-05 | MEDIUM | 5.5 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_reject: don't leak dst refcount for loopback packets recent patches to add a W NVD ↗ · NTAP-20260123-0006 |
CVE-2025-39823 | 2025-09-16 | HIGH | 7.8 | In the Linux kernel, the following vulnerability has been resolved: KVM: x86: use array_index_nospec with indices that come from guest min and dest_id are guest NVD ↗ · NTAP-20251224-0012 |
CVE-2025-39828 | 2025-09-16 | HIGH | 7.8 | In the Linux kernel, the following vulnerability has been resolved: atm: atmtcp: Prevent arbitrary write in atmtcp_recv_control(). syzbot reported the splat bel NVD ↗ · NTAP-20251224-0013 |
CVE-2025-39942 | 2025-10-04 | HIGH | 7.5 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: smbdirect: verify remaining_data_length respects max_fragmented_recv_size This is ins NVD ↗ · NTAP-20260123-0004 |
CVE-2025-39946 | 2025-10-04 | CRITICAL | 9.8 | In the Linux kernel, the following vulnerability has been resolved: tls: make sure to abort the stream if headers are bogus Normally we wait for the socket to b NVD ↗ · NTAP-20260121-0010 |
CVE-2025-39973 | 2025-10-15 | HIGH | 8.8 | In the Linux kernel, the following vulnerability has been resolved: i40e: add validation for ring_len param The `ring_len` parameter provided by the virtual fun NVD ↗ · NTAP-20260213-0016 |
CVE-2025-40027 | 2025-10-28 | HIGH | 7.8 | In the Linux kernel, the following vulnerability has been resolved: net/9p: fix double req put in p9_fd_cancelled Syzkaller reports a KASAN issue as below: gene NVD ↗ · NTAP-20260123-0005 |
CVE-2025-4516 | 2025-05-15 | MEDIUM | 5.9 | There is an issue in CPython when using `bytes.decode("unicode_escape", error="ignore|replace")`. If you are not using the "unicode_escape" encoding or an error NVD ↗ · NTAP-20250711-0004 |
CVE-2025-48988 | 2025-06-16 | HIGH | 7.5 | Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1. NVD ↗ · NTAP-20251114-0003 |
CVE-2025-48989 | 2025-08-13 | HIGH | 7.5 | Improper Resource Shutdown or Release vulnerability in Apache Tomcat made Tomcat vulnerable to the made you reset attack. This issue affects Apache Tomcat: from NVD ↗ · NTAP-20250822-0010 |
CVE-2025-4947 | 2025-05-28 | MEDIUM | 6.5 | libcurl accidentally skips the certificate verification for QUIC connections when connecting to a host specified as an IP address in the URL. Therefore, it does NVD ↗ · NTAP-20250620-0009 |
CVE-2025-49630 | 2025-07-10 | HIGH | 7.5 | In certain proxy configurations, a denial of service attack against Apache HTTP Server versions 2.4.26 through to 2.4.63 can be triggered by untrusted clients c NVD ↗ · NTAP-20250718-0013 |
CVE-2025-49812 | 2025-07-10 | HIGH | 7.4 | In some mod_ssl configurations on Apache HTTP Server versions through to 2.4.63, an HTTP desynchronisation attack allows a man-in-the-middle attacker to hijack NVD ↗ · NTAP-20250718-0013 |
CVE-2025-5025 | 2025-05-28 | MEDIUM | 4.8 | libcurl supports *pinning* of the server certificate public key for HTTPS transfers. Due to an omission, this check is not performed when connecting with QUIC f NVD ↗ · NTAP-20250620-0008 |
CVE-2025-52565 | 2025-11-06 | HIGH | 7.5 | runc is a CLI tool for spawning and running containers according to the OCI specification. Versions 1.0.0-rc3 through 1.2.7, 1.3.0-rc.1 through 1.3.2, and 1.4.0 NVD ↗ · NTAP-20251121-0002 |
CVE-2025-52881 | 2025-11-06 | HIGH | 7.5 | runc is a CLI tool for spawning and running containers according to the OCI specification. In versions 1.2.7, 1.3.2 and 1.4.0-rc.2, an attacker can trick runc i NVD ↗ · NTAP-20251121-0003 |
CVE-2025-53020 | 2025-07-10 | HIGH | 7.5 | Late Release of Memory after Effective Lifetime vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: from 2.4.17 up to 2.4.63. Users are NVD ↗ · NTAP-20250718-0013 |
CVE-2025-58183 | 2025-10-29 | MEDIUM | 4.3 | tar.Reader does not set a maximum size on the number of sparse region data blocks in GNU tar pax 1.0 sparse files. A maliciously-crafted archive containing a la NVD ↗ · NTAP-20260703-0007 |
CVE-2025-58185 | 2025-10-29 | MEDIUM | 5.3 | Parsing a maliciously crafted DER payload could allocate large amounts of memory, causing memory exhaustion. NVD ↗ · NTAP-20260703-0007 |
CVE-2025-58186 | 2025-10-29 | MEDIUM | 5.3 | Despite HTTP headers having a default limit of 1MB, the number of cookies that can be parsed does not have a limit. By sending a lot of very small cookies such NVD ↗ · NTAP-20260703-0007 |
CVE-2025-58187 | 2025-10-29 | HIGH | 7.5 | Due to the design of the name constraint checking algorithm, the processing time of some inputs scale non-linearly with respect to the size of the certificate. NVD ↗ · NTAP-20260612-0003 |
CVE-2025-58188 | 2025-10-29 | HIGH | 7.5 | Validating certificate chains which contain DSA public keys can cause programs to panic, due to a interface cast that assumes they implement the Equal method. T NVD ↗ · NTAP-20260703-0007 |
CVE-2025-58189 | 2025-10-29 | MEDIUM | 5.3 | When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the client) which is not escape NVD ↗ · NTAP-20260703-0007 |
CVE-2025-6020 | 2025-06-17 | HIGH | 7.8 | A flaw was found in linux-pam. The module pam_namespace may use access user-controlled paths without proper protection, allowing local users to elevate their pr NVD ↗ · NTAP-20260403-0005 |
CVE-2025-6021 | 2025-06-12 | HIGH | 7.5 | A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue NVD ↗ · NTAP-20250711-0009 |
CVE-2025-61723 | 2025-10-29 | HIGH | 7.5 | The processing time for parsing some invalid inputs scales non-linearly with respect to the size of the input. This affects programs which parse untrusted PEM i NVD ↗ · NTAP-20260703-0007 |
CVE-2025-61724 | 2025-10-29 | MEDIUM | 5.3 | The Reader.ReadResponse function constructs a response string through repeated string concatenation of lines. When the number of lines in a response is large, t NVD ↗ · NTAP-20260703-0007 |
CVE-2025-61725 | 2025-10-29 | HIGH | 7.5 | The ParseAddress function constructs domain-literal address components through repeated string concatenation. When parsing large domain-literal components, this NVD ↗ · NTAP-20260703-0007 |
CVE-2025-61726 | 2026-01-28 | HIGH | 7.5 | The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query parameters in URLs is generally limited b NVD ↗ · NTAP-20260311-0009 |
CVE-2025-61727 | 2025-12-03 | MEDIUM | 6.5 | An excluded subdomain constraint in a certificate chain does not restrict the usage of wildcard SANs in the leaf certificate. For example a constraint that excl NVD ↗ · NTAP-20260130-0003 |
CVE-2025-61728 | 2026-01-28 | MEDIUM | 6.5 | archive/zip uses a super-linear file name indexing algorithm that is invoked the first time a file in an archive is opened. This can lead to a denial of service NVD ↗ · NTAP-20260703-0006 |
CVE-2025-61729 | 2025-12-02 | HIGH | 7.5 | Within HostnameError.Error(), when constructing an error string, there is no limit to the number of hosts that will be printed out. Furthermore, the error strin NVD ↗ · NTAP-20260130-0002 |
CVE-2025-61730 | 2026-01-28 | MEDIUM | 5.3 | During the TLS 1.3 handshake if multiple messages are sent in records that span encryption level boundaries (for instance the Client Hello and Encrypted Extensi NVD ↗ · NTAP-20260703-0006 |
CVE-2025-61731 | 2026-01-28 | HIGH | 7.8 | Building a malicious file with cmd/go can cause can cause a write to an attacker-controlled file with partial control of the file content. The "#cgo pkg-config: NVD ↗ · NTAP-20260703-0006 |
CVE-2025-6395 | 2025-07-10 | MEDIUM | 6.5 | A NULL pointer dereference flaw was found in the GnuTLS software in _gnutls_figure_common_ciphersuite(). NVD ↗ · NTAP-20250725-0007 |
CVE-2025-64506 | 2025-11-25 | MEDIUM | 6.1 | LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From version 1.6.0 t NVD ↗ · NTAP-20260116-0005 |
CVE-2025-66035 | 2025-11-26 | HIGH | 7.7 | Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to versions 19.2.16, 2 NVD ↗ · NTAP-20251224-0007 |
CVE-2025-66199 | 2026-01-27 | MEDIUM | 5.9 | Issue summary: A TLS 1.3 connection using certificate compression can be forced to allocate a large buffer before decompression without checking against the con NVD ↗ · NTAP-20260204-0015 |
CVE-2025-66412 | 2025-12-01 | MEDIUM | 5.4 | Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 21.0.2, 20.3.15, an NVD ↗ · NTAP-20251224-0006 |
CVE-2025-66418 | 2025-12-05 | HIGH | 7.5 | urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.24 and prior to 2.6.0, the number of links in the decompression chain was unbou NVD ↗ · NTAP-20251224-0008 |
CVE-2025-66471 | 2025-12-05 | HIGH | 7.5 | urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.0 and prior to 2.6.0, the Streaming API improperly handles highly compressed da NVD ↗ · NTAP-20251224-0009 |
CVE-2025-68119 | 2026-01-28 | HIGH | 7.0 | Downloading and building modules with malicious version strings can cause local code execution. On systems with Mercurial (hg) installed, downloading modules fr NVD ↗ · NTAP-20260703-0006 |
CVE-2025-69419 | 2026-01-27 | HIGH | 7.4 | Issue summary: Calling PKCS12_get_friendlyname() function on a maliciously crafted PKCS#12 file with a BMPString (UTF-16BE) friendly name containing non-ASCII B NVD ↗ · NTAP-20260204-0008 |
CVE-2025-69420 | 2026-01-27 | HIGH | 7.5 | Issue summary: A type confusion vulnerability exists in the TimeStamp Response verification code where an ASN1_TYPE union member is accessed without first valid NVD ↗ · NTAP-20260204-0006 |
CVE-2025-7425 | 2025-07-10 | HIGH | 7.8 | A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management. When XSLT functions, such as NVD ↗ · NTAP-20260116-0014 |
CVE-2025-8885 | 2025-08-12 | MEDIUM | 6.3 | Allocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc. BC Java bcprov on All (API modules), Legion of the Bouncy NVD ↗ · NTAP-20250912-0012 |
CVE-2025-8916 | 2025-08-13 | MEDIUM | 6.3 | Allocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc. BC Java bcpkix on All (API modules), Legion of the Bouncy NVD ↗ · NTAP-20250912-0011 |
CVE-2025-8941 | 2025-08-13 | HIGH | 7.8 | A flaw was found in linux-pam. The pam_namespace module may improperly handle user-controlled paths, allowing local users to exploit symlink attacks and race co NVD ↗ · NTAP-20260403-0006 |
CVE-2025-9086 | 2025-09-12 | HIGH | 7.5 | 1. A cookie is set using the `secure` keyword for `https://target` 2. curl is redirected to or otherwise made to speak with `http://target` (same hostname, but NVD ↗ · NTAP-20251031-0007 |
CVE-2025-9230 | 2025-09-30 | HIGH | 7.5 | Issue summary: An application trying to decrypt CMS messages encrypted using password based encryption can trigger an out-of-bounds read and write. Impact summa NVD ↗ · NTAP-20251003-0011 |
CVE-2025-9714 | 2025-09-10 | MEDIUM | 6.2 | Uncontrolled recursion in XPath evaluation in libxml2 up to and including version 2.9.14 allows a local attacker to cause a stack overflow via crafted expressio NVD ↗ · NTAP-20260320-0006 |
CVE-2026-0603 | 2026-01-23 | HIGH | 8.3 | A flaw was found in Hibernate. A remote attacker with low privileges could exploit a second-order SQL injection vulnerability by providing specially crafted, un NVD ↗ · NTAP-20260508-0018 |
CVE-2026-0915 | 2026-01-15 | HIGH | 7.5 | Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend for networks and queries for a zero-valued netwo NVD ↗ · NTAP-20260313-0003 |
CVE-2026-0964 | 2026-03-26 | MEDIUM | 6.3 | A malicious SCP server can send unexpected paths that could make the client application override local files outside of working directory. This could be misused NVD ↗ · NTAP-20260501-0015 |
CVE-2026-0965 | 2026-03-26 | LOW | 3.3 | A flaw was found in libssh where it can attempt to open arbitrary files during configuration parsing. A local attacker can exploit this by providing a malicious NVD ↗ · NTAP-20260501-0015 |
CVE-2026-0966 | 2026-03-26 | HIGH | 8.2 | A flaw was found in libssh. The API function `ssh_get_hexa()` is vulnerable to a denial of service when processing zero-length input. This can be exploited remo NVD ↗ · NTAP-20260501-0015 |
CVE-2026-0967 | 2026-03-26 | MEDIUM | 5.5 | A flaw was found in libssh. A remote attacker, by controlling client configuration files or known_hosts files, could craft specific hostnames that when processe NVD ↗ · NTAP-20260501-0015 |
CVE-2026-0968 | 2026-03-26 | LOW | 3.1 | A flaw was found in libssh in which a malicious SFTP (SSH File Transfer Protocol) server can exploit this by sending a malformed 'longname' field within an `SSH NVD ↗ · NTAP-20260501-0015 |
CVE-2026-0990 | 2026-01-15 | MEDIUM | 5.9 | A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion vulnerability occurs in the xmlCatalogXMLResolveURI function when an XML catalo NVD ↗ · NTAP-20260220-0013 |
CVE-2026-1965 | 2026-03-11 | MEDIUM | 6.5 | libcurl can in some circumstances reuse the wrong connection when asked to do an Negotiate-authenticated HTTP or HTTPS request. libcurl features a pool of recen NVD ↗ · NTAP-20260327-0002 |
CVE-2026-22049 | 2026-07-22 | HIGH | 8.8 | ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to a vulnerability related to the Relying Party ID w NVD ↗ · NTAP-20260722-0001 |
CVE-2026-22050 | 2026-01-12 | MEDIUM | 4.3 | ONTAP versions 9.16.1 prior to 9.16.1P9 and 9.17.1 prior to 9.17.1P2 with snapshot locking enabled are susceptible to a vulnerability which could allow a privil NVD ↗ · NTAP-20260112-0001 |
CVE-2026-22052 | 2026-03-05 | MEDIUM | 4.3 | ONTAP versions 9.12.1 and higher with S3 NAS buckets are susceptible to an information disclosure vulnerability. Successful exploit could allow an authenticated NVD ↗ · NTAP-20260304-0001 |
CVE-2026-22732 | 2026-03-19 | CRITICAL | 9.1 | When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility that the HTTP Headers will not be writt NVD ↗ · NTAP-20260501-0013 |
CVE-2026-22795 | 2026-01-27 | MEDIUM | 5.5 | Issue summary: An invalid or NULL pointer dereference can happen in an application processing a malformed PKCS#12 file. Impact summary: An application processin NVD ↗ · NTAP-20260204-0005 |
CVE-2026-22796 | 2026-01-27 | MEDIUM | 5.3 | Issue summary: A type confusion vulnerability exists in the signature verification of signed PKCS#7 data where an ASN1_TYPE union member is accessed without fir NVD ↗ · NTAP-20260204-0004 |
CVE-2026-22990 | 2026-01-23 | HIGH | 7.5 | In the Linux kernel, the following vulnerability has been resolved: libceph: replace overzealous BUG_ON in osdmap_apply_incremental() If the osdmap is (maliciou NVD ↗ · NTAP-20260508-0002 |
CVE-2026-22991 | 2026-01-23 | HIGH | 7.5 | In the Linux kernel, the following vulnerability has been resolved: libceph: make free_choose_arg_map() resilient to partial allocation free_choose_arg_map() ma NVD ↗ · NTAP-20260508-0006 |
CVE-2026-22992 | 2026-01-23 | HIGH | 7.5 | In the Linux kernel, the following vulnerability has been resolved: libceph: return the handler error from mon_handle_auth_done() Currently any error from ceph_ NVD ↗ · NTAP-20260508-0005 · NTAP-20260508-0005 |
CVE-2026-22998 | 2026-01-25 | HIGH | 7.5 | In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: fix NULL pointer dereferences in nvmet_tcp_build_pdu_iovec Commit efa56305908b ("n NVD ↗ · NTAP-20260424-0019 · NTAP-20260424-0019 |
CVE-2026-23098 | 2026-02-04 | HIGH | 8.8 | In the Linux kernel, the following vulnerability has been resolved: netrom: fix double-free in nr_route_frame() In nr_route_frame(), old_skb is immediately free NVD ↗ · NTAP-20260424-0015 · NTAP-20260424-0015 |
CVE-2026-23230 | 2026-02-18 | HIGH | 8.8 | In the Linux kernel, the following vulnerability has been resolved: smb: client: split cached_fid bitfields to avoid shared-byte RMW races is_open, has_lease an NVD ↗ · NTAP-20260424-0014 |
CVE-2026-23231 | 2026-03-04 | HIGH | 7.8 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix use-after-free in nf_tables_addchain() nf_tables_addchain() publis NVD ↗ · NTAP-20260320-0013 |
CVE-2026-23941 | 2026-03-13 | CRITICAL | 9.4 | Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Erlang OTP (inets httpd module) allows HTTP Request Smuggling. This vul NVD ↗ · NTAP-20260703-0005 |
CVE-2026-23942 | 2026-03-13 | MEDIUM | 5.4 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Erlang OTP (ssh_sftpd module) allows Path Traversal. This vulner NVD ↗ · NTAP-20260703-0005 |
CVE-2026-23943 | 2026-03-13 | MEDIUM | 5.3 | Improper Handling of Highly Compressed Data (Compression Bomb) vulnerability in Erlang OTP ssh (ssh_transport modules) allows Denial of Service via Resource Dep NVD ↗ · NTAP-20260703-0005 |
CVE-2026-23949 | 2026-01-20 | HIGH | 8.6 | jaraco.context, an open-source software package that provides some useful decorators and context managers, has a Zip Slip path traversal vulnerability in the `j NVD ↗ · NTAP-20260327-0011 |
CVE-2026-24880 | 2026-04-09 | HIGH | 7.5 | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Tomcat via invalid chunk extension. This issue affects NVD ↗ · NTAP-20260501-0014 |
CVE-2026-25639 | 2026-02-09 | HIGH | 7.5 | Axios is a promise based HTTP client for the browser and Node.js. Prior to versions 0.30.3 and 1.13.5, the mergeConfig function in axios crashes with a TypeErro NVD ↗ · NTAP-20260313-0010 |
CVE-2026-25679 | 2026-03-06 | HIGH | 7.5 | url.Parse insufficiently validated the host/authority component and accepted some invalid URLs. NVD ↗ · NTAP-20260422-0007 |
CVE-2026-2673 | 2026-03-13 | MEDIUM | 6.5 | Issue summary: An OpenSSL TLS 1.3 server may fail to negotiate the expected preferred key exchange group when its key exchange group configuration includes the NVD ↗ · NTAP-20260320-0015 |
CVE-2026-27135 | 2026-03-18 | HIGH | 7.5 | nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. Prior to version 1.68.1, the nghttp2 library stops reading the incoming data whe NVD ↗ · NTAP-20260717-0011 |
CVE-2026-27137 | 2026-03-06 | HIGH | 7.5 | When verifying a certificate chain which contains a certificate containing multiple email address constraints which share common local portions but different do NVD ↗ · NTAP-20260508-0020 · NTAP-20260508-0020 |
CVE-2026-27140 | 2026-04-08 | HIGH | 8.8 | SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at build time due to trust layer bypass. NVD ↗ · NTAP-20260424-0001 |
CVE-2026-27142 | 2026-03-06 | MEDIUM | 6.1 | Actions which insert URLs into the content attribute of HTML meta tags are not escaped. This can allow XSS if the meta tag also has an http-equiv attribute with NVD ↗ · NTAP-20260422-0006 |
CVE-2026-27143 | 2026-04-08 | CRITICAL | 9.8 | Arithmetic over induction variables in loops were not correctly checked for underflow or overflow. As a result, the compiler would allow for invalid indexing to NVD ↗ · NTAP-20260424-0001 |
CVE-2026-27144 | 2026-04-08 | HIGH | 7.1 | The compiler is meant to unwrap pointers which are the operands of a memory move; a no-op interface conversion prevented the compiler from making the correct de NVD ↗ · NTAP-20260424-0001 |
CVE-2026-28390 | 2026-04-07 | HIGH | 7.5 | Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen. Impact summary: Ap NVD ↗ · NTAP-20260417-0012 |
CVE-2026-29167 | 2026-06-08 | CRITICAL | 9.8 | Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67 NVD ↗ · NTAP-20260610-0001 |
CVE-2026-31402 | 2026-04-03 | CRITICAL | 9.8 | In the Linux kernel, the following vulnerability has been resolved: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache The NFSv4.0 replay cache uses a fixed 1 NVD ↗ · NTAP-20260417-0008 |
CVE-2026-32280 | 2026-04-08 | HIGH | 7.5 | During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Int NVD ↗ · NTAP-20260424-0001 |
CVE-2026-32281 | 2026-04-08 | HIGH | 7.5 | Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mappings, poss NVD ↗ · NTAP-20260424-0001 |
CVE-2026-32282 | 2026-04-08 | MEDIUM | 6.4 | On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can operate on the target of the symlink, even NVD ↗ · NTAP-20260424-0001 |
CVE-2026-32283 | 2026-04-08 | HIGH | 7.5 | If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consum NVD ↗ · NTAP-20260424-0001 |
CVE-2026-32288 | 2026-04-08 | MEDIUM | 5.5 | tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large number of sparse regions encoded in the "old NVD ↗ · NTAP-20260424-0001 |
CVE-2026-32289 | 2026-04-08 | MEDIUM | 6.1 | Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escaping of content when branches were used. A NVD ↗ · NTAP-20260424-0001 |
CVE-2026-33186 | 2026-03-20 | CRITICAL | 9.1 | gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 NVD ↗ · NTAP-20260422-0005 · NTAP-20260422-0005 |
CVE-2026-33845 | 2026-04-30 | HIGH | 7.5 | A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and r NVD ↗ · NTAP-20260724-0002 |
CVE-2026-33846 | 2026-05-04 | HIGH | 7.5 | A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS. The issue arises in merge_handshake_packet() where incomi NVD ↗ · NTAP-20260724-0002 |
CVE-2026-34180 | 2026-06-09 | HIGH | 7.5 | Issue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive element whose content exceeds 2 gigabytes in length may cause a heap buffer over-r NVD ↗ · NTAP-20260617-0009 |
CVE-2026-34181 | 2026-06-09 | HIGH | 7.4 | Issue Summary: The PKCS#12 file processing fails to perform sufficient input validation for files that use Password-Based Message Authentication Code 1 (PBMAC1) NVD ↗ · NTAP-20260617-0010 |
CVE-2026-34182 | 2026-06-09 | CRITICAL | 9.1 | Issue Summary: Cryptographic Message Services (CMS) processing fails to perform sufficient input validation on the cipher and tag length fields of AuthEnveloped NVD ↗ · NTAP-20260617-0001 |
CVE-2026-34355 | 2026-06-08 | HIGH | 7.5 | A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend. Users are recommended to upgrade to versi NVD ↗ · NTAP-20260610-0001 |
CVE-2026-34356 | 2026-06-08 | HIGH | 7.5 | Heap-based Buffer Overflow vulnerability in Apache HTTP Server with malicious backend servers and ProxyPassReverseCookie* This issue affects Apache HTTP Server: NVD ↗ · NTAP-20260610-0001 |
CVE-2026-35188 | 2026-06-09 | MEDIUM | 5.0 | Issue summary: A malicious server can exploit TLS OCSP stapling by delivering a crafted response through the status_request extension, triggering a double-free NVD ↗ · NTAP-20260617-0015 |
CVE-2026-35385 | 2026-04-02 | HIGH | 7.5 | In OpenSSH before 10.3, a file downloaded by scp may be installed setuid or setgid, an outcome contrary to some users' expectations, if the download is performe NVD ↗ · NTAP-20260417-0018 |
CVE-2026-35414 | 2026-04-02 | MEDIUM | 4.2 | OpenSSH before 10.3 mishandles the authorized_keys principals option in uncommon scenarios involving a principals list in conjunction with a Certificate Authori NVD ↗ · NTAP-20260417-0019 |
CVE-2026-35547 | 2026-04-30 | HIGH | 8.1 | When processing the header of an incoming message, libnv failed to properly validate the message size. The lack of validation allows a malicious program to writ NVD ↗ · NTAP-20260501-0002 |
CVE-2026-3783 | 2026-03-11 | MEDIUM | 5.3 | When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a redirect to a second URL, curl could leak that token to the second hos NVD ↗ · NTAP-20260327-0004 |
CVE-2026-3784 | 2026-03-11 | MEDIUM | 6.5 | curl would wrongly reuse an existing HTTP proxy connection doing CONNECT to a server, even if the new request uses different credentials for the HTTP proxy. The NVD ↗ · NTAP-20260327-0003 |
CVE-2026-3805 | 2026-03-11 | HIGH | 7.5 | When doing a second SMB request to the same host again, curl would wrongly use a data pointer pointing into already freed memory. NVD ↗ · NTAP-20260327-0001 |
CVE-2026-3833 | 2026-04-30 | MEDIUM | 6.5 | A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` NVD ↗ · NTAP-20260724-0002 |
CVE-2026-4046 | 2026-03-30 | HIGH | 7.5 | The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 cha NVD ↗ · NTAP-20260422-0003 |
CVE-2026-42511 | 2026-04-30 | HIGH | 8.1 | The BOOTP file field is written to the lease file without escaping embedded double-quotes, allowing injection of arbitrary dhclient.conf directives. When the le NVD ↗ · NTAP-20260501-0005 |
CVE-2026-42512 | 2026-04-30 | HIGH | 8.1 | As dhclient is building an environment to pass to dhclient-script, it may need to resize the array of string pointers. The code which expands the array incorrec NVD ↗ · NTAP-20260501-0006 |
CVE-2026-42536 | 2026-06-08 | HIGH | 7.5 | Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content This issue affects Apache HTTP Server: fr NVD ↗ · NTAP-20260610-0001 |
CVE-2026-42764 | 2026-06-09 | HIGH | 7.5 | Issue summary: Receiving a QUIC initial packet with an invalid token may trigger a NULL pointer dereference in the OpenSSL QUIC server with address validation d NVD ↗ · NTAP-20260617-0004 · NTAP-20260617-0004 |
CVE-2026-42765 | 2026-06-09 | HIGH | 7.5 | Issue summary: When a partial-chain certificate verification is enabled together with OCSP response checking for the whole chain, a NULL dereference will happen NVD ↗ · NTAP-20260617-0005 |
CVE-2026-42766 | 2026-06-09 | MEDIUM | 5.9 | Issue summary: A specially crafted password-encrypted CMS message can trigger a NULL pointer dereference during CMS decryption. Impact summary: This NULL pointe NVD ↗ · NTAP-20260617-0013 |
CVE-2026-42767 | 2026-06-09 | MEDIUM | 5.9 | Issue summary: An attacker-controlled CMP (Certificate Management Protocol) server could trigger a NULL pointer dereference in a CMP client application. Impact NVD ↗ · NTAP-20260617-0012 |
CVE-2026-42768 | 2026-06-09 | LOW | 3.7 | Issue summary: The CMS_decrypt and PKCS7_decrypt functions are vulnerable to Bleichenbacher-style attack when an attacker is able to provide the CMS or S/MIME m NVD ↗ · NTAP-20260617-0017 |
CVE-2026-42769 | 2026-06-09 | MEDIUM | 5.3 | Issue Summary: An error in the callback used to verify the certificate provided in a Root CA key update Certificate Management Protocol (CMP) message response r NVD ↗ · NTAP-20260617-0014 |
CVE-2026-42770 | 2026-06-09 | LOW | 3.7 | Issue summary: When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the peer key is not properly checked for the subgroup membership. Impact s NVD ↗ · NTAP-20260617-0018 |
CVE-2026-42771 | 2026-06-09 | MEDIUM | 6.2 | Issue summary: When the X509_VERIFY_PARAM_set1_email is called by an application to validate a crafted e-mail address, such as during S/MIME message validation, NVD ↗ · NTAP-20260617-0011 |
CVE-2026-43951 | 2026-06-08 | MEDIUM | 6.5 | Out-of-bounds Read vulnerability in Apache HTTP Server with mod_headers and mod_mime and multiple response languages. This issue affects Apache HTTP Server: fro NVD ↗ · NTAP-20260610-0001 |
CVE-2026-44119 | 2026-06-08 | MEDIUM | 5.5 | Improper Privilege Management vulnerability in Apache HTTP Server 2.4.67 and earlier allows local .htaccess authors to read files with the privileges of the htt NVD ↗ · NTAP-20260610-0001 |
CVE-2026-44185 | 2026-06-08 | HIGH | 7.3 | Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server This issue affects Apache HTTP Server: fro NVD ↗ · NTAP-20260610-0001 |
CVE-2026-44186 | 2026-06-08 | HIGH | 7.3 | Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the mod_proxy_ftp module in Apache HTTP Server with an attacker controlled backend FTP s NVD ↗ · NTAP-20260610-0001 |
CVE-2026-44631 | 2026-06-08 | CRITICAL | 9.8 | Buffer Underwrite vulnerability in Apache HTTP Server on crafted regular expressions in the configuration. This issue affects Apache HTTP Server: from 2.4.0 thr NVD ↗ · NTAP-20260610-0001 |
CVE-2026-45445 | 2026-06-09 | HIGH | 7.5 | Issue summary: When an application drives an AES-OCB context through the public EVP_Cipher() one-shot interface, the application-supplied initialisation vector NVD ↗ · NTAP-20260617-0007 |
CVE-2026-45446 | 2026-06-09 | MEDIUM | 4.8 | Issue summary: The implementations of AES-SIV (RFC 5297) and AES-GCM-SIV (RFC 8452) mishandle the authentication of AAD (Additional Authenticated Data) with an NVD ↗ · NTAP-20260617-0016 |
CVE-2026-45447 | 2026-06-09 | HIGH | 8.8 | Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification. Impact summary: A use-af NVD ↗ · NTAP-20260617-0002 |
CVE-2026-48095 | 2026-06-05 | HIGH | 8.8 | 7-Zip is a file archiver with a high compression ratio. Versions 26.00 and prior contain a heap buffer overflow vulnerability caused by an under-allocation in t NVD ↗ · NTAP-20260619-0001 |
CVE-2026-49759 | 2026-06-10 | HIGH | 8.2 | Stack-based Buffer Overflow vulnerability in Erlang OTP erts (inet_drv) allows an unauthenticated remote attacker to crash the BEAM VM by sending a crafted SCTP NVD ↗ · NTAP-20260626-0014 |
CVE-2026-55200 | 2026-06-17 | HIGH | 8.1 | libssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write vulnerability in ssh2_transport_read() that fails to enforce upper bounds on pac NVD ↗ · NTAP-20260703-0020 · NTAP-20260703-0020 |
CVE-2026-5946 | 2026-05-20 | HIGH | 7.5 | Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS is not Internet (`IN`) — for example, `CHAOS` or `HESIOD`, or NVD ↗ · NTAP-20260529-0002 |
CVE-2026-59995 | 2026-07-08 | MEDIUM | 4.2 | sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server. NVD ↗ · NTAP-20260717-0012 |
CVE-2026-59996 | 2026-07-08 | MEDIUM | 4.2 | scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations. NVD ↗ · NTAP-20260717-0012 |
CVE-2026-59997 | 2026-07-08 | MEDIUM | 4.2 | internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would h NVD ↗ · NTAP-20260717-0012 |
CVE-2026-59998 | 2026-07-08 | MEDIUM | 4.8 | sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory. NVD ↗ · NTAP-20260717-0012 |
CVE-2026-59999 | 2026-07-08 | MEDIUM | 5.9 | In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not. NVD ↗ · NTAP-20260717-0012 |
CVE-2026-60000 | 2026-07-08 | LOW | 3.7 | sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTr NVD ↗ · NTAP-20260717-0012 |
CVE-2026-60001 | 2026-07-08 | MEDIUM | 6.5 | sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay. NVD ↗ · NTAP-20260717-0012 |
CVE-2026-60002 | 2026-07-08 | HIGH | 7.7 | ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.) NVD ↗ · NTAP-20260717-0012 |
CVE-2026-66032 | 2026-07-24 | HIGH | 8.8 | libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH serv NVD ↗ · NTAP-20260807-0001 |
CVE-2026-66033 | 2026-07-24 | HIGH | 7.5 | libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in src/openss NVD ↗ · NTAP-20260807-0002 |
CVE-2026-7598 | 2026-05-01 | HIGH | 7.3 | A security vulnerability has been detected in libssh2 up to 1.11.1. The impacted element is the function userauth_password of the file src/userauth.c. Such mani NVD ↗ · NTAP-20260814-0020 |
CVE-2026-9076 | 2026-06-09 | HIGH | 7.5 | Issue summary: When CMS password-based decryption (RFC 3211 / PWRI key unwrap) processes attacker-supplied CMS data, an attacker-chosen stream-mode KEK cipher c NVD ↗ · NTAP-20260617-0008 |