NetApp / Vasa Provider for Clustered Data Ontap
69 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2021-28165 | jetty: Resource exhaustion when receiving an invalid large TLS frame | HIGH | 7.5 | Apr 1, 2021 |
| CVE-2021-28164 | jetty: Ambiguous paths can access WEB-INF | MEDIUM | 5.3 | Apr 1, 2021 |
| CVE-2021-28163 | jetty: Symlink directory exposes webapp directory contents | LOW | 2.7 | Apr 1, 2021 |
| CVE-2020-13954 | Apache CXF Reflected XSS in the services listing page via the styleSheetPath | MEDIUM | 6.1 | Nov 12, 2020 |
| CVE-2020-11868 | ntp: DoS on client ntpd using server mode packet | HIGH | 7.5 | Apr 17, 2020 |
| CVE-2019-11815 | kernel: race condition in rds_tcp_kill_sock in net/rds/tcp.c leading to use-after-free | HIGH | 8.1 | May 8, 2019 |
| CVE-2018-20836 | kernel: race condition in smp_task_timedout() and smp_task_done() in drivers/scsi/libsas/sas_expander.c leads to use-after-free | HIGH | 8.1 | May 7, 2019 |
| CVE-2019-3900 | Kernel: vhost_net: infinite loop while receiving packets leads to DoS | HIGH | 7.7 | Apr 25, 2019 |
| CVE-2019-3882 | kernel: denial of service vector through vfio DMA mappings | MEDIUM | 5.5 | Apr 24, 2019 |
| CVE-2019-11486 | kernel: multiple race conditions in Siemens R3964 line discipline driver in drivers/tty/n_r3964.c leading to denial of service | HIGH | 7.0 | Apr 23, 2019 |
| CVE-2019-10247 | jetty: error path information disclosure | MEDIUM | 5.3 | Apr 22, 2019 |
| CVE-2019-10246 | jetty: Directory Listing on Windows reveals Resource Base path | MEDIUM | 5.3 | Apr 22, 2019 |
| CVE-2019-3901 | kernel: perf_event_open() and execve() race in setuid programs allows a data leak | MEDIUM | 4.7 | Apr 22, 2019 |
| CVE-2018-2973 | JDK: unspecified vulnerability fixed in 6u201, 7u191, 8u181, and 10.0.2 (JSSE) | MEDIUM | 5.9 | Jul 18, 2018 |
| CVE-2018-2964 | JDK: unspecified vulnerability fixed in 8u181 and 10.0.2 (Deployment) | HIGH | 8.3 | Jul 18, 2018 |
| CVE-2018-2952 | OpenJDK: insufficient index validation in PatternSyntaxException getMessage() (Concurrency, 8199547) | LOW | 3.7 | Jul 18, 2018 |
| CVE-2018-2942 | JDK: unspecified vulnerability fixed in 7u191 and 8u181 (Windows DLL) | HIGH | 8.3 | Jul 18, 2018 |
| CVE-2018-2941 | JDK: unspecified vulnerability fixed in 7u191, 8u181, and 10.0.2 (JavaFX) | HIGH | 8.3 | Jul 18, 2018 |
| CVE-2018-2940 | JDK: unspecified vulnerability fixed in 6u201, 7u191, 8u181, and 10.0.2 (Libraries) | MEDIUM | 4.3 | Jul 18, 2018 |
| CVE-2018-2938 | JDK: unspecified vulnerability fixed in 6u201, 7u191, and 8u181 (Java DB) | CRITICAL | 9.0 | Jul 18, 2018 |
| CVE-2018-2638 | JDK: unspecified vulnerability fixed in 8u161 and 9.0.4 (Deployment) | HIGH | 8.3 | Jan 18, 2018 |
| CVE-2018-2627 | JDK: unspecified vulnerability fixed in 8u161 and 9.0.4 (Installer) | HIGH | 7.5 | Jan 18, 2018 |
| CVE-2018-2581 | JDK: unspecified vulnerability fixed in 7u171, 8u161, and 9.0.4 (JavaFX) | MEDIUM | 4.7 | Jan 18, 2018 |
| CVE-2016-6904 | Versions of VASA Provider for Clustered Data ONTAP prior to 7.0P1 contain a web server that accepts plain text authentication. This could allow an unauthentica… | HIGH | 8.1 | Dec 11, 2017 |
| CVE-2017-15906 | openssh: Improper write operations in readonly mode allow for zero-length file creation | MEDIUM | 5.3 | Oct 26, 2017 |
Showing 1 to 25 of 69 CVEs