Netapp
Netapp Data Ontap Edge: vulnerabilidades y CVE
Netapp Data Ontap Edge tiene 23 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE23
Últimos 12 meses0
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2018-5740 | Alta (7.5) | 60% | — | 16 ene 2019 | "deny-answer-aliases" is a little-used feature intended to help recursive server operators protect end users against DNS rebinding attacks, a potential method of circumventing the security model used by client browsers.… |
| CVE-2018-5737 | Alta (7.5) | 10% | — | 16 ene 2019 | A problem with the implementation of the new serve-stale feature in BIND 9.12 can lead to an assertion failure in rbtdb.c, even when stale-answer-enable is off. Additionally, problematic interaction between the… |
| CVE-2018-5736 | Media (5.3) | 18% | — | 16 ene 2019 | An error in zone database reference counting can lead to an assertion failure if a server which is running an affected version of BIND attempts several transfers of a slave zone in quick succession. This defect could be… |
| CVE-2018-5734 | Alta (7.5) | 6.3% | — | 16 ene 2019 | While handling a particular type of malformed packet BIND erroneously selects a SERVFAIL rcode instead of a FORMERR rcode. If the receiving view has the SERVFAIL cache feature enabled, this can trigger an assertion… |
| CVE-2017-3145 | Alta (7.5) | 28% | — | 16 ene 2019 | BIND was improperly sequencing cleanup operations on upstream recursion fetch contexts, leading in some cases to a use-after-free error that can trigger an assertion failure and crash in named. Affects BIND 9.0.0 to… |
| CVE-2017-3140 | Media (5.9) | 12% | — | 16 ene 2019 | If named is configured to use Response Policy Zones (RPZ) an error processing some rule types can lead to a condition where BIND will endlessly loop while handling a query. Affects BIND 9.9.10, 9.10.5, 9.11.0->9.11.1,… |
| CVE-2017-3138 | Media (5.3) | 5.5% | — | 16 ene 2019 | named contains a feature which allows operators to issue commands to a running server by communicating with the server process over a control channel, using a utility program such as rndc. A regression introduced in a… |
| CVE-2017-3137 | Alta (7.5) | 9.0% | — | 16 ene 2019 | Mistaken assumptions about the ordering of records in the answer section of a response containing CNAME or DNAME resource records could lead to a situation in which named would exit with an assertion failure when… |
| CVE-2017-3136 | Media (5.9) | 11% | — | 16 ene 2019 | A query with a specific set of characteristics could cause a server using DNS64 to encounter an assertion failure and terminate. An attacker could deliberately construct a query, enabling denial-of-service against a… |
| CVE-2017-3135 | Media (5.9) | 17% | — | 16 ene 2019 | Under some conditions when using both DNS64 and RPZ to rewrite query responses, query processing can resume in an inconsistent state leading to either an INSIST assertion failure or an attempt to read through a NULL… |
| CVE-2016-9778 | Media (5.9) | 6.8% | — | 16 ene 2019 | An error in handling certain queries can cause an assertion failure when a server is using the nxdomain-redirect feature to cover a zone for which it is also providing authoritative service. A vulnerable server could be… |
| CVE-2018-15919 | Media (5.3) | 3.6% | — | 28 ago 2018 | Remotely observable behaviour in auth-gss2.c in OpenSSH through 7.8 could be used by remote attackers to detect existence of users on a target system when GSS2 is in use. NOTE: the discoverer states 'We understand that… |
| CVE-2018-15473 | Media (5.3) | 99% | — | 17 ago 2018 | OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet containing the request has been fully parsed, related to… |
| CVE-2018-12015 | Alta (7.5) | 7.3% | — | 7 jun 2018 | In Perl through 5.26.2, the Archive::Tar module allows remote attackers to bypass a directory-traversal protection mechanism, and overwrite arbitrary files, via an archive file containing a symlink and a regular file… |
| CVE-2018-11237 | Alta (7.8) | 0.88% | — | 18 may 2018 | An AVX-512-optimized implementation of the mempcpy function in the GNU C Library (aka glibc or libc6) 2.27 and earlier may write data beyond the target buffer, leading to a buffer overflow in… |
| CVE-2018-11236 | Crítica (9.8) | 7.1% | — | 18 may 2018 | stdlib/canonicalize.c in the GNU C Library (aka glibc or libc6) 2.27 and earlier, when processing very long pathname arguments to the realpath function, could encounter an integer overflow on 32-bit architectures,… |
| CVE-2018-6485 | Crítica (9.8) | 4.7% | — | 1 feb 2018 | An integer overflow in the implementation of the posix_memalign in memalign functions in the GNU C Library (aka glibc or libc6) 2.26 and earlier could cause these functions to return a pointer to a heap area that is too… |
| CVE-2016-10708 | Alta (7.5) | 16% | — | 21 ene 2018 | sshd in OpenSSH before 7.4 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an out-of-sequence NEWKEYS message, as demonstrated by Honggfuzz, related to kex.c and… |
| CVE-2016-8610 | Alta (7.5) | 40% | — | 13 nov 2017 | A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined processing of ALERT packets during a connection handshake. A remote attacker could use… |
| CVE-2017-15906 | Media (5.3) | 3.4% | — | 26 oct 2017 | The process_open function in sftp-server.c in OpenSSH before 7.6 does not properly prevent write operations in readonly mode, which allows attackers to create zero-length files. |
| CVE-2016-9131 | Alta (7.5) | 41% | — | 12 ene 2017 | named in ISC BIND 9.x before 9.9.9-P5, 9.10.x before 9.10.4-P5, and 9.11.x before 9.11.0-P2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed response to an RTYPE… |
| CVE-2016-8864 | Alta (7.5) | 39% | — | 2 nov 2016 | named in ISC BIND 9.x before 9.9.9-P4, 9.10.x before 9.10.4-P4, and 9.11.x before 9.11.0-P1 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a DNAME record in the answer… |
| CVE-2015-8960 | Alta (8.1) | 1.9% | — | 21 sept 2016 | The TLS protocol 1.2 and earlier supports the rsa_fixed_dh, dss_fixed_dh, rsa_fixed_ecdh, and ecdsa_fixed_ecdh values for ClientCertificateType but does not directly document the ability to compute the master secret in… |
Otros productos de Netapp
Oncommand Insight · 971Active IQ Unified Manager · 848Oncommand Workflow Automation · 743Snapcenter · 575Cloud Backup · 349H700s Firmware · 294H500s Firmware · 293H410s Firmware · 293H300s Firmware · 293E-series Santricity OS Controller · 242H410c Firmware · 241Steelstore Cloud Integrated Storage · 211