📦 Active Iq Unified Manager

by Netapp

🔍 What is Active Iq Unified Manager?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-52533

CRITICAL CVSS 9.8 Nov 11, 2024

This vulnerability is a buffer overflow in GLib's SOCKS4 proxy implementation due to an off-by-one error. It allows attackers to execute arbitrary code or cause denial of service by sending specially ...

CVE-2021-32292

CRITICAL CVSS 9.8 Aug 22, 2023

This is a stack buffer overflow vulnerability in json-c's auxiliary sample program json_parse. It allows attackers to execute arbitrary code or cause denial of service by providing malicious JSON inpu...

CVE-2023-23914

CRITICAL CVSS 9.1 Feb 23, 2023

A vulnerability in curl versions before 7.88.0 causes HSTS (HTTP Strict Transport Security) to fail when processing multiple URLs sequentially on the same command line. This allows sensitive informati...

CVE-2022-1587

CRITICAL CVSS 9.1 May 16, 2022

An out-of-bounds read vulnerability in PCRE2 library's JIT compiler allows reading memory beyond allocated buffers during recursive regular expression processing. This affects any software using PCRE2...

CVE-2021-44228

CRITICAL CVSS 10.0 Dec 10, 2021

CVE-2021-44228 (Log4Shell) is a critical remote code execution vulnerability in Apache Log4j2 that allows attackers to execute arbitrary code by exploiting JNDI lookups in log messages. This affects a...

CVE-2021-22931

CRITICAL CVSS 9.8 Aug 16, 2021

Node.js DNS library vulnerability allows remote code execution, XSS, and application crashes due to improper validation of DNS responses. Attackers can inject malicious hostnames leading to domain hij...

CVE-2021-35942

CRITICAL CVSS 9.1 Jul 22, 2021

This vulnerability in glibc's wordexp function allows attackers to cause denial of service or potentially read arbitrary memory when processing malicious input. It affects any application using glibc'...

CVE-2021-3520

CRITICAL CVSS 9.8 Jun 2, 2021

CVE-2021-3520 is an integer overflow vulnerability in the LZ4 compression library that allows attackers to trigger out-of-bounds writes by submitting crafted files. This can lead to application crashe...

CVE-2021-20231

CRITICAL CVSS 9.8 Mar 12, 2021

This CVE-2021-20231 is a critical use-after-free vulnerability in GnuTLS that occurs when a client sends a key_share extension, potentially leading to memory corruption. Attackers could exploit this t...

CVE-2021-3177

CRITICAL CVSS 9.8 Jan 19, 2021

This is a buffer overflow vulnerability in Python's ctypes module that could allow remote code execution. It affects Python applications that process untrusted floating-point numbers through ctypes. T...

CVE-2025-24928

HIGH CVSS 7.8 Feb 18, 2025

This CVE describes a stack-based buffer overflow vulnerability in libxml2's xmlSnprintfElements function. Attackers can exploit this by providing malicious XML documents with DTD validation enabled, p...

CVE-2025-0411

HIGH CVSS 7.0 Jan 25, 2025

This vulnerability allows attackers to bypass Windows' Mark-of-the-Web security feature when extracting files with 7-Zip. Attackers can craft malicious archives that, when extracted, don't inherit the...

CVE-2024-47561

HIGH CVSS 7.3 Oct 3, 2024

This vulnerability in Apache Avro's Java SDK allows attackers to execute arbitrary code by exploiting schema parsing flaws. It affects all users of Apache Avro versions 1.11.3 and earlier. The vulnera...

CVE-2024-7254

HIGH CVSS 7.5 Sep 19, 2024

This vulnerability allows attackers to cause a stack overflow by sending malicious Protocol Buffers data with deeply nested groups, potentially crashing applications. It affects any system using Googl...

CVE-2024-2398

HIGH CVSS 8.6 Mar 27, 2024

CVE-2024-2398 is a memory leak vulnerability in libcurl that occurs when HTTP/2 server push headers exceed the 1000-header limit. This allows attackers to cause denial of service through resource exha...

CVE-2024-22259

HIGH CVSS 8.1 Mar 16, 2024

Spring Framework applications using UriComponentsBuilder to parse external URLs with host validation are vulnerable to open redirect and SSRF attacks. Attackers can manipulate URLs to bypass validatio...

CVE-2024-28757

HIGH CVSS 7.5 Mar 10, 2024

CVE-2024-28757 is an XML Entity Expansion vulnerability in libexpat that allows attackers to cause denial of service through resource exhaustion when external parsers are created via XML_ExternalEntit...

CVE-2024-26461

HIGH CVSS 7.5 Feb 29, 2024

CVE-2024-26461 is a memory leak vulnerability in Kerberos 5's GSSAPI sealing implementation that can lead to denial of service through resource exhaustion. Systems using krb5 1.21.2 for authentication...

CVE-2023-6516

HIGH CVSS 7.5 Feb 13, 2024

This vulnerability in BIND 9 DNS resolver allows attackers to cause uncontrolled memory growth by triggering specific query patterns that overwhelm cache cleanup mechanisms. Affected systems running B...

CVE-2023-5679

HIGH CVSS 7.5 Feb 13, 2024

A vulnerability in BIND DNS servers where enabling both DNS64 and serve-stale features can cause named to crash during recursive resolution. This affects BIND 9 installations with these specific featu...

CVE-2024-0567

HIGH CVSS 7.5 Jan 16, 2024

A vulnerability in GnuTLS causes Cockpit to reject certificate chains with distributed trust when using cockpit-certificate-ensure, allowing unauthenticated remote attackers to trigger denial of servi...

CVE-2023-31102

HIGH CVSS 7.8 Nov 3, 2023

This vulnerability in 7-Zip's PPMd7 compression module allows attackers to craft malicious 7Z archives that trigger an integer underflow, leading to invalid memory reads. Successful exploitation could...

CVE-2023-5178

HIGH CVSS 8.8 Nov 1, 2023

This CVE describes a use-after-free vulnerability in the NVMe/TCP subsystem of the Linux kernel that could allow attackers to execute arbitrary code or escalate privileges. It affects Linux systems wi...

CVE-2023-41105

HIGH CVSS 7.5 Aug 23, 2023

A vulnerability in Python 3.11 through 3.11.4 allows path truncation via null bytes in os.path.normpath(). This can bypass security checks that previously rejected malicious filenames, potentially ena...

CVE-2023-37920

HIGH CVSS 7.5 Jul 25, 2023

This vulnerability affects systems using certifi Python package versions before 2023.07.22, which included compromised e-Tugra root certificates. Attackers could perform man-in-the-middle attacks or s...

CVE-2023-2829

HIGH CVSS 7.5 Jun 21, 2023

A vulnerability in BIND 9 DNS servers configured with DNSSEC validation and aggressive cache usage allows remote attackers to cause denial of service by sending specially crafted NSEC records. This af...

CVE-2023-2953

HIGH CVSS 7.5 May 30, 2023

This vulnerability in OpenLDAP causes a null pointer dereference in the ber_memalloc_x() function, which can lead to denial of service (DoS) by crashing the LDAP service. Any system running vulnerable...

CVE-2023-27533

HIGH CVSS 8.8 Mar 30, 2023

A vulnerability in curl versions before 8.0 allows attackers to inject malicious content during TELNET protocol negotiation when user input is accepted. This could lead to arbitrary code execution on ...

CVE-2023-27534

HIGH CVSS 8.8 Mar 30, 2023

A path traversal vulnerability in curl's SFTP implementation allows attackers to bypass path filtering by using specially crafted paths containing tilde characters. This affects curl versions before 8...

CVE-2023-24329

HIGH CVSS 7.5 Feb 17, 2023

This vulnerability in Python's urllib.parse component allows attackers to bypass URL blocklisting mechanisms by using URLs that begin with blank characters (like spaces or tabs). This affects applicat...

CVE-2023-0361

HIGH CVSS 7.4 Feb 15, 2023

This CVE describes a timing side-channel vulnerability in GnuTLS that allows attackers to perform Bleichenbacher-style attacks against RSA encryption. By sending specially crafted messages to vulnerab...

CVE-2022-27778

HIGH CVSS 8.1 Jun 2, 2022

This vulnerability in curl versions before 7.83.1 could cause the wrong file to be deleted when using the --no-clobber option with --remove-on-error. It affects systems using curl with these specific ...

CVE-2022-24903

HIGH CVSS 8.1 May 6, 2022

Rsyslog's TCP syslog reception modules contain a heap buffer overflow vulnerability when octet-counted framing is used. This can cause segmentation faults or system malfunctions, with potential for re...

CVE-2022-1292

HIGH CVSS 7.3 May 3, 2022

CVE-2022-1292 is a command injection vulnerability in the c_rehash script distributed with OpenSSL. It allows attackers to execute arbitrary commands with script privileges when the script processes u...

CVE-2022-1473

HIGH CVSS 7.5 May 3, 2022

A memory leak vulnerability in OpenSSL's OPENSSL_LH_flush() function causes unbounded memory growth when processing certificates or keys. This affects long-lived processes like TLS clients/servers usi...

CVE-2022-25647

HIGH CVSS 7.7 May 1, 2022

CVE-2022-25647 is a deserialization vulnerability in Google's Gson library versions before 2.8.9. Attackers can exploit the writeReplace() method in internal classes to cause denial of service (DoS) a...

CVE-2022-21476

HIGH CVSS 7.5 Apr 19, 2022

This vulnerability in Oracle Java SE and GraalVM Enterprise Edition allows unauthenticated remote attackers to access sensitive data from Java applications. It affects Java deployments running sandbox...

CVE-2022-21449

HIGH CVSS 7.5 Apr 19, 2022

This vulnerability in Oracle Java SE and GraalVM Enterprise Edition allows unauthenticated attackers with network access to modify critical data without authorization. It affects Java deployments runn...

CVE-2015-20107

HIGH CVSS 7.6 Apr 13, 2022

This vulnerability in Python's mailcap module allows shell command injection when applications call mailcap.findmatch() with untrusted input. Attackers can execute arbitrary commands on affected syste...

CVE-2022-28796

HIGH CVSS 7.0 Apr 8, 2022

CVE-2022-28796 is a use-after-free vulnerability in the Linux kernel's jbd2 journaling subsystem caused by a transaction_t race condition. This allows local attackers to potentially escalate privilege...

CVE-2018-25032

HIGH CVSS 7.5 Mar 25, 2022

This vulnerability in zlib allows memory corruption during compression (deflating) when processing input with many distant matches. It affects any software using vulnerable zlib versions for compressi...

CVE-2022-27223

HIGH CVSS 8.8 Mar 16, 2022

This vulnerability allows a malicious USB device host to manipulate endpoint indexes in the Linux kernel's Xilinx USB gadget driver, leading to out-of-bounds array access. It affects Linux systems usi...

CVE-2020-36518

HIGH CVSS 7.5 Mar 11, 2022

CVE-2020-36518 is a denial-of-service vulnerability in Jackson Databind where processing deeply nested JSON objects causes a Java StackOverflowError, crashing the application. This affects any Java ap...

CVE-2022-26488

HIGH CVSS 7.0 Mar 10, 2022

This CVE allows local Windows users to escalate privileges by hijacking the system search path. The Python installer on Windows can incorrectly add user-writable directories to PATH during repair oper...

CVE-2022-23308

HIGH CVSS 7.5 Feb 26, 2022

CVE-2022-23308 is a use-after-free vulnerability in libxml2's validation component that allows attackers to potentially execute arbitrary code or cause denial of service. It affects applications that ...

CVE-2022-24407

HIGH CVSS 8.8 Feb 24, 2022

CVE-2022-24407 is a SQL injection vulnerability in Cyrus SASL authentication library. It allows attackers to inject arbitrary SQL commands via unescaped passwords in SQL INSERT/UPDATE statements. Syst...

CVE-2021-20322

HIGH CVSS 7.4 Feb 18, 2022

This Linux kernel vulnerability allows remote attackers to bypass UDP source port randomization by exploiting flaws in ICMP error processing. Attackers can scan open UDP ports more effectively, compro...

CVE-2022-0391

HIGH CVSS 7.5 Feb 9, 2022

This vulnerability in Python's urllib.parse module allows injection attacks via crafted URLs containing carriage return (\r) or line feed (\n) characters in the path component. Attackers can exploit t...

CVE-2022-23913

HIGH CVSS 7.5 Feb 4, 2022

This vulnerability in Apache ActiveMQ Artemis allows attackers to cause a denial-of-service (DoS) condition by consuming excessive memory resources. Systems running vulnerable versions of ActiveMQ Art...

CVE-2021-46143

HIGH CVSS 8.1 Jan 6, 2022

CVE-2021-46143 is an integer overflow vulnerability in Expat's XML parser that can lead to heap memory corruption. Attackers can exploit this by providing specially crafted XML input, potentially caus...

CVE-2025-30722

MEDIUM CVSS 5.3 Apr 15, 2025

A vulnerability in Oracle MySQL's mysqldump client allows low-privileged attackers with network access to potentially access or modify sensitive data. The vulnerability affects MySQL Client versions 8...

CVE-2025-31672

MEDIUM CVSS 5.3 Apr 9, 2025

This vulnerability allows attackers to create malicious OOXML files (like Excel, Word, or PowerPoint documents) with duplicate zip entries that can cause different applications to interpret the same f...

CVE-2025-26465

MEDIUM CVSS 6.8 Feb 18, 2025

This OpenSSH vulnerability allows machine-in-the-middle attacks when VerifyHostKeyDNS is enabled. Attackers can impersonate legitimate servers by exploiting error code mishandling during host key veri...

CVE-2025-1181

MEDIUM CVSS 5.0 Feb 11, 2025

A critical memory corruption vulnerability in GNU Binutils' linker component (ld) allows remote attackers to potentially execute arbitrary code or cause denial of service. This affects systems using B...

CVE-2025-1178

MEDIUM CVSS 5.6 Feb 11, 2025

A memory corruption vulnerability exists in GNU Binutils' bfd_putl64 function within the ld component. This allows remote attackers to potentially execute arbitrary code or cause denial of service by ...

CVE-2025-21492

MEDIUM CVSS 4.9 Jan 21, 2025

This vulnerability in MySQL Server's Optimizer component allows high-privileged attackers with network access to cause denial of service by crashing or hanging the server. Affected versions include My...

CVE-2024-9823

MEDIUM CVSS 5.3 Oct 14, 2024

This vulnerability in Jetty's DosFilter allows unauthenticated attackers to send crafted requests that trigger OutOfMemory errors, leading to denial-of-service conditions. It affects servers using Jet...

CVE-2024-47554

MEDIUM CVSS 4.3 Oct 3, 2024

This vulnerability in Apache Commons IO allows attackers to cause denial of service by consuming excessive CPU resources through maliciously crafted input to the XmlStreamReader class. It affects appl...

CVE-2024-8372

MEDIUM CVSS 4.8 Sep 9, 2024

This AngularJS vulnerability allows attackers to bypass image source restrictions via improper sanitization of the 'srcset' attribute, enabling content spoofing attacks. It affects AngularJS versions ...

CVE-2024-37891

MEDIUM CVSS 4.4 Jun 17, 2024

urllib3's CVE-2024-37891 allows the Proxy-Authorization header to leak during cross-origin redirects when configured incorrectly without using urllib3's built-in proxy support. This could expose proxy...

CVE-2020-8908

LOW CVSS 3.3 Dec 10, 2020

This vulnerability in Google Guava's createTempDir() method creates temporary directories with world-readable permissions on Unix-like systems, allowing any user on the same machine to potentially rea...