Netapp

Clustered Data Ontap

144 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.37%
  • Veröffentlicht 21.05.2017 19:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The i_zval_ptr_dtor function in Zend/zend_variables.h in PHP 7.1.5 allows attackers to cause a denial of service (memory consumption and application crash) or possibly have unspecified other impact by triggering crafted operations on array data struc...

  • EPSS 0.6%
  • Veröffentlicht 10.04.2017 15:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

NetApp Clustered Data ONTAP 8.1 through 9.1P1, when NFS or SMB is enabled, allows remote attackers to cause a denial of service via unspecified vectors.

  • EPSS 0.2%
  • Veröffentlicht 10.04.2017 15:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

NetApp OnCommand Performance Manager and OnCommand Unified Manager for Clustered Data ONTAP before 7.1P1 improperly bind the Java Management Extension Remote Method Invocation (aka JMX RMI) service to the network, which allows remote attackers to obt...

  • EPSS 0.48%
  • Veröffentlicht 07.02.2017 17:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

NetApp Clustered Data ONTAP before 8.3.2P7 allows remote attackers to obtain SMB share information via unspecified vectors.

  • EPSS 1.47%
  • Veröffentlicht 30.01.2017 21:59:01
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The MATCH_ASSOC function in NTP before version 4.2.8p9 and 4.3.x before 4.3.92 allows remote attackers to cause an out-of-bounds reference via an addpeer request with a large hmode value.

  • EPSS 4.59%
  • Veröffentlicht 30.01.2017 21:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

NTP before 4.2.8p6 and 4.3.x before 4.3.90, when configured in broadcast mode, allows man-in-the-middle attackers to conduct replay attacks by sniffing the network.

  • EPSS 9.71%
  • Veröffentlicht 30.01.2017 21:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

ntpd in NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to cause a denial of service (NULL pointer dereference) via a ntpdc reslist command.

  • EPSS 3.77%
  • Veröffentlicht 24.01.2017 21:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Off-by-one error in the phar_parse_pharfile function in ext/phar/phar.c in PHP before 5.6.30 and 7.0.x before 7.0.15 allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted PHAR archiv...

  • EPSS 0.25%
  • Veröffentlicht 11.01.2017 16:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Clustered Data ONTAP versions 8.0, 8.3.1, and 8.3.2 contain a default privileged account which under certain conditions can be used for unauthorized information disclosure.

Exploit
  • EPSS 5.23%
  • Veröffentlicht 11.01.2017 07:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The SplObjectStorage unserialize implementation in ext/spl/spl_observer.c in PHP before 7.0.12 does not verify that a key is an object, which allows remote attackers to execute arbitrary code or cause a denial of service (uninitialized memory access)...