Netapp

Oncommand Insight

969 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.84%
  • Published 09.09.2019 17:15:13
  • Last modified 21.11.2024 04:30:11

In SQLite through 3.29.0, whereLoopAddBtreeIndex in sqlite3.c can crash a browser or other application because of missing validation of a sqlite_stat1 sz field, aka a "severe division by zero in the query planner."

  • EPSS 0.33%
  • Published 09.08.2019 18:15:12
  • Last modified 21.11.2024 04:45:03

OnCommand Insight versions through 7.3.6 may disclose sensitive account information to an authenticated user.

  • EPSS 0.95%
  • Published 02.07.2019 19:15:10
  • Last modified 21.11.2024 04:44:56

A non-privileged user or program can put code and a config file in a known non-privileged path (under C:/usr/local/) that will make curl <= 7.65.1 automatically run the code (as an openssl "engine") on invocation. If that curl is invoked by a privile...

  • EPSS 1.21%
  • Published 01.07.2019 02:15:09
  • Last modified 21.11.2024 04:24:13

In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an invalid character/length combination could be passed to xsltNumberFormatDecimal, leading to a read of uninitialized stack data.

  • EPSS 0.21%
  • Published 10.05.2019 20:29:00
  • Last modified 21.11.2024 04:45:03

Oncommand Insight versions prior to 7.3.5 shipped without certain HTTP Security headers configured which could allow an attacker to obtain sensitive information via unspecified vectors.

  • EPSS 1.01%
  • Published 10.04.2019 20:29:01
  • Last modified 21.11.2024 04:20:28

libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead can return -1 for a crafted URL that is not actually invalid and is su...

  • EPSS 5.05%
  • Published 27.02.2019 23:29:00
  • Last modified 21.11.2024 04:36:48

If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid...

Exploit
  • EPSS 26.44%
  • Published 06.02.2019 20:29:00
  • Last modified 21.11.2024 04:42:36

libcurl versions from 7.36.0 to before 7.64.0 are vulnerable to a stack-based buffer overflow. The function creating an outgoing NTLM type-3 header (`lib/vauth/ntlm.c:Curl_auth_create_ntlm_type3_message()`), generates the request HTTP header contents...

Exploit
  • EPSS 0.99%
  • Published 04.02.2019 08:29:00
  • Last modified 21.11.2024 04:48:00

png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_safe_execute.

  • EPSS 0.41%
  • Published 16.01.2019 19:30:34
  • Last modified 21.11.2024 04:41:00

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 8.0.13 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols...