📦 Bootstrap Os

by Netapp

🔍 What is Bootstrap Os?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-24813

CRITICAL CVSS 9.8 Mar 10, 2025

This vulnerability in Apache Tomcat allows path traversal attacks via internal dot handling in filenames, potentially leading to remote code execution, information disclosure, or file corruption. It a...

CVE-2025-0665

CRITICAL CVSS 9.8 Feb 5, 2025

libcurl incorrectly closes the same eventfd file descriptor twice during threaded name resolution cleanup, causing a use-after-free condition. This vulnerability affects applications using libcurl wit...

CVE-2024-56337

CRITICAL CVSS 9.8 Dec 20, 2024

A Time-of-check Time-of-use (TOCTOU) race condition vulnerability in Apache Tomcat allows attackers to bypass security checks and write malicious files to case-insensitive file systems. This affects T...

CVE-2024-50379

CRITICAL CVSS 9.8 Dec 17, 2024

A Time-of-check Time-of-use (TOCTOU) race condition vulnerability in Apache Tomcat's JSP compilation allows attackers to achieve Remote Code Execution (RCE) on case-insensitive file systems when the d...

CVE-2022-32207

CRITICAL CVSS 9.8 Jul 7, 2022

CVE-2022-32207 is a privilege escalation vulnerability in curl versions before 7.84.0 where file permission widening occurs during atomic file operations. When curl saves cookies, alt-svc, or hsts dat...

CVE-2024-32487

HIGH CVSS 8.6 Apr 13, 2024

CVE-2024-32487 is a command injection vulnerability in the 'less' pager utility that allows attackers to execute arbitrary OS commands via specially crafted filenames containing newline characters. Th...

CVE-2023-29483

HIGH CVSS 7.0 Apr 11, 2024

This vulnerability allows remote attackers to interfere with DNS name resolution by sending invalid packets from expected IP addresses and source ports, disrupting DNS queries. It affects systems usin...

CVE-2024-2398

HIGH CVSS 8.6 Mar 27, 2024

CVE-2024-2398 is a memory leak vulnerability in libcurl that occurs when HTTP/2 server push headers exceed the 1000-header limit. This allows attackers to cause denial of service through resource exha...

CVE-2023-4911

HIGH CVSS 7.8 Oct 3, 2023

CVE-2023-4911 is a buffer overflow vulnerability in the GNU C Library's dynamic loader (ld.so) that allows local attackers to exploit SUID binaries. By crafting malicious GLIBC_TUNABLES environment va...

CVE-2022-21476

HIGH CVSS 7.5 Apr 19, 2022

This vulnerability in Oracle Java SE and GraalVM Enterprise Edition allows unauthenticated remote attackers to access sensitive data from Java applications. It affects Java deployments running sandbox...

CVE-2022-23308

HIGH CVSS 7.5 Feb 26, 2022

CVE-2022-23308 is a use-after-free vulnerability in libxml2's validation component that allows attackers to potentially execute arbitrary code or cause denial of service. It affects applications that ...

CVE-2025-29768

MEDIUM CVSS 4.4 Mar 13, 2025

Vim versions before 9.1.1198 contain a vulnerability in zip.vim that could cause data loss when users view specially crafted zip files and press 'x' on unusual filenames. This affects users who open z...

CVE-2025-22134

MEDIUM CVSS 4.2 Jan 13, 2025

CVE-2025-22134 is a heap-buffer overflow vulnerability in Vim that occurs when switching buffers using the :all command while visual mode is active. This allows attackers to potentially execute arbitr...

CVE-2024-9823

MEDIUM CVSS 5.3 Oct 14, 2024

This vulnerability in Jetty's DosFilter allows unauthenticated attackers to send crafted requests that trigger OutOfMemory errors, leading to denial-of-service conditions. It affects servers using Jet...

CVE-2024-43374

MEDIUM CVSS 4.5 Aug 16, 2024

CVE-2024-43374 is a use-after-free vulnerability in Vim's argument list handling that can cause the editor to crash. It affects users running Vim versions prior to 9.1.0678 who manually create unusual...

CVE-2024-26306

MEDIUM CVSS 5.9 May 14, 2024

This vulnerability in iPerf3 allows attackers to exploit a timing side channel in RSA decryption operations when using OpenSSL with RSA authentication. Attackers could potentially recover credential p...