VUMETRIC
CYBER PORTAL
Dashboard
Security News
Latest Vulnerabilities
Browse Vulnerabilities
by Vendors
by Products
by Categories
Weekly Reports
Vulnerabilities
> Netapp
Exclude new CVEs:
DATE
CVE
VULNERABILITY TITLE
RISK
2020-12-15
CVE-2020-29569
Use After Free vulnerability in multiple products
An issue was discovered in the Linux kernel through 5.10.1, as used with Xen through 4.14.x.
local
low complexity
xen
linux
netapp
debian
CWE-416
8.8
8.8
2020-12-14
CVE-2020-8286
Improper Certificate Validation vulnerability in multiple products
curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response.
network
low complexity
haxx
fedoraproject
debian
netapp
apple
siemens
oracle
splunk
CWE-295
7.5
7.5
2020-12-14
CVE-2020-8285
Uncontrolled Recursion vulnerability in multiple products
curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcard match parsing.
network
low complexity
haxx
debian
fedoraproject
netapp
apple
oracle
fujitsu
siemens
splunk
CWE-674
7.5
7.5
2020-12-14
CVE-2020-8284
A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP address and port, and this way potentially make curl extract information about services that are otherwise private and not disclosed, for example doing port scanning and service banner extractions.
network
high complexity
haxx
fedoraproject
debian
netapp
apple
oracle
fujitsu
siemens
splunk
3.7
3.7
2020-12-14
CVE-2020-29511
The encoding/xml package in Go (all versions) does not correctly preserve the semantics of element namespace prefixes during tokenization round-trips, which allows an attacker to craft inputs that behave in conflicting ways during different stages of processing in affected downstream applications.
network
high complexity
golang
netapp
5.6
5.6
2020-12-14
CVE-2020-29510
The encoding/xml package in Go versions 1.15 and earlier does not correctly preserve the semantics of directives during tokenization round-trips, which allows an attacker to craft inputs that behave in conflicting ways during different stages of processing in affected downstream applications.
network
high complexity
golang
netapp
5.6
5.6
2020-12-14
CVE-2020-29509
The encoding/xml package in Go (all versions) does not correctly preserve the semantics of attribute namespace prefixes during tokenization round-trips, which allows an attacker to craft inputs that behave in conflicting ways during different stages of processing in affected downstream applications.
network
high complexity
golang
netapp
5.6
5.6
2020-12-11
CVE-2020-27730
Path Traversal vulnerability in multiple products
In versions 3.0.0-3.9.0, 2.0.0-2.9.0, and 1.0.1, the NGINX Controller Agent does not use absolute paths when calling system utilities.
network
low complexity
f5
netapp
CWE-22
critical
9.8
9.8
2020-12-11
CVE-2020-27825
A use-after-free flaw was found in kernel/trace/ring_buffer.c in Linux kernel (before 5.10-rc1).
local
high complexity
linux
redhat
debian
netapp
5.7
5.7
2020-12-11
CVE-2020-27786
A flaw was found in the Linux kernel’s implementation of MIDI, where an attacker with a local account and the permissions to issue ioctl commands to midi devices could trigger a use-after-free issue.
local
low complexity
linux
redhat
netapp
7.8
7.8
«
Previous
1
2
...
81
82
83
(current)
84
85
...
180
181
»
Next