Netapp

Ontap Tools

30 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.03%
  • Veröffentlicht 24.04.2025 11:44:25
  • Zuletzt bearbeitet 16.07.2025 14:48:52

A bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks, affecting cookie management and host name verification. Discovered by the Apache HttpClient team. Fixed in the 5.4.3 release

Exploit
  • EPSS 0.08%
  • Veröffentlicht 05.02.2025 10:15:22
  • Zuletzt bearbeitet 30.07.2025 19:41:45

When asked to use a `.netrc` file for credentials **and** to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has a `de...

Exploit
  • EPSS 2.46%
  • Veröffentlicht 11.11.2024 23:15:05
  • Zuletzt bearbeitet 17.06.2025 01:23:56

gio/gsocks4aproxy.c in GNOME GLib before 2.82.1 has an off-by-one error and resultant buffer overflow because SOCKS4_CONN_MSG_LEN is not sufficient for a trailing '\0' character.

  • EPSS 1.36%
  • Veröffentlicht 07.11.2024 08:15:13
  • Zuletzt bearbeitet 08.08.2025 11:15:28

Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M20, from 10.1.0-M1 through 10.1.24, from 9.0.13 through 9.0.89. The following versions were EOL a...

  • EPSS 1.15%
  • Veröffentlicht 28.10.2024 15:15:05
  • Zuletzt bearbeitet 21.03.2025 16:37:05

REXML is an XML toolkit for Ruby. The REXML gem before 3.3.9 has a ReDoS vulnerability when it parses an XML that has many digits between &# and x...; in a hex numeric character reference (&#x...;). This does not happen with Ruby 3.2 or later. Ruby 3...

  • EPSS 0.21%
  • Veröffentlicht 03.10.2024 12:15:02
  • Zuletzt bearbeitet 10.07.2025 21:10:32

Uncontrolled Resource Consumption vulnerability in Apache Commons IO. The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input. This issue affects Apache Commons IO: from...

  • EPSS 0.08%
  • Veröffentlicht 19.09.2024 01:15:10
  • Zuletzt bearbeitet 26.09.2025 17:10:19

Any project that parses untrusted Protocol Buffers data containing an arbitrary number of nested groups / series of SGROUP tags can corrupted by exceeding the stack limit i.e. StackOverflow. Parsing nested groups as unknown fields with DiscardUnknown...

Exploit
  • EPSS 0.21%
  • Veröffentlicht 11.09.2024 10:15:02
  • Zuletzt bearbeitet 30.07.2025 19:42:16

When curl is told to use the Certificate Status Request TLS extension, often referred to as OCSP stapling, to verify that the server certificate is valid, it might fail to detect some OCSP problems and instead wrongly consider the response as fine. ...

  • EPSS 4.4%
  • Veröffentlicht 03.09.2024 16:15:07
  • Zuletzt bearbeitet 03.06.2025 10:51:54

Issue summary: Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address resulting in abnormal termination of the application process. Impact summary: Abnormal term...

  • EPSS 21.23%
  • Veröffentlicht 05.07.2024 19:15:10
  • Zuletzt bearbeitet 15.02.2025 00:15:13

Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi starting in 2021.5.30 and prior to 2024.7.4 recognized root certificates from `GLOBALTRUST`...