📦 Ontap Tools

by Netapp

🔍 What is Ontap Tools?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-52533

CRITICAL CVSS 9.8 Nov 11, 2024

This vulnerability is a buffer overflow in GLib's SOCKS4 proxy implementation due to an off-by-one error. It allows attackers to execute arbitrary code or cause denial of service by sending specially ...

CVE-2024-28752

CRITICAL CVSS 9.3 Mar 15, 2024

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Apache CXF's Aegis DataBinding component. It allows attackers to make unauthorized HTTP requests from the vulnerable server to ...

CVE-2021-44228

CRITICAL CVSS 10.0 Dec 10, 2021

CVE-2021-44228 (Log4Shell) is a critical remote code execution vulnerability in Apache Log4j2 that allows attackers to execute arbitrary code by exploiting JNDI lookups in log messages. This affects a...

CVE-2024-38286

HIGH CVSS 8.6 Nov 7, 2024

This vulnerability in Apache Tomcat allows attackers to cause denial of service by exploiting the TLS handshake process to trigger OutOfMemoryError conditions. It affects Tomcat versions 11.0.0-M1 thr...

CVE-2024-49761

HIGH CVSS 7.5 Oct 28, 2024

CVE-2024-49761 is a Regular Expression Denial of Service (ReDoS) vulnerability in REXML, Ruby's XML toolkit. It allows attackers to cause denial of service by sending specially crafted XML documents w...

CVE-2024-7254

HIGH CVSS 7.5 Sep 19, 2024

This vulnerability allows attackers to cause a stack overflow by sending malicious Protocol Buffers data with deeply nested groups, potentially crashing applications. It affects any system using Googl...

CVE-2024-39689

HIGH CVSS 7.5 Jul 5, 2024

This CVE involves the removal of GLOBALTRUST root certificates from the certifi Python package due to compliance issues. Systems using affected certifi versions may trust certificates issued by GLOBAL...

CVE-2024-34750

HIGH CVSS 7.5 Jul 3, 2024

This vulnerability in Apache Tomcat allows attackers to cause uncontrolled resource consumption through HTTP/2 connections. By sending excessive HTTP headers, attackers can force Tomcat to keep connec...

CVE-2023-38709

HIGH CVSS 7.3 Apr 4, 2024

CVE-2023-38709 is an input validation vulnerability in Apache HTTP Server that allows malicious backend applications or content generators to split HTTP responses, potentially enabling response smuggl...

CVE-2024-29131

HIGH CVSS 7.3 Mar 21, 2024

This CVE describes an out-of-bounds write vulnerability in Apache Commons Configuration that could allow attackers to write data beyond allocated memory boundaries. It affects versions from 2.0 up to ...

CVE-2024-28757

HIGH CVSS 7.5 Mar 10, 2024

CVE-2024-28757 is an XML Entity Expansion vulnerability in libexpat that allows attackers to cause denial of service through resource exhaustion when external parsers are created via XML_ExternalEntit...

CVE-2023-2953

HIGH CVSS 7.5 May 30, 2023

This vulnerability in OpenLDAP causes a null pointer dereference in the ber_memalloc_x() function, which can lead to denial of service (DoS) by crashing the LDAP service. Any system running vulnerable...

CVE-2021-28165

HIGH CVSS 7.5 Apr 1, 2021

This vulnerability in Eclipse Jetty allows denial-of-service attacks by causing 100% CPU usage when processing large invalid TLS frames. Attackers can exploit this to make affected servers unresponsiv...

CVE-2024-47554

MEDIUM CVSS 4.3 Oct 3, 2024

This vulnerability in Apache Commons IO allows attackers to cause denial of service by consuming excessive CPU resources through maliciously crafted input to the XmlStreamReader class. It affects appl...