VendorsNetAppontap_toolsall versions
Vulnerabilities

NetApp Ontap Tools - for Vmware Vsphere

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

29CVEs
CVE-2021-44228
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
Published 2021-12-10 · Analyzed
10.0KEV3 PoCEPSS 1.000
CVE-2024-52533
gio/gsocks4aproxy.c in GNOME GLib before 2.82.1 has an off-by-one error and resultant buffer overflow because SOCKS4_CONN_MSG_LEN is not sufficient for a trailing '\0' character.
Published 2024-11-11 · Analyzed
9.8EPSS 0.013
CVE-2024-1351
MongoDB Server may allow successful untrusted connection
Published 2024-03-07 · Analyzed
9.8EPSS 0.005
CVE-2024-28752
Apache CXF SSRF Vulnerability using the Aegis databinding
Published 2024-03-15 · Analyzed
9.3EPSS 0.025
CVE-2024-7254
Stack overflow in Protocol Buffers Java Lite
Published 2024-09-19 · Analyzed
8.7EPSS 0.028
CVE-2024-38286
Apache Tomcat: Denial of Service
Published 2024-11-07 · Modified
8.6EPSS 0.017
CVE-2024-6387
Openssh: regresshion - race condition in ssh allows rce/dos
Published 2024-07-01 · Modified
8.11 PoCEPSS 0.995
CVE-2021-3156
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.
Published 2021-01-26 · Analyzed
7.8KEV2 PoCEPSS 1.000
CVE-2021-28165
In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large invalid TLS frame.
Published 2021-04-01 · Modified
7.8EPSS 0.539
CVE-2023-52433
netfilter: nft_set_rbtree: skip sync GC for new elements in this transaction
Published 2024-02-20 · Modified
7.8EPSS 0.003
CVE-2024-6119
Possible denial of service in X.509 name checks
Published 2024-09-03 · Modified
7.5EPSS 0.666
CVE-2024-34750
Apache Tomcat: HTTP/2 excess header handling DoS
Published 2024-07-03 · Modified
7.5EPSS 0.046
CVE-2024-28757
libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityParserCreate).
Published 2024-03-10 · Modified
7.5EPSS 0.020
CVE-2023-2953
A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function.
Published 2023-05-30 · Modified
7.5EPSS 0.019
CVE-2024-49761
REXML ReDoS vulnerability
Published 2024-10-28 · Modified
7.5EPSS 0.014
CVE-2024-39689
Certifi removes GLOBALTRUST root certificate
Published 2024-07-05 · Modified
7.5EPSS 0.010
CVE-2025-27820
Apache HttpComponents: PSL (Public Suffix List) validation bypass
Published 2025-04-24 · Analyzed
7.5EPSS 0.010
CVE-2020-13817
ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows remote attackers to cause a denial of service (daemon exit or system time change) by predicting transmit timestamps for use in spoofed packets. The victim must be relying on unauthenticated IPv4 time sources. There must be an off-path attacker who can query time from the victim's ntpd instance.
Published 2020-06-04 · Modified
7.4EPSS 0.033
CVE-2024-0565
Kernel: cifs filesystem decryption improper input validation remote code execution vulnerability in function receive_encrypted_standard of client
Published 2024-01-15 · Modified
7.4EPSS 0.020
CVE-2023-38709
Apache HTTP Server: HTTP response splitting
Published 2024-04-04 · Modified
7.3EPSS 0.039
CVE-2024-29131
Apache Commons Configuration: StackOverflowError adding property in AbstractListDelimiterHandler.flattenIterator()
Published 2024-03-21 · Analyzed
7.3EPSS 0.021
CVE-2023-36054
lib/kadm5/kadm_rpc_xdr.c in MIT Kerberos 5 (aka krb5) before 1.20.2 and 1.21.x before 1.21.1 frees an uninitialized pointer. A remote authenticated user can trigger a kadmind crash. This occurs because _xdr_kadm5_principal_ent_rec does not validate the relationship between n_key_data and the key_data array count.
Published 2023-08-07 · Modified
6.5EPSS 0.028
CVE-2024-8096
OCSP stapling bypass with GnuTLS
Published 2024-09-11 · Analyzed
6.5EPSS 0.007
CVE-2024-24795
Apache HTTP Server: HTTP Response Splitting in multiple modules
Published 2024-04-04 · Analyzed
6.3EPSS 0.029
CVE-2024-39884
Apache HTTP Server: source code disclosure with handlers configured via AddType
Published 2024-07-04 · Analyzed
6.2EPSS 0.009
CVE-2024-26633
ip6_tunnel: fix NEXTHDR_FRAGMENT handling in ip6_tnl_parse_tlv_enc_lim()
Published 2024-03-18 · Analyzed
5.5EPSS 0.003
CVE-2024-34397
An issue was discovered in GNOME GLib before 2.78.5, and 2.79.x and 2.80.x before 2.80.1. When a GDBus-based client subscribes to signals from a trusted system service such as NetworkManager on a shared computer, other users of the same computer can send spoofed D-Bus signals that the GDBus-based client will wrongly interpret as having been sent by the trusted system service. This could lead to the GDBus-based client behaving incorrectly, with an application-dependent impact.
Published 2024-05-07 · Modified
5.2EPSS 0.008
CVE-2024-47554
Apache Commons IO: Possible denial of service attack on untrusted input to XmlStreamReader
Published 2024-10-03 · Analyzed
4.3EPSS 0.013
CVE-2025-0167
netrc and default credential leak
Published 2025-02-05 · Analyzed
3.4EPSS 0.007