NetApp / Oncommand Balance
83 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2017-3140 | An error processing RPZ rules can cause named to loop endlessly after handling a query | MEDIUM | 5.9 | Jan 16, 2019 |
| CVE-2017-3138 | named exits with a REQUIRE assertion failure if it receives a null command string on its control channel | MEDIUM | 6.5 | Jan 16, 2019 |
| CVE-2017-3137 | A response packet can cause a resolver to terminate when processing an answer containing a CNAME or DNAME | HIGH | 7.5 | Jan 16, 2019 |
| CVE-2017-3136 | An error handling synthesized records could cause an assertion failure when using DNS64 with "break-dnssec yes;" | MEDIUM | 5.9 | Jan 16, 2019 |
| CVE-2017-7525 | jackson-databind: Deserialization vulnerability via readValue method of ObjectMapper | CRITICAL | 9.8 | Feb 6, 2018 |
| CVE-2017-15095 | jackson-databind: Unsafe deserialization due to incomplete black list (incomplete fix for CVE-2017-7525) | CRITICAL | 9.8 | Feb 6, 2018 |
| CVE-2017-15707 | struts2: Crafted JSON request can result in DoS | HIGH | 7.5 | Dec 1, 2017 |
| CVE-2016-8610 | SSL/TLS: Malformed plain-text ALERT packets could cause remote DoS | HIGH | 7.5 | Nov 13, 2017 |
| CVE-2017-10388 | OpenJDK: use of unprotected sname in Kerberos client (Libraries, 8178794) | HIGH | 7.5 | Oct 19, 2017 |
| CVE-2017-10384 | mysql: Server: DDL unspecified vulnerability (CPU Oct 2017) | MEDIUM | 6.5 | Oct 19, 2017 |
| CVE-2017-10379 | mysql: Client programs unspecified vulnerability (CPU Oct 2017) | MEDIUM | 6.5 | Oct 19, 2017 |
| CVE-2017-10378 | mysql: Server: Optimizer unspecified vulnerability (CPU Oct 2017) | MEDIUM | 6.5 | Oct 19, 2017 |
| CVE-2017-10365 | mysql: Server: InnoDB unspecified vulnerability (CPU Oct 2017) | LOW | 3.8 | Oct 19, 2017 |
| CVE-2017-10357 | OpenJDK: unbounded memory allocation in ObjectInputStream deserialization (Serialization, 8181597) | MEDIUM | 5.3 | Oct 19, 2017 |
| CVE-2017-10356 | OpenJDK: weak protection of key stores against brute forcing (Security, 8181692) | MEDIUM | 6.2 | Oct 19, 2017 |
| CVE-2017-10355 | OpenJDK: no default network operations timeouts in FtpClient (Networking, 8181612) | MEDIUM | 5.3 | Oct 19, 2017 |
| CVE-2017-10350 | OpenJDK: unbounded memory allocation in JAXWSExceptionBase deserialization (JAX-WS, 8181100) | MEDIUM | 5.3 | Oct 19, 2017 |
| CVE-2017-10349 | OpenJDK: unbounded memory allocation in PredicatedNodeTest deserialization (JAXP, 8181327) | MEDIUM | 5.3 | Oct 19, 2017 |
| CVE-2017-10348 | OpenJDK: multiple unbounded memory allocations in deserialization (Libraries, 8181432) | MEDIUM | 5.3 | Oct 19, 2017 |
| CVE-2017-10347 | OpenJDK: unbounded memory allocation in SimpleTimeZone deserialization (Serialization, 8181323) | MEDIUM | 5.3 | Oct 19, 2017 |
| CVE-2017-10346 | OpenJDK: insufficient loader constraints checks for invokespecial (Hotspot, 8180711) | CRITICAL | 9.6 | Oct 19, 2017 |
| CVE-2017-10345 | OpenJDK: unbounded resource use in JceKeyStore deserialization (Serialization, 8181370) | LOW | 3.1 | Oct 19, 2017 |
| CVE-2017-10320 | mysql: Server: InnoDB unspecified vulnerability (CPU Oct 2017) | MEDIUM | 4.9 | Oct 19, 2017 |
| CVE-2017-10309 | JDK: unspecified vulnerability fixed in 8u151 and 9.0.1 (Deployment) | HIGH | 7.1 | Oct 19, 2017 |
| CVE-2017-10295 | OpenJDK: HTTP client insufficient check for newline in URLs (Networking, 8176751) | MEDIUM | 4.0 | Oct 19, 2017 |
Showing 1 to 25 of 83 CVEs