Netapp

Ontap

20 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.11%
  • Veröffentlicht 30.03.2025 06:15:14
  • Zuletzt bearbeitet 02.07.2025 20:17:38

In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when parsing HTTP redirect in the response to an HTTP request, there is currently limit on the location value size caused by limited size of...

  • EPSS 0.12%
  • Veröffentlicht 30.03.2025 06:15:14
  • Zuletzt bearbeitet 02.07.2025 20:14:40

In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when user-supplied headers are sent, the insufficient validation of the end-of-line characters may prevent certain headers from being sent o...

  • EPSS 0.08%
  • Veröffentlicht 30.03.2025 06:15:14
  • Zuletzt bearbeitet 02.07.2025 20:13:31

In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when receiving headers from HTTP server, the headers missing a colon (:) are treated as valid headers even though they are not. This may con...

Medienbericht
  • EPSS 58.35%
  • Veröffentlicht 18.02.2025 19:15:29
  • Zuletzt bearbeitet 26.09.2025 07:15:41

A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legit server. This issue occurs due to how OpenSSH mishandles error codes in spec...

Exploit
  • EPSS 0.08%
  • Veröffentlicht 05.02.2025 10:15:22
  • Zuletzt bearbeitet 30.07.2025 19:41:45

When asked to use a `.netrc` file for credentials **and** to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has a `de...

Exploit
  • EPSS 0.29%
  • Veröffentlicht 11.12.2024 08:15:05
  • Zuletzt bearbeitet 30.07.2025 17:39:25

When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has an e...

  • EPSS 0.64%
  • Veröffentlicht 22.11.2024 06:15:20
  • Zuletzt bearbeitet 02.07.2025 20:08:35

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, uncontrolled long string inputs to ldap_escape() function on 32-bit systems can cause an integer overflow, resulting in an out-of-bounds write.

  • EPSS 1.19%
  • Veröffentlicht 01.07.2024 19:15:05
  • Zuletzt bearbeitet 01.07.2025 20:25:56

Potential SSRF in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to cause unsafe RewriteRules to unexpectedly setup URL's to be handled by mod_proxy. Users are recommended to upgrade to version 2.4.60, which fixes this issue.

  • EPSS 89.75%
  • Veröffentlicht 01.07.2024 19:15:04
  • Zuletzt bearbeitet 01.07.2025 20:24:46

SSRF in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or content Users are recommended to upgrade to version 2.4.60 which fixes this issue.  Note: Existing configurations t...

  • EPSS 87.11%
  • Veröffentlicht 01.07.2024 19:15:04
  • Zuletzt bearbeitet 01.07.2025 20:25:09

Encoding problem in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows request URLs with incorrect encoding to be sent to backend services, potentially bypassing authentication via crafted requests. Users are recommended to upgrade to version ...