NetApp / E-Series Santricity OS Controller
242 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2024-6387 | Openssh: regresshion - race condition in ssh allows rce/dos | HIGH | 8.1 | Jul 1, 2024 |
| CVE-2024-26735 | ipv6: sr: fix possible use-after-free and null-ptr-deref | MEDIUM | 5.5 | Apr 3, 2024 |
| CVE-2024-26733 | arp: Prevent overflow in arp_req_get(). | MEDIUM | 5.5 | Apr 3, 2024 |
| CVE-2023-26049 | Cookie parsing of quoted values can exfiltrate values from other cookies in Eclipse Jetty | MEDIUM | 5.3 | Apr 18, 2023 |
| CVE-2022-39399 | OpenJDK: missing SNI caching in HTTP/2 (Networking, 8289366) | LOW | 3.7 | Oct 18, 2022 |
| CVE-2022-21628 | OpenJDK: HttpServer no connection count limit (Lightweight HTTP Server, 8286918) | MEDIUM | 5.3 | Oct 18, 2022 |
| CVE-2022-21626 | OpenJDK: excessive memory allocation in X.509 certificate parsing (Security, 8286533) | MEDIUM | 5.3 | Oct 18, 2022 |
| CVE-2022-21624 | OpenJDK: insufficient randomization of JNDI DNS port numbers (JNDI, 8286910) | LOW | 3.7 | Oct 18, 2022 |
| CVE-2022-21619 | OpenJDK: improper handling of long NTLM client hostnames (Security, 8286526) | LOW | 3.7 | Oct 18, 2022 |
| CVE-2022-21618 | OpenJDK: improper MultiByte conversion can lead to buffer overflow (JGSS, 8286077) | MEDIUM | 5.3 | Oct 18, 2022 |
| CVE-2022-36879 | kernel: xfrm_expand_policies() in net/xfrm/xfrm_policy.c can cause a refcount to be dropped twice | MEDIUM | 5.5 | Jul 27, 2022 |
| CVE-2022-23237 | E-Series SANtricity OS Controller Software 11.x versions through 11.70.2 are vulnerable to host header injection attacks that could allow an attacker to redire… | MEDIUM | 6.1 | Jun 1, 2022 |
| CVE-2022-23236 | E-Series SANtricity OS Controller Software versions 11.40 through 11.70.2 store the LDAP BIND password in plaintext within a file accessible only to privileged… | MEDIUM | 4.4 | Jun 1, 2022 |
| CVE-2022-1678 | kernel: improper update of sock reference in TCP pacing can lead to memory leak | HIGH | 7.5 | May 25, 2022 |
| CVE-2022-21496 | OpenJDK: URI parsing inconsistencies (JNDI, 8278972) | MEDIUM | 5.3 | Apr 19, 2022 |
| CVE-2022-21476 | OpenJDK: Defective secure validation in Apache Santuario (Libraries, 8278008) | HIGH | 7.5 | Apr 19, 2022 |
| CVE-2022-21449 | OpenJDK: Improper ECDSA signature verification (Libraries, 8277233) | HIGH | 7.5 | Apr 19, 2022 |
| CVE-2022-21443 | OpenJDK: Missing check for negative ObjectIdentifier (Libraries, 8275151) | LOW | 3.7 | Apr 19, 2022 |
| CVE-2022-21434 | OpenJDK: Improper object-to-string conversion in AnnotationInvocationHandler (Libraries, 8277672) | MEDIUM | 5.3 | Apr 19, 2022 |
| CVE-2022-21426 | OpenJDK: Unbounded memory allocation when compiling crafted XPath expressions (JAXP, 8270504) | MEDIUM | 5.3 | Apr 19, 2022 |
| CVE-2021-4203 | kernel: Race condition in races in sk_peer_pid and sk_peer_cred accesses | MEDIUM | 6.8 | Mar 25, 2022 |
| CVE-2018-25032 | zlib: A flaw found in zlib when compressing (not decompressing) certain inputs | HIGH | 8.2 | Mar 25, 2022 |
| CVE-2021-3772 | kernel: sctp: Invalid chunks may be used to remotely remove existing associations | MEDIUM | 6.5 | Mar 2, 2022 |
| CVE-2020-36516 | kernel: off-path attacker may inject data or terminate victim's TCP session | MEDIUM | 5.9 | Feb 26, 2022 |
| CVE-2021-20322 | kernel: new DNS Cache Poisoning Attack based on ICMP fragment needed packets replies | HIGH | 7.4 | Feb 18, 2022 |
Showing 1 to 25 of 242 CVEs