Netapp

Santricity Cloud Connector

27 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.2%
  • Published 21.10.2020 15:15:18
  • Last modified 27.05.2025 16:42:14

Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows una...

  • EPSS 7.33%
  • Published 30.01.2019 22:29:00
  • Last modified 21.11.2024 03:54:04

In Apache HTTP Server 2.4 release 2.4.37 and prior, mod_session checks the session expiry time before decoding the session. This causes session expiry time to be ignored for mod_session_cookie sessions since the expiry time is loaded when the session...

  • EPSS 6.15%
  • Published 30.01.2019 22:29:00
  • Last modified 21.11.2024 03:54:03

In Apache HTTP server versions 2.4.37 and prior, by sending request bodies in a slow loris way to plain resources, the h2 stream for that request unnecessarily occupied a server thread cleaning up that incoming data. This affects only HTTP/2 (mod_htt...

  • EPSS 11.35%
  • Published 26.06.2018 17:29:00
  • Last modified 21.11.2024 03:32:23

In Eclipse Jetty Server, versions 9.2.x and older, 9.3.x (all non HTTP/1.x configurations), and 9.4.x (all HTTP/1.x configurations), when presented with two content-lengths headers, Jetty ignored the second. When presented with a content-length and a...

  • EPSS 7.64%
  • Published 26.06.2018 16:29:00
  • Last modified 21.11.2024 03:32:23

In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled), transfer-encoding chunks are handled poorly. The chunk length parsing was vulnerable to an integer overflow...

  • EPSS 0.43%
  • Published 22.06.2018 19:29:00
  • Last modified 21.11.2024 03:45:23

In Eclipse Jetty versions 9.4.0 through 9.4.8, when using the optional Jetty provided FileSessionDataStore for persistent storage of HttpSession details, it is possible for a malicious user to access/hijack other HttpSessions and even delete unmatche...

  • EPSS 2.92%
  • Published 19.04.2018 02:29:05
  • Last modified 06.05.2025 15:15:56

Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Libraries). The supported version that is affected is Java SE: 10. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols t...

  • EPSS 1.13%
  • Published 19.04.2018 02:29:05
  • Last modified 06.05.2025 15:15:56

Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Libraries). The supported version that is affected is Java SE: 10. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols t...

  • EPSS 36.12%
  • Published 26.03.2018 15:29:00
  • Last modified 21.11.2024 03:59:34

A specially crafted HTTP request header could have crashed the Apache HTTP Server prior to version 2.4.30 due to an out of bound read while preparing data to be cached in shared memory. It could be used as a Denial of Service attack against users of ...

  • EPSS 8.12%
  • Published 26.03.2018 15:29:00
  • Last modified 21.11.2024 03:59:34

When an HTTP/2 stream was destroyed after being handled, the Apache HTTP Server prior to version 2.4.30 could have written a NULL pointer potentially to an already freed memory. The memory pools maintained by the server make this vulnerability hard t...