CVE-2020-8590
- EPSS 0.07%
- Published 08.02.2021 22:15:12
- Last modified 21.11.2024 05:39:05
Clustered Data ONTAP versions prior to 9.1P18 and 9.3P12 are susceptible to a vulnerability which could allow an attacker to discover node names via AutoSupport bundles even when the –remove-private-data parameter is set to true.
CVE-2020-8588
- EPSS 0.09%
- Published 03.02.2021 18:15:16
- Last modified 21.11.2024 05:39:04
Clustered Data ONTAP versions prior to 9.3P20 and 9.5P15 are susceptible to a vulnerability which could allow unauthorized tenant users to discover the existence of data on other Storage Virtual Machines (SVMs).
CVE-2020-8589
- EPSS 0.09%
- Published 03.02.2021 18:15:16
- Last modified 21.11.2024 05:39:05
Clustered Data ONTAP versions prior to 9.3P20 and 9.5P15 are susceptible to a vulnerability which could allow unauthorized tenant users to discover the names of other Storage Virtual Machines (SVMs) and filenames on those SVMs.
CVE-2020-8581
- EPSS 0.23%
- Published 19.01.2021 18:15:12
- Last modified 21.11.2024 05:39:04
Clustered Data ONTAP versions prior to 9.3P20 and 9.5 are susceptible to a vulnerability which could allow an authenticated but unauthorized attacker to overwrite arbitrary data when VMware vStorage support is enabled.
CVE-2020-8286
- EPSS 0.28%
- Published 14.12.2020 20:15:14
- Last modified 21.11.2024 05:38:39
curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response.
CVE-2020-8284
- EPSS 0.1%
- Published 14.12.2020 20:15:13
- Last modified 21.11.2024 05:38:39
A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP address and port, and this way potentially make curl extract information about services that are otherwise private and not disclosed,...
CVE-2020-8285
- EPSS 0.59%
- Published 14.12.2020 20:15:13
- Last modified 21.11.2024 05:38:39
curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcard match parsing.
CVE-2020-8696
- EPSS 0.12%
- Published 12.11.2020 18:15:16
- Last modified 21.11.2024 05:39:16
Improper removal of sensitive information before storage or transfer in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
CVE-2020-8698
- EPSS 0.21%
- Published 12.11.2020 18:15:16
- Last modified 21.11.2024 05:39:17
Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
CVE-2020-0590
- EPSS 0.36%
- Published 12.11.2020 18:15:13
- Last modified 21.11.2024 04:53:48
Improper input validation in BIOS firmware for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege via local access.