Skip to main content

Vendor/product archive

netapp / clustered_data_ontap CVEs

Beta · best-effort

186 CVEs tagged to netapp / clustered_data_ontap28 Critical, 81 High, 68 Medium, 9 Low, 0 Unrated.

CVE-2024-21985

Published Jan 26, 2024

ONTAP 9 versions prior to 9.9.1P18, 9.10.1P16, 9.11.1P13, 9.12.1P10 and 9.13.1P4 are susceptible to a vulnerability which could allow an authenticated user with multiple remote…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2024-21982

Published Jan 12, 2024

ONTAP versions 9.4 and higher are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information to unprivileged attackers wh…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-27314

Published Oct 12, 2023

ONTAP 9 versions prior to 9.8P19, 9.9.1P16, 9.10.1P12, 9.11.1P8, 9.12.1P2 and 9.13.1 are susceptible to a vulnerability which could allow a remote unauthenticated attacker to ca…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-28322

Published May 26, 2023

An information disclosure vulnerability exists in curl <v8.1.0 when doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for da…

CVSS 3.7 · Low

CVE-2023-28321

Published May 26, 2023

An improper certificate validation vulnerability exists in curl <v8.1.0 in the way it supports matching of wildcard patterns when listed as "Subject Alternative Name" in TLS serve…

CVSS 5.9 · Medium

CVE-2023-28320

Published May 26, 2023

A denial of service vulnerability exists in curl <v8.1.0 in the way libcurl provides several different backends for resolving host names, selected at build time. If it is built to…

CVSS 5.9 · Medium

CVE-2023-28319

Published May 26, 2023

A use after free vulnerability exists in curl <v8.1.0 in the way libcurl offers a feature to verify an SSH server's public key using a SHA 256 hash. When this check fails, libcurl…

CVSS 7.5 · High

CVE-2023-27538

Published Mar 30, 2023

An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH option was modified,…

CVSS 5.5 · Medium

CVE-2023-27537

Published Mar 30, 2023

A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS data between separate "handles". This sharing was introduced without considerations for do this sharing acro…

CVSS 5.9 · Medium

CVE-2023-27533

Published Mar 30, 2023

A vulnerability in input validation exists in curl <8.0 during communication using the TELNET protocol may allow an attacker to pass on maliciously crafted user name and "telnet o…

CVSS 8.8 · High

CVE-2023-23916

Published Feb 23, 2023

An allocation of resources without limits or throttling vulnerability exists in curl <v7.88.0 based on the "chained" HTTP compression algorithms, meaning that a server response ca…

CVSS 6.5 · Medium

CVE-2023-23915

Published Feb 23, 2023

A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality to behave incorrectly when multiple URLs are requested…

CVSS 6.5 · Medium

CVE-2023-23914

Published Feb 23, 2023

A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality fail when multiple URLs are requested serially. Using i…

CVSS 9.1 · Critical

CVE-2022-35260

Published Dec 5, 2022

curl can be told to parse a `.netrc` file for credentials. If that file endsin a line with 4095 consecutive non-white space letters and no newline, curlwould first read past the e…

CVSS 6.5 · Medium

CVE-2022-32221

Published Dec 5, 2022

When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been…

CVSS 9.8 · Critical
Showing 1-25 of 186 CVEsPage 1 of 8