Home / Security / CVE index / 2025
2025 NetApp CVEs (page 3)
Showing 150 CVEs with a 2025 identifier — page 3 of 3. Sorted by CVE id.
Always verify. NetApp's advisory is authoritative for affected versions and fixes; NVD carries the CVSS record.
Showing 150 of 150
| CVE | Published | Severity | CVSS | Summary / Sources |
|---|---|---|---|---|
CVE-2025-58181 | — | — | — | NVD ↗ · NTAP-20251219-0003 |
CVE-2025-58183 | 2025-10-29 | MEDIUM | 4.3 | tar.Reader does not set a maximum size on the number of sparse region data blocks in GNU tar pax 1.0 sparse files. A maliciously-crafted archive containing a la NVD ↗ · NTAP-20260703-0007 |
CVE-2025-58185 | 2025-10-29 | MEDIUM | 5.3 | Parsing a maliciously crafted DER payload could allocate large amounts of memory, causing memory exhaustion. NVD ↗ · NTAP-20260703-0007 |
CVE-2025-58186 | 2025-10-29 | MEDIUM | 5.3 | Despite HTTP headers having a default limit of 1MB, the number of cookies that can be parsed does not have a limit. By sending a lot of very small cookies such NVD ↗ · NTAP-20260703-0007 |
CVE-2025-58187 | 2025-10-29 | HIGH | 7.5 | Due to the design of the name constraint checking algorithm, the processing time of some inputs scale non-linearly with respect to the size of the certificate. NVD ↗ · NTAP-20260612-0003 |
CVE-2025-58188 | 2025-10-29 | HIGH | 7.5 | Validating certificate chains which contain DSA public keys can cause programs to panic, due to a interface cast that assumes they implement the Equal method. T NVD ↗ · NTAP-20260703-0007 |
CVE-2025-58189 | 2025-10-29 | MEDIUM | 5.3 | When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the client) which is not escape NVD ↗ · NTAP-20260703-0007 |
CVE-2025-58190 | — | — | — | NVD ↗ · NTAP-20260311-0008 |
CVE-2025-58767 | — | — | — | NVD ↗ · NTAP-20260116-0020 |
CVE-2025-5889 | — | — | — | NVD ↗ · NTAP-20260522-0001 |
CVE-2025-5916 | — | — | — | NVD ↗ · NTAP-20260130-0020 |
CVE-2025-59375 | 2025-09-15 | HIGH | 7.5 | libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing. NVD ↗ · NTAP-20260917-0001 |
CVE-2025-59419 | — | — | — | NVD ↗ · NTAP-20260109-0001 |
CVE-2025-59464 | — | — | — | NVD ↗ · NTAP-20260311-0012 |
CVE-2025-59465 | — | — | — | NVD ↗ · NTAP-20260320-0007 |
CVE-2025-59466 | — | — | — | NVD ↗ · NTAP-20260311-0011 |
CVE-2025-59775 | — | — | — | NVD ↗ · NTAP-20251212-0005 |
CVE-2025-5987 | — | — | — | NVD ↗ · NTAP-20260109-0009 |
CVE-2025-5999 | — | — | — | NVD ↗ · NTAP-20250829-0007 |
CVE-2025-6000 | — | — | — | NVD ↗ · NTAP-20250822-0007 |
CVE-2025-6004 | — | — | — | NVD ↗ · NTAP-20250829-0004 |
CVE-2025-6011 | — | — | — | NVD ↗ · NTAP-20250829-0008 |
CVE-2025-6013 | — | — | — | NVD ↗ · NTAP-20250829-0006 |
CVE-2025-6014 | — | — | — | NVD ↗ · NTAP-20250829-0003 |
CVE-2025-6015 | — | — | — | NVD ↗ · NTAP-20250829-0005 |
CVE-2025-6020 | 2025-06-17 | HIGH | 7.8 | A flaw was found in linux-pam. The module pam_namespace may use access user-controlled paths without proper protection, allowing local users to elevate their pr NVD ↗ · NTAP-20260522-0001 · NTAP-20260403-0005 |
CVE-2025-6021 | 2025-06-12 | HIGH | 7.5 | A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue NVD ↗ · NTAP-20260123-0013 · NTAP-20250711-0009 |
CVE-2025-6023 | — | — | — | NVD ↗ · NTAP-20251010-0002 |
CVE-2025-6037 | — | — | — | NVD ↗ · NTAP-20250829-0003 |
CVE-2025-6052 | — | — | — | NVD ↗ · NTAP-20260123-0013 |
CVE-2025-6069 | — | — | — | NVD ↗ · NTAP-20250718-0005 |
CVE-2025-6075 | — | — | — | NVD ↗ · NTAP-20251128-0014 |
CVE-2025-60753 | — | — | — | NVD ↗ · NTAP-20251128-0013 |
CVE-2025-6170 | — | — | — | NVD ↗ · NTAP-20251017-0002 |
CVE-2025-61723 | 2025-10-29 | HIGH | 7.5 | The processing time for parsing some invalid inputs scales non-linearly with respect to the size of the input. This affects programs which parse untrusted PEM i NVD ↗ · NTAP-20260703-0007 |
CVE-2025-61724 | 2025-10-29 | MEDIUM | 5.3 | The Reader.ReadResponse function constructs a response string through repeated string concatenation of lines. When the number of lines in a response is large, t NVD ↗ · NTAP-20260703-0007 |
CVE-2025-61725 | 2025-10-29 | HIGH | 7.5 | The ParseAddress function constructs domain-literal address components through repeated string concatenation. When parsing large domain-literal components, this NVD ↗ · NTAP-20260703-0007 |
CVE-2025-61726 | 2026-01-28 | HIGH | 7.5 | The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query parameters in URLs is generally limited b NVD ↗ · NTAP-20260311-0009 |
CVE-2025-61727 | 2025-12-03 | MEDIUM | 6.5 | An excluded subdomain constraint in a certificate chain does not restrict the usage of wildcard SANs in the leaf certificate. For example a constraint that excl NVD ↗ · NTAP-20260130-0003 |
CVE-2025-61728 | 2026-01-28 | MEDIUM | 6.5 | archive/zip uses a super-linear file name indexing algorithm that is invoked the first time a file in an archive is opened. This can lead to a denial of service NVD ↗ · NTAP-20260703-0006 |
CVE-2025-61729 | 2025-12-02 | HIGH | 7.5 | Within HostnameError.Error(), when constructing an error string, there is no limit to the number of hosts that will be printed out. Furthermore, the error strin NVD ↗ · NTAP-20260130-0002 |
CVE-2025-61730 | 2026-01-28 | MEDIUM | 5.3 | During the TLS 1.3 handshake if multiple messages are sent in records that span encryption level boundaries (for instance the Client Hello and Encrypted Extensi NVD ↗ · NTAP-20260703-0006 |
CVE-2025-61731 | 2026-01-28 | HIGH | 7.8 | Building a malicious file with cmd/go can cause can cause a write to an attacker-controlled file with partial control of the file content. The "#cgo pkg-config: NVD ↗ · NTAP-20260703-0006 |
CVE-2025-61748 | — | — | — | NVD ↗ · NTAP-20251024-0010 |
CVE-2025-61770 | — | — | — | NVD ↗ · NTAP-20260116-0008 |
CVE-2025-61771 | — | — | — | NVD ↗ · NTAP-20260116-0012 |
CVE-2025-61772 | — | — | — | NVD ↗ · NTAP-20260116-0010 |
CVE-2025-61780 | — | — | — | NVD ↗ · NTAP-20260116-0009 |
CVE-2025-61795 | — | — | — | NVD ↗ · NTAP-20251107-0014 |
CVE-2025-61919 | — | — | — | NVD ↗ · NTAP-20260116-0011 |
CVE-2025-6197 | — | — | — | NVD ↗ · NTAP-20251010-0003 |
CVE-2025-61984 | — | — | — | NVD ↗ · NTAP-20251017-0010 |
CVE-2025-61985 | — | — | — | NVD ↗ · NTAP-20251017-0010 |
CVE-2025-6203 | — | — | — | NVD ↗ · NTAP-20260130-0006 |
CVE-2025-62408 | — | — | — | NVD ↗ · NTAP-20251224-0014 |
CVE-2025-62507 | — | — | — | NVD ↗ · NTAP-20260123-0015 |
CVE-2025-62718 | 2026-04-09 | CRITICAL | 9.9 | Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.31.0, Axios does not correctly handle hostname normalization when checki NVD ↗ · NTAP-20260917-0001 · NTAP-20260417-0020 |
CVE-2025-6297 | — | — | — | NVD ↗ · NTAP-20250808-0008 |
CVE-2025-6395 | 2025-07-10 | MEDIUM | 6.5 | A NULL pointer dereference flaw was found in the GnuTLS software in _gnutls_figure_common_ciphersuite(). NVD ↗ · NTAP-20250725-0007 |
CVE-2025-64118 | — | — | — | NVD ↗ · NTAP-20260422-0019 |
CVE-2025-64505 | — | — | — | NVD ↗ · NTAP-20260116-0007 |
CVE-2025-64506 | 2025-11-25 | MEDIUM | 6.1 | LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From version 1.6.0 t NVD ↗ · NTAP-20260116-0005 |
CVE-2025-64720 | — | — | — | NVD ↗ · NTAP-20260116-0004 |
CVE-2025-64756 | — | — | — | NVD ↗ · NTAP-20260424-0007 |
CVE-2025-64775 | — | — | — | NVD ↗ · NTAP-20251212-0006 |
CVE-2025-6491 | — | — | — | NVD ↗ · NTAP-20250801-0008 |
CVE-2025-65018 | — | — | — | NVD ↗ · NTAP-20260116-0003 |
CVE-2025-65082 | — | — | — | NVD ↗ · NTAP-20251212-0001 |
CVE-2025-65945 | — | — | — | NVD ↗ · NTAP-20260417-0009 |
CVE-2025-66035 | 2025-11-26 | HIGH | 7.7 | Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to versions 19.2.16, 2 NVD ↗ · NTAP-20251224-0007 |
CVE-2025-66168 | — | — | — | NVD ↗ · NTAP-20260422-0001 |
CVE-2025-66199 | 2026-01-27 | MEDIUM | 5.9 | Issue summary: A TLS 1.3 connection using certificate compression can be forced to allocate a large buffer before decompression without checking against the con NVD ↗ · NTAP-20260204-0015 |
CVE-2025-66200 | — | — | — | NVD ↗ · NTAP-20251212-0003 |
CVE-2025-66221 | — | — | — | NVD ↗ · NTAP-20251219-0012 |
CVE-2025-66293 | — | — | — | NVD ↗ · NTAP-20260116-0006 |
CVE-2025-66412 | 2025-12-01 | MEDIUM | 5.4 | Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 21.0.2, 20.3.15, an NVD ↗ · NTAP-20251224-0006 |
CVE-2025-66418 | 2025-12-05 | HIGH | 7.5 | urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.24 and prior to 2.6.0, the number of links in the decompression chain was unbou NVD ↗ · NTAP-20251224-0008 |
CVE-2025-66471 | 2025-12-05 | HIGH | 7.5 | urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.0 and prior to 2.6.0, the Streaming API improperly handles highly compressed da NVD ↗ · NTAP-20251224-0009 |
CVE-2025-66516 | — | — | — | NVD ↗ · NTAP-20260227-0004 |
CVE-2025-66567 | — | — | — | NVD ↗ · NTAP-20260123-0003 |
CVE-2025-66568 | — | — | — | NVD ↗ · NTAP-20260123-0002 |
CVE-2025-66614 | — | — | — | NVD ↗ · NTAP-20260227-0001 |
CVE-2025-66675 | — | — | — | NVD ↗ · NTAP-20251219-0013 |
CVE-2025-66863 | — | — | — | NVD ↗ · NTAP-20260220-0014 |
CVE-2025-66864 | — | — | — | NVD ↗ · NTAP-20260220-0015 |
CVE-2025-66866 | — | — | — | NVD ↗ · NTAP-20260130-0013 |
CVE-2025-67735 | — | — | — | NVD ↗ · NTAP-20260422-0011 · NTAP-20260130-0017 |
CVE-2025-67779 | — | — | — | NVD ↗ · NTAP-20251219-0014 |
CVE-2025-68119 | 2026-01-28 | HIGH | 7.0 | Downloading and building modules with malicious version strings can cause local code execution. On systems with Mercurial (hg) installed, downloading modules fr NVD ↗ · NTAP-20260703-0006 |
CVE-2025-68121 | — | — | — | NVD ↗ · NTAP-20260424-0002 |
CVE-2025-68146 | — | — | — | NVD ↗ · NTAP-20260522-0001 |
CVE-2025-68160 | — | — | — | NVD ↗ · NTAP-20260204-0010 |
CVE-2025-68161 | — | — | — | NVD ↗ · NTAP-20260422-0013 · NTAP-20260123-0014 |
CVE-2025-68263 | 2025-12-16 | CRITICAL | 9.8 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: ipc: fix use-after-free in ipc_msg_send_request ipc_msg_send_request() waits for a ge NVD ↗ · NTAP-20260424-0012 |
CVE-2025-68372 | — | — | — | NVD ↗ · NTAP-20260313-0007 |
CVE-2025-68384 | — | — | — | NVD ↗ · NTAP-20260130-0019 |
CVE-2025-68390 | — | — | — | NVD ↗ · NTAP-20260130-0018 |
CVE-2025-68493 | — | — | — | NVD ↗ · NTAP-20260130-0012 |
CVE-2025-68615 | — | — | — | NVD ↗ · NTAP-20260109-0002 |
CVE-2025-68803 | — | — | — | NVD ↗ · NTAP-20260204-0003 |
CVE-2025-68813 | — | — | — | NVD ↗ · NTAP-20260204-0002 |
CVE-2025-68823 | 2026-01-13 | MEDIUM | 5.5 | In the Linux kernel, the following vulnerability has been resolved: ublk: fix deadlock when reading partition table When one process(such as udev) opens ublk bl NVD ↗ · NTAP-20260925-0013 |
CVE-2025-68973 | — | — | — | NVD ↗ · NTAP-20260130-0014 |
CVE-2025-69277 | — | — | — | NVD ↗ · NTAP-20260429-0015 |
CVE-2025-69418 | — | — | — | NVD ↗ · NTAP-20260204-0009 |
CVE-2025-69419 | 2026-01-27 | HIGH | 7.4 | Issue summary: Calling PKCS12_get_friendlyname() function on a maliciously crafted PKCS#12 file with a BMPString (UTF-16BE) friendly name containing non-ASCII B NVD ↗ · NTAP-20260204-0008 |
CVE-2025-69420 | 2026-01-27 | HIGH | 7.5 | Issue summary: A type confusion vulnerability exists in the TimeStamp Response verification code where an ASN1_TYPE union member is accessed without first valid NVD ↗ · NTAP-20260204-0006 |
CVE-2025-69421 | — | — | — | NVD ↗ · NTAP-20260204-0007 |
CVE-2025-69534 | 2026-03-05 | HIGH | 7.5 | Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError du NVD ↗ · NTAP-20260917-0001 |
CVE-2025-6965 | — | — | — | NVD ↗ · NTAP-20260123-0011 · NTAP-20260102-0013 |
CVE-2025-7039 | — | — | — | NVD ↗ · NTAP-20251010-0009 |
CVE-2025-7345 | — | — | — | NVD ↗ · NTAP-20260605-0006 |
CVE-2025-7424 | — | — | — | NVD ↗ · NTAP-20260102-0012 |
CVE-2025-7425 | 2025-07-10 | HIGH | 7.8 | A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management. When XSLT functions, such as NVD ↗ · NTAP-20260123-0013 · NTAP-20260116-0014 |
CVE-2025-7545 | — | — | — | NVD ↗ · NTAP-20251031-0005 |
CVE-2025-7709 | — | — | — | NVD ↗ · NTAP-20251010-0011 |
CVE-2025-7783 | — | — | — | NVD ↗ · NTAP-20250801-0002 |
CVE-2025-7962 | — | — | — | NVD ↗ · NTAP-20260522-0001 |
CVE-2025-8058 | — | — | — | NVD ↗ · NTAP-20250808-0002 |
CVE-2025-8114 | — | — | — | NVD ↗ · NTAP-20260109-0010 |
CVE-2025-8176 | — | — | — | NVD ↗ · NTAP-20260206-0003 |
CVE-2025-8177 | — | — | — | NVD ↗ · NTAP-20260206-0004 |
CVE-2025-8191 | — | — | — | NVD ↗ · NTAP-20260227-0011 |
CVE-2025-8194 | — | — | — | NVD ↗ · NTAP-20250814-0001 |
CVE-2025-8224 | — | — | — | NVD ↗ · NTAP-20251212-0010 |
CVE-2025-8225 | — | — | — | NVD ↗ · NTAP-20251212-0011 |
CVE-2025-8277 | — | — | — | NVD ↗ · NTAP-20251031-0010 |
CVE-2025-8534 | — | — | — | NVD ↗ · NTAP-20260109-0015 |
CVE-2025-8671 | — | — | — | NVD ↗ · NTAP-20251003-0004 |
CVE-2025-8677 | — | — | — | NVD ↗ · NTAP-20251031-0003 |
CVE-2025-8714 | — | — | — | NVD ↗ · NTAP-20251205-0005 |
CVE-2025-8715 | — | — | — | NVD ↗ · NTAP-20251205-0004 |
CVE-2025-8851 | — | — | — | NVD ↗ · NTAP-20251212-0007 |
CVE-2025-8885 | 2025-08-12 | MEDIUM | 6.3 | Allocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc. BC Java bcprov on All (API modules), Legion of the Bouncy NVD ↗ · NTAP-20260917-0001 · NTAP-20250912-0012 |
CVE-2025-8916 | 2025-08-13 | MEDIUM | 6.3 | Allocation of Resources Without Limits or Throttling vulnerability in Legion of the Bouncy Castle Inc. BC Java bcpkix on All (API modules), Legion of the Bouncy NVD ↗ · NTAP-20250912-0011 |
CVE-2025-8941 | 2025-08-13 | HIGH | 7.8 | A flaw was found in linux-pam. The pam_namespace module may improperly handle user-controlled paths, allowing local users to exploit symlink attacks and race co NVD ↗ · NTAP-20260403-0006 |
CVE-2025-8961 | — | — | — | NVD ↗ · NTAP-20260109-0014 |
CVE-2025-9086 | 2025-09-12 | HIGH | 7.5 | 1. A cookie is set using the `secure` keyword for `https://target` 2. curl is redirected to or otherwise made to speak with `http://target` (same hostname, but NVD ↗ · NTAP-20251031-0007 |
CVE-2025-9095 | 2025-08-17 | LOW | 3.5 | A flaw has been found in ExpressGateway express-gateway up to 1.16.10. This issue affects some unknown processing in the library lib/rest/routes/users.js of the NVD ↗ · NTAP-20260917-0001 |
CVE-2025-9096 | 2025-08-18 | LOW | 3.5 | A vulnerability has been found in ExpressGateway express-gateway up to 1.16.10. Affected is an unknown function in the library lib/rest/routes/apps.js of the co NVD ↗ · NTAP-20260917-0001 |
CVE-2025-9230 | 2025-09-30 | HIGH | 7.5 | Issue summary: An application trying to decrypt CMS messages encrypted using password based encryption can trigger an out-of-bounds read and write. Impact summa NVD ↗ · NTAP-20260123-0009 · NTAP-20251003-0011 |
CVE-2025-9231 | — | — | — | NVD ↗ · NTAP-20251003-0012 |
CVE-2025-9232 | — | — | — | NVD ↗ · NTAP-20251003-0013 |
CVE-2025-9390 | — | — | — | NVD ↗ · NTAP-20251205-0008 |
CVE-2025-9566 | — | — | — | NVD ↗ · NTAP-20260109-0007 |
CVE-2025-9640 | — | — | — | NVD ↗ · NTAP-20251024-0002 |
CVE-2025-9714 | 2025-09-10 | MEDIUM | 6.2 | Uncontrolled recursion in XPath evaluation in libxml2 up to and including version 2.9.14 allows a local attacker to cause a stack overflow via crafted expressio NVD ↗ · NTAP-20260320-0006 |
CVE-2025-9784 | — | — | — | NVD ↗ · NTAP-20251003-0007 |
CVE-2025-9820 | — | — | — | NVD ↗ · NTAP-20260305-0016 |
CVE-2025-9900 | — | — | — | NVD ↗ · NTAP-20260109-0012 |
Years: 2026 · 2025 · 2024 · 2023 · 2022 · 2021 · 2020 · 2019 · 2018 · 2017 · 2016 · 2015 · 2014 · 2013 · 2012 · 2011 · 2010 · 2009 · 2008 · 2007 · 2006 · 2005 · 2004 · 2003 · 2002 · 1999