VendorsNetAppontap9
Vulnerabilities

NetApp Ontap 9

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

21CVEs
CVE-2024-8932
OOB access in ldap_escape
Published 2024-11-22 · Modified
9.8EPSS 0.013
CVE-2024-56171
libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlschemas.c. To exploit this, a crafted XML document must be validated against an XML schema with certain identity constraints, or a crafted XML schema must be used.
Published 2025-02-18 · Modified
9.8EPSS 0.012
CVE-2025-1861
Stream HTTP wrapper truncates redirect location to 1024 bytes
Published 2025-03-30 · Modified
9.8EPSS 0.008
CVE-2024-6387
Openssh: regresshion - race condition in ssh allows rce/dos
Published 2024-07-01 · Modified
8.11 PoCEPSS 0.995
CVE-2024-38473
Apache HTTP Server proxy encoding problem
Published 2024-07-01 · Analyzed
8.1EPSS 0.259
CVE-2025-24928
libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a stack-based buffer overflow in xmlSnprintfElements in valid.c. To exploit this, DTD validation must occur for an untrusted document or untrusted DTD. NOTE: this is similar to CVE-2017-9047.
Published 2025-02-18 · Modified
7.8EPSS 0.004
CVE-2024-27316
Apache HTTP Server: HTTP/2 DoS by memory exhaustion on endless continuation frames
Published 2024-04-04 · Modified
7.5EPSS 0.913
CVE-2024-38472
Apache HTTP Server on WIndows UNC SSRF
Published 2024-07-01 · Analyzed
7.5EPSS 0.695
CVE-2024-39573
Apache HTTP Server: mod_rewrite proxy handler substitution
Published 2024-07-01 · Modified
7.5EPSS 0.372
CVE-2024-28757
libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityParserCreate).
Published 2024-03-10 · Modified
7.5EPSS 0.020
CVE-2023-38709
Apache HTTP Server: HTTP response splitting
Published 2024-04-04 · Modified
7.3EPSS 0.039
CVE-2025-1736
Stream HTTP wrapper header check might omit basic auth header
Published 2025-03-30 · Modified
7.3EPSS 0.005
CVE-2025-26465
Openssh: machine-in-the-middle attack if verifyhostkeydns is enabled
Published 2025-02-18 · Modified
6.8EPSS 0.077
CVE-2024-24795
Apache HTTP Server: HTTP Response Splitting in multiple modules
Published 2024-04-04 · Analyzed
6.3EPSS 0.029
CVE-2025-1734
Streams HTTP wrapper does not fail for headers with invalid name and no colon
Published 2025-03-30 · Modified
6.3EPSS 0.005
CVE-2023-27536
An authentication bypass vulnerability exists libcurl <8.0.0 in the connection reuse feature which can reuse previously established connections with incorrect user permissions due to a failure to check for changes in the CURLOPT_GSSAPI_DELEGATION option. This vulnerability affects krb5/kerberos/negotiate/GSSAPI transfers and could potentially result in unauthorized access to sensitive information. The safest option is to not reuse connections if the CURLOPT_GSSAPI_DELEGATION option has been changed.
Published 2023-03-30 · Modified
5.9EPSS 0.016
CVE-2024-36387
Apache HTTP Server: DoS by Null pointer in websocket over HTTP/2
Published 2024-07-01 · Analyzed
5.4EPSS 0.017
CVE-2026-22052
ONTAP versions 9.12.1 and higher with S3 NAS buckets are susceptible to an information disclosure vulnerability. Successful exploit could allow an authenticated attacker to view a listing of the contents in a directory for which they lack permission.
Published 2026-03-04 · Analyzed
5.3EPSS 0.002
CVE-2024-2004
Usage of disabled protocol
Published 2024-03-27 · Analyzed
3.5EPSS 0.017
CVE-2024-11053
netrc and redirect credential leak
Published 2024-12-11 · Modified
3.4EPSS 0.013
CVE-2025-0167
netrc and default credential leak
Published 2025-02-05 · Analyzed
3.4EPSS 0.007