NetApp / Oncommand Unified Manager Core Package
11 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2021-3156 KEV | sudo: Heap buffer overflow in argument parsing | HIGH | 7.8 | Jan 26, 2021 |
| CVE-2021-23926 | XMLBeans XML Entity Expansion | CRITICAL | 9.1 | Jan 14, 2021 |
| CVE-2020-14779 | OpenJDK: High memory usage during deserialization of Proxy class with many interfaces (Serialization, 8236862) | LOW | 3.7 | Oct 21, 2020 |
| CVE-2020-14621 | OpenJDK: XML validation manipulation due to incomplete application of the use-grammar-pool-only feature (JAXP, 8242136) | MEDIUM | 5.3 | Jul 15, 2020 |
| CVE-2020-14002 | PuTTY 0.68 through 0.73 has an Observable Discrepancy leading to an information leak in the algorithm negotiation. This allows man-in-the-middle attackers to t… | MEDIUM | 5.9 | Jun 29, 2020 |
| CVE-2020-1927 | httpd: mod_rewrite configurations vulnerable to open redirect | MEDIUM | 6.1 | Apr 1, 2020 |
| CVE-2019-17069 | PuTTY before 0.73 might allow remote SSH-1 servers to cause a denial of service by accessing freed memory locations via an SSH1_MSG_DISCONNECT message. | HIGH | 7.5 | Oct 1, 2019 |
| CVE-2019-1559 | 0-byte record padding oracle | MEDIUM | 5.9 | Feb 27, 2019 |
| CVE-2017-15906 | openssh: Improper write operations in readonly mode allow for zero-length file creation | MEDIUM | 5.3 | Oct 26, 2017 |
| CVE-2017-7439 | NetApp OnCommand Unified Manager Core Package 5.x before 5.2.2P1 might allow remote attackers to obtain sensitive information via vectors involving error messa… | HIGH | 7.5 | May 25, 2017 |
| CVE-2017-7236 | SQL injection vulnerability in NetApp OnCommand Unified Manager Core Package 5.x before 5.2.2P1 allows remote attackers to execute arbitrary SQL commands via u… | HIGH | 7.5 | May 25, 2017 |
Showing 1 to 11 of 11 CVEs