Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.9
CVE-2016-6495
NetApp Data ONTAP before 8.2.4P5, when operating in 7-Mode, allows remote attackers to obtain information about the volumes configured for HTTP acces…
Data Ontap
after 8.2.4
CRITICAL 9.8
CVE-2017-5600
The Data Warehouse component in NetApp OnCommand Insight before 7.2.3 allows remote attackers to obtain administrative access by leveraging a default…
Oncommand Insight
after 7.2.2
HIGH 7.5
CVE-2016-6820
MetroCluster Tiebreaker for clustered Data ONTAP in versions before 1.2 discloses sensitive information in cleartext which may be viewed by an unauth…
Metrocluster Tiebreaker
after 1.1
HIGH 7.5
CVE-2015-7848EPSS 6%
An integer overflow can occur in NTP-dev.4.3.70 leading to an out-of-bounds memory copy operation when processing a specially crafted private mode pa…
Clustered Data Ontap
4.2.8 / 4.3.77+
HIGH 7.5
CVE-2016-7172
NetApp Snap Creator Framework before 4.3.1 discloses sensitive information which could be viewed by an unauthorized user.
Snap Creator Framework
after 4.3.0
MEDIUM 5.6
CVE-2016-7171
NetApp Plug-in for Symantec NetBackup prior to version 2.0.1 makes use of a non-unique server certificate, making it vulnerable to impersonation.
Netapp Plug In
after 2.0
MEDIUM 6.5
CVE-2016-5047
NetApp OnCommand System Manager 8.3.x before 8.3.2P5 allows remote authenticated users to cause a denial of service via unspecified vectors.
Oncommand System Manager
Patch available
MEDIUM 6.5
CVE-2016-3064
NetApp Clustered Data ONTAP before 8.2.4P4 and 8.3.x before 8.3.2P2 allows remote authenticated users to obtain sensitive cluster and tenant informat…
Clustered Data Ontap
after 8.2.4
MEDIUM 6.8
CVE-2016-1563
NetApp Clustered Data ONTAP 8.3.1 does not properly verify X.509 certificates from TLS servers, which allows man-in-the-middle attackers to spoof ser…
Clustered Data Ontap
Mitigation only
HIGH 10.0
CVE-2015-3292EPSS 12%
The installer in NetApp OnCommand Workflow Automation before 2.2.1P1 and 3.x before 3.0P1 sets up the Java Debugging Wire Protocol (JDWP) service, wh…
Oncommand Workflow Automation
after 2.2.1
HIGH 10.0
CVE-2014-9353
NetApp OnCommand Balance before 4.2P2 contains a "default privileged account," which allows remote attackers to gain privileges via unspecified vecto…
Oncommand Balance
after 4.2
HIGH 10.0
CVE-2008-3349
Multiple unspecified vulnerabilities in NetApp Data ONTAP, as used on NetApp and IBM eServer platforms, allow remote attackers to execute arbitrary c…
Data Ontap
Mitigation only