VendorsNetAppontap_tools10
Vulnerabilities

NetApp Ontap Tools - for Vmware Vsphere 10

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

18CVEs
CVE-2024-52533
gio/gsocks4aproxy.c in GNOME GLib before 2.82.1 has an off-by-one error and resultant buffer overflow because SOCKS4_CONN_MSG_LEN is not sufficient for a trailing '\0' character.
Published 2024-11-11 · Analyzed
9.8EPSS 0.013
CVE-2024-1351
MongoDB Server may allow successful untrusted connection
Published 2024-03-07 · Analyzed
9.8EPSS 0.005
CVE-2024-28752
Apache CXF SSRF Vulnerability using the Aegis databinding
Published 2024-03-15 · Analyzed
9.3EPSS 0.025
CVE-2024-7254
Stack overflow in Protocol Buffers Java Lite
Published 2024-09-19 · Analyzed
8.7EPSS 0.028
CVE-2024-38286
Apache Tomcat: Denial of Service
Published 2024-11-07 · Modified
8.6EPSS 0.017
CVE-2024-6387
Openssh: regresshion - race condition in ssh allows rce/dos
Published 2024-07-01 · Modified
8.11 PoCEPSS 0.995
CVE-2023-52433
netfilter: nft_set_rbtree: skip sync GC for new elements in this transaction
Published 2024-02-20 · Modified
7.8EPSS 0.003
CVE-2024-28757
libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityParserCreate).
Published 2024-03-10 · Modified
7.5EPSS 0.020
CVE-2024-49761
REXML ReDoS vulnerability
Published 2024-10-28 · Modified
7.5EPSS 0.014
CVE-2024-39689
Certifi removes GLOBALTRUST root certificate
Published 2024-07-05 · Modified
7.5EPSS 0.010
CVE-2025-27820
Apache HttpComponents: PSL (Public Suffix List) validation bypass
Published 2025-04-24 · Analyzed
7.5EPSS 0.010
CVE-2023-38709
Apache HTTP Server: HTTP response splitting
Published 2024-04-04 · Modified
7.3EPSS 0.039
CVE-2024-29131
Apache Commons Configuration: StackOverflowError adding property in AbstractListDelimiterHandler.flattenIterator()
Published 2024-03-21 · Analyzed
7.3EPSS 0.021
CVE-2024-8096
OCSP stapling bypass with GnuTLS
Published 2024-09-11 · Analyzed
6.5EPSS 0.007
CVE-2024-24795
Apache HTTP Server: HTTP Response Splitting in multiple modules
Published 2024-04-04 · Analyzed
6.3EPSS 0.029
CVE-2024-39884
Apache HTTP Server: source code disclosure with handlers configured via AddType
Published 2024-07-04 · Analyzed
6.2EPSS 0.009
CVE-2024-34397
An issue was discovered in GNOME GLib before 2.78.5, and 2.79.x and 2.80.x before 2.80.1. When a GDBus-based client subscribes to signals from a trusted system service such as NetworkManager on a shared computer, other users of the same computer can send spoofed D-Bus signals that the GDBus-based client will wrongly interpret as having been sent by the trusted system service. This could lead to the GDBus-based client behaving incorrectly, with an application-dependent impact.
Published 2024-05-07 · Modified
5.2EPSS 0.008
CVE-2024-47554
Apache Commons IO: Possible denial of service attack on untrusted input to XmlStreamReader
Published 2024-10-03 · Analyzed
4.3EPSS 0.013