Home / Security / CVE index / 2025

2025 NetApp CVEs (page 3)

Showing 150 CVEs with a 2025 identifier — page 3 of 3. Sorted by CVE id.

Always verify. NetApp's advisory is authoritative for affected versions and fixes; NVD carries the CVSS record.
Showing 150 of 150
CVEPublishedSeverityCVSSSummary / Sources
CVE-2025-58181——— NVD ↗ · NTAP-20251219-0003
CVE-2025-581832025-10-29MEDIUM4.3tar.Reader does not set a maximum size on the number of sparse region data blocks in GNU tar pax 1.0 sparse files. A maliciously-crafted archive containing a la NVD ↗ · NTAP-20260703-0007
CVE-2025-581852025-10-29MEDIUM5.3Parsing a maliciously crafted DER payload could allocate large amounts of memory, causing memory exhaustion. NVD ↗ · NTAP-20260703-0007
CVE-2025-581862025-10-29MEDIUM5.3Despite HTTP headers having a default limit of 1MB, the number of cookies that can be parsed does not have a limit. By sending a lot of very small cookies such NVD ↗ · NTAP-20260703-0007
CVE-2025-581872025-10-29HIGH7.5Due to the design of the name constraint checking algorithm, the processing time of some inputs scale non-linearly with respect to the size of the certificate. NVD ↗ · NTAP-20260612-0003
CVE-2025-581882025-10-29HIGH7.5Validating certificate chains which contain DSA public keys can cause programs to panic, due to a interface cast that assumes they implement the Equal method. T NVD ↗ · NTAP-20260703-0007
CVE-2025-581892025-10-29MEDIUM5.3When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the client) which is not escape NVD ↗ · NTAP-20260703-0007
CVE-2025-58190——— NVD ↗ · NTAP-20260311-0008
CVE-2025-58767——— NVD ↗ · NTAP-20260116-0020
CVE-2025-5889——— NVD ↗ · NTAP-20260522-0001
CVE-2025-5916——— NVD ↗ · NTAP-20260130-0020
CVE-2025-593752025-09-15HIGH7.5libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing. NVD ↗ · NTAP-20260917-0001
CVE-2025-59419——— NVD ↗ · NTAP-20260109-0001
CVE-2025-59464——— NVD ↗ · NTAP-20260311-0012
CVE-2025-59465——— NVD ↗ · NTAP-20260320-0007
CVE-2025-59466——— NVD ↗ · NTAP-20260311-0011
CVE-2025-59775——— NVD ↗ · NTAP-20251212-0005
CVE-2025-5987——— NVD ↗ · NTAP-20260109-0009
CVE-2025-5999——— NVD ↗ · NTAP-20250829-0007
CVE-2025-6000——— NVD ↗ · NTAP-20250822-0007
CVE-2025-6004——— NVD ↗ · NTAP-20250829-0004
CVE-2025-6011——— NVD ↗ · NTAP-20250829-0008
CVE-2025-6013——— NVD ↗ · NTAP-20250829-0006
CVE-2025-6014——— NVD ↗ · NTAP-20250829-0003
CVE-2025-6015——— NVD ↗ · NTAP-20250829-0005
CVE-2025-60202025-06-17HIGH7.8A flaw was found in linux-pam. The module pam_namespace may use access user-controlled paths without proper protection, allowing local users to elevate their pr NVD ↗ · NTAP-20260522-0001 · NTAP-20260403-0005
CVE-2025-60212025-06-12HIGH7.5A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue NVD ↗ · NTAP-20260123-0013 · NTAP-20250711-0009
CVE-2025-6023——— NVD ↗ · NTAP-20251010-0002
CVE-2025-6037——— NVD ↗ · NTAP-20250829-0003
CVE-2025-6052——— NVD ↗ · NTAP-20260123-0013
CVE-2025-6069——— NVD ↗ · NTAP-20250718-0005
CVE-2025-6075——— NVD ↗ · NTAP-20251128-0014
CVE-2025-60753——— NVD ↗ · NTAP-20251128-0013
CVE-2025-6170——— NVD ↗ · NTAP-20251017-0002
CVE-2025-617232025-10-29HIGH7.5The processing time for parsing some invalid inputs scales non-linearly with respect to the size of the input. This affects programs which parse untrusted PEM i NVD ↗ · NTAP-20260703-0007
CVE-2025-617242025-10-29MEDIUM5.3The Reader.ReadResponse function constructs a response string through repeated string concatenation of lines. When the number of lines in a response is large, t NVD ↗ · NTAP-20260703-0007
CVE-2025-617252025-10-29HIGH7.5The ParseAddress function constructs domain-literal address components through repeated string concatenation. When parsing large domain-literal components, this NVD ↗ · NTAP-20260703-0007
CVE-2025-617262026-01-28HIGH7.5The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query parameters in URLs is generally limited b NVD ↗ · NTAP-20260311-0009
CVE-2025-617272025-12-03MEDIUM6.5An excluded subdomain constraint in a certificate chain does not restrict the usage of wildcard SANs in the leaf certificate. For example a constraint that excl NVD ↗ · NTAP-20260130-0003
CVE-2025-617282026-01-28MEDIUM6.5archive/zip uses a super-linear file name indexing algorithm that is invoked the first time a file in an archive is opened. This can lead to a denial of service NVD ↗ · NTAP-20260703-0006
CVE-2025-617292025-12-02HIGH7.5Within HostnameError.Error(), when constructing an error string, there is no limit to the number of hosts that will be printed out. Furthermore, the error strin NVD ↗ · NTAP-20260130-0002
CVE-2025-617302026-01-28MEDIUM5.3During the TLS 1.3 handshake if multiple messages are sent in records that span encryption level boundaries (for instance the Client Hello and Encrypted Extensi NVD ↗ · NTAP-20260703-0006
CVE-2025-617312026-01-28HIGH7.8Building a malicious file with cmd/go can cause can cause a write to an attacker-controlled file with partial control of the file content. The "#cgo pkg-config: NVD ↗ · NTAP-20260703-0006
CVE-2025-61748——— NVD ↗ · NTAP-20251024-0010
CVE-2025-61770——— NVD ↗ · NTAP-20260116-0008
CVE-2025-61771——— NVD ↗ · NTAP-20260116-0012
CVE-2025-61772——— NVD ↗ · NTAP-20260116-0010
CVE-2025-61780——— NVD ↗ · NTAP-20260116-0009
CVE-2025-61795——— NVD ↗ · NTAP-20251107-0014
CVE-2025-61919——— NVD ↗ · NTAP-20260116-0011
CVE-2025-6197——— NVD ↗ · NTAP-20251010-0003
CVE-2025-61984——— NVD ↗ · NTAP-20251017-0010
CVE-2025-61985——— NVD ↗ · NTAP-20251017-0010
CVE-2025-6203——— NVD ↗ · NTAP-20260130-0006
CVE-2025-62408——— NVD ↗ · NTAP-20251224-0014
CVE-2025-62507——— NVD ↗ · NTAP-20260123-0015
CVE-2025-627182026-04-09CRITICAL9.9Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.31.0, Axios does not correctly handle hostname normalization when checki NVD ↗ · NTAP-20260917-0001 · NTAP-20260417-0020
CVE-2025-6297——— NVD ↗ · NTAP-20250808-0008
CVE-2025-63952025-07-10MEDIUM6.5A NULL pointer dereference flaw was found in the GnuTLS software in _gnutls_figure_common_ciphersuite(). NVD ↗ · NTAP-20250725-0007
CVE-2025-64118——— NVD ↗ · NTAP-20260422-0019
CVE-2025-64505——— NVD ↗ · NTAP-20260116-0007
CVE-2025-645062025-11-25MEDIUM6.1LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From version 1.6.0 t NVD ↗ · NTAP-20260116-0005
CVE-2025-64720——— NVD ↗ · NTAP-20260116-0004
CVE-2025-64756——— NVD ↗ · NTAP-20260424-0007
CVE-2025-64775——— NVD ↗ · NTAP-20251212-0006
CVE-2025-6491——— NVD ↗ · NTAP-20250801-0008
CVE-2025-65018——— NVD ↗ · NTAP-20260116-0003
CVE-2025-65082——— NVD ↗ · NTAP-20251212-0001
CVE-2025-65945——— NVD ↗ · NTAP-20260417-0009
CVE-2025-660352025-11-26HIGH7.7Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to versions 19.2.16, 2 NVD ↗ · NTAP-20251224-0007
CVE-2025-66168——— NVD ↗ · NTAP-20260422-0001
CVE-2025-661992026-01-27MEDIUM5.9Issue summary: A TLS 1.3 connection using certificate compression can be forced to allocate a large buffer before decompression without checking against the con NVD ↗ · NTAP-20260204-0015
CVE-2025-66200——— NVD ↗ · NTAP-20251212-0003
CVE-2025-66221——— NVD ↗ · NTAP-20251219-0012
CVE-2025-66293——— NVD ↗ · NTAP-20260116-0006
CVE-2025-664122025-12-01MEDIUM5.4Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 21.0.2, 20.3.15, an NVD ↗ · NTAP-20251224-0006
CVE-2025-664182025-12-05HIGH7.5urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.24 and prior to 2.6.0, the number of links in the decompression chain was unbou NVD ↗ · NTAP-20251224-0008
CVE-2025-664712025-12-05HIGH7.5urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.0 and prior to 2.6.0, the Streaming API improperly handles highly compressed da NVD ↗ · NTAP-20251224-0009
CVE-2025-66516——— NVD ↗ · NTAP-20260227-0004
CVE-2025-66567——— NVD ↗ · NTAP-20260123-0003
CVE-2025-66568——— NVD ↗ · NTAP-20260123-0002
CVE-2025-66614——— NVD ↗ · NTAP-20260227-0001
CVE-2025-66675——— NVD ↗ · NTAP-20251219-0013
CVE-2025-66863——— NVD ↗ · NTAP-20260220-0014
CVE-2025-66864——— NVD ↗ · NTAP-20260220-0015
CVE-2025-66866——— NVD ↗ · NTAP-20260130-0013
CVE-2025-67735——— NVD ↗ · NTAP-20260422-0011 · NTAP-20260130-0017
CVE-2025-67779——— NVD ↗ · NTAP-20251219-0014
CVE-2025-681192026-01-28HIGH7.0Downloading and building modules with malicious version strings can cause local code execution. On systems with Mercurial (hg) installed, downloading modules fr NVD ↗ · NTAP-20260703-0006
CVE-2025-68121——— NVD ↗ · NTAP-20260424-0002
CVE-2025-68146——— NVD ↗ · NTAP-20260522-0001
CVE-2025-68160——— NVD ↗ · NTAP-20260204-0010
CVE-2025-68161——— NVD ↗ · NTAP-20260422-0013 · NTAP-20260123-0014
CVE-2025-682632025-12-16CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: ksmbd: ipc: fix use-after-free in ipc_msg_send_request ipc_msg_send_request() waits for a ge NVD ↗ · NTAP-20260424-0012
CVE-2025-68372——— NVD ↗ · NTAP-20260313-0007
CVE-2025-68384——— NVD ↗ · NTAP-20260130-0019
CVE-2025-68390——— NVD ↗ · NTAP-20260130-0018
CVE-2025-68493——— NVD ↗ · NTAP-20260130-0012
CVE-2025-68615——— NVD ↗ · NTAP-20260109-0002
CVE-2025-68803——— NVD ↗ · NTAP-20260204-0003
CVE-2025-68813——— NVD ↗ · NTAP-20260204-0002
CVE-2025-688232026-01-13MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ublk: fix deadlock when reading partition table When one process(such as udev) opens ublk bl NVD ↗ · NTAP-20260925-0013
CVE-2025-68973——— NVD ↗ · NTAP-20260130-0014
CVE-2025-69277——— NVD ↗ · NTAP-20260429-0015
CVE-2025-69418——— NVD ↗ · NTAP-20260204-0009
CVE-2025-694192026-01-27HIGH7.4Issue summary: Calling PKCS12_get_friendlyname() function on a maliciously crafted PKCS#12 file with a BMPString (UTF-16BE) friendly name containing non-ASCII B NVD ↗ · NTAP-20260204-0008
CVE-2025-694202026-01-27HIGH7.5Issue summary: A type confusion vulnerability exists in the TimeStamp Response verification code where an ASN1_TYPE union member is accessed without first valid NVD ↗ · NTAP-20260204-0006
CVE-2025-69421——— NVD ↗ · NTAP-20260204-0007
CVE-2025-695342026-03-05HIGH7.5Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError du NVD ↗ · NTAP-20260917-0001
CVE-2025-6965——— NVD ↗ · NTAP-20260123-0011 · NTAP-20260102-0013
CVE-2025-7039——— NVD ↗ · NTAP-20251010-0009
CVE-2025-7345——— NVD ↗ · NTAP-20260605-0006
CVE-2025-7424——— NVD ↗ · NTAP-20260102-0012
CVE-2025-74252025-07-10HIGH7.8A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management. When XSLT functions, such as NVD ↗ · NTAP-20260123-0013 · NTAP-20260116-0014
CVE-2025-7545——— NVD ↗ · NTAP-20251031-0005
CVE-2025-7709——— NVD ↗ · NTAP-20251010-0011
CVE-2025-7783——— NVD ↗ · NTAP-20250801-0002
CVE-2025-7962——— NVD ↗ · NTAP-20260522-0001
CVE-2025-8058——— NVD ↗ · NTAP-20250808-0002
CVE-2025-8114——— NVD ↗ · NTAP-20260109-0010
CVE-2025-8176——— NVD ↗ · NTAP-20260206-0003
CVE-2025-8177——— NVD ↗ · NTAP-20260206-0004
CVE-2025-8191——— NVD ↗ · NTAP-20260227-0011
CVE-2025-8194——— NVD ↗ · NTAP-20250814-0001
CVE-2025-8224——— NVD ↗ · NTAP-20251212-0010
CVE-2025-8225——— NVD ↗ · NTAP-20251212-0011
CVE-2025-8277——— NVD ↗ · NTAP-20251031-0010
CVE-2025-8534——— NVD ↗ · NTAP-20260109-0015
CVE-2025-8671——— NVD ↗ · NTAP-20251003-0004
CVE-2025-8677——— NVD ↗ · NTAP-20251031-0003
CVE-2025-8714——— NVD ↗ · NTAP-20251205-0005
CVE-2025-8715——— NVD ↗ · NTAP-20251205-0004
CVE-2025-8851——— NVD ↗ · NTAP-20251212-0007
CVE-2025-88852025-08-12MEDIUM6.3Allocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc. BC Java bcprov on All (API modules), Legion of the Bouncy NVD ↗ · NTAP-20260917-0001 · NTAP-20250912-0012
CVE-2025-89162025-08-13MEDIUM6.3Allocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc. BC Java bcpkix on All (API modules), Legion of the Bouncy NVD ↗ · NTAP-20250912-0011
CVE-2025-89412025-08-13HIGH7.8A flaw was found in linux-pam. The pam_namespace module may improperly handle user-controlled paths, allowing local users to exploit symlink attacks and race co NVD ↗ · NTAP-20260403-0006
CVE-2025-8961——— NVD ↗ · NTAP-20260109-0014
CVE-2025-90862025-09-12HIGH7.51. A cookie is set using the `secure` keyword for `https://target` 2. curl is redirected to or otherwise made to speak with `http://target` (same hostname, but NVD ↗ · NTAP-20251031-0007
CVE-2025-90952025-08-17LOW3.5A flaw has been found in ExpressGateway express-gateway up to 1.16.10. This issue affects some unknown processing in the library lib/rest/routes/users.js of the NVD ↗ · NTAP-20260917-0001
CVE-2025-90962025-08-18LOW3.5A vulnerability has been found in ExpressGateway express-gateway up to 1.16.10. Affected is an unknown function in the library lib/rest/routes/apps.js of the co NVD ↗ · NTAP-20260917-0001
CVE-2025-92302025-09-30HIGH7.5Issue summary: An application trying to decrypt CMS messages encrypted using password based encryption can trigger an out-of-bounds read and write. Impact summa NVD ↗ · NTAP-20260123-0009 · NTAP-20251003-0011
CVE-2025-9231——— NVD ↗ · NTAP-20251003-0012
CVE-2025-9232——— NVD ↗ · NTAP-20251003-0013
CVE-2025-9390——— NVD ↗ · NTAP-20251205-0008
CVE-2025-9566——— NVD ↗ · NTAP-20260109-0007
CVE-2025-9640——— NVD ↗ · NTAP-20251024-0002
CVE-2025-97142025-09-10MEDIUM6.2Uncontrolled recursion in XPath evaluation in libxml2 up to and including version 2.9.14 allows a local attacker to cause a stack overflow via crafted expressio NVD ↗ · NTAP-20260320-0006
CVE-2025-9784——— NVD ↗ · NTAP-20251003-0007
CVE-2025-9820——— NVD ↗ · NTAP-20260305-0016
CVE-2025-9900——— NVD ↗ · NTAP-20260109-0012

Years: 2026 · 2025 · 2024 · 2023 · 2022 · 2021 · 2020 · 2019 · 2018 · 2017 · 2016 · 2015 · 2014 · 2013 · 2012 · 2011 · 2010 · 2009 · 2008 · 2007 · 2006 · 2005 · 2004 · 2003 · 2002 · 1999

← CVE index · Security hub