Vulnerabilities > Netapp

DATE CVE VULNERABILITY TITLE RISK
2017-02-07 CVE-2016-4341 Information Exposure vulnerability in Netapp Clustered Data Ontap
NetApp Clustered Data ONTAP before 8.3.2P7 allows remote attackers to obtain SMB share information via unspecified vectors.
network
low complexity
netapp CWE-200
7.5
2017-02-07 CVE-2016-3063 Improper Encoding or Escaping of Output vulnerability in Netapp Oncommand System Manager
Multiple functions in NetApp OnCommand System Manager before 8.3.2 do not properly escape special characters, which allows remote authenticated users to execute arbitrary API calls via unspecified vectors.
network
high complexity
netapp CWE-116
7.5
2017-02-07 CVE-2016-1894 Improper Access Control vulnerability in Netapp Oncommand Workflow Automation 2.2.1/3.0/3.1
NetApp OnCommand Workflow Automation before 3.1P2 allows remote attackers to bypass authentication via unspecified vectors.
network
high complexity
netapp CWE-284
8.1
2017-02-07 CVE-2016-1502 Improper Authentication vulnerability in Netapp Snapcenter Server 1.0
NetApp SnapCenter Server 1.0 and 1.0P1 allows remote attackers to partially bypass authentication and then list and delete backups via unspecified vectors.
network
low complexity
netapp CWE-287
7.3
2017-02-07 CVE-2015-8544 Information Exposure vulnerability in Netapp Snapdrive
NetApp SnapDrive for Windows before 7.0.2P4, 7.0.3, and 7.1 before 7.1.3P1 allows remote attackers to obtain sensitive information via unspecified vectors.
network
low complexity
netapp CWE-200
7.5
2017-02-07 CVE-2015-8322 Unspecified vulnerability in Netapp Data Ontap 8.3/8.3.1
NetApp OnCommand System Manager 8.3.x before 8.3.2 allows remote authenticated users to execute arbitrary code via unspecified vectors.
network
low complexity
netapp
8.8
2017-02-03 CVE-2016-10165 Out-of-bounds Read vulnerability in multiple products
The Type_MLU_Read function in cmstypes.c in Little CMS (aka lcms2) allows remote attackers to obtain sensitive information or cause a denial of service via an image with a crafted ICC profile, which triggers an out-of-bounds heap read.
7.1
2017-02-02 CVE-2017-5600 Use of Hard-coded Credentials vulnerability in Netapp Oncommand Insight
The Data Warehouse component in NetApp OnCommand Insight before 7.2.3 allows remote attackers to obtain administrative access by leveraging a default privileged account.
network
low complexity
netapp CWE-798
critical
9.8
2017-01-30 CVE-2016-2518 Out-of-bounds Read vulnerability in multiple products
The MATCH_ASSOC function in NTP before version 4.2.8p9 and 4.3.x before 4.3.92 allows remote attackers to cause an out-of-bounds reference via an addpeer request with a large hmode value.
network
low complexity
ntp debian netapp oracle redhat freebsd siemens CWE-125
5.3
2017-01-30 CVE-2015-7977 NULL Pointer Dereference vulnerability in multiple products
ntpd in NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to cause a denial of service (NULL pointer dereference) via a ntpdc reslist command.
5.9