Home / Security / CVE index / 2024

2024 NetApp CVEs (page 2)

Showing 300 CVEs with a 2024 identifier — page 2 of 3. Sorted by CVE id.

Always verify. NetApp's advisory is authoritative for affected versions and fixes; NVD carries the CVSS record.
Showing 300 of 300
CVEPublishedSeverityCVSSSummary / Sources
CVE-2024-26327——— NVD ↗ · NTAP-20240419-0010
CVE-2024-26328——— NVD ↗ · NTAP-20240419-0010
CVE-2024-264582024-02-29MEDIUM5.3Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c. NVD ↗ · NTAP-20240415-0010
CVE-2024-264612024-02-29HIGH7.5Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c. NVD ↗ · NTAP-20240415-0011
CVE-2024-264622024-02-29MEDIUM5.5Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/kdc/ndr.c. NVD ↗ · NTAP-20240415-0012
CVE-2024-26581——— NVD ↗ · NTAP-20260227-0005
CVE-2024-26594——— NVD ↗ · NTAP-20260213-0018
CVE-2024-2660——— NVD ↗ · NTAP-20240524-0007
CVE-2024-266332024-03-18MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: fix NEXTHDR_FRAGMENT handling in ip6_tnl_parse_tlv_enc_lim() syzbot pointed out NVD ↗ · NTAP-20241220-0001
CVE-2024-266412024-03-18HIGH8.6In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: make sure to pull inner header in __ip6_tnl_rcv() syzbot found __ip6_tnl_rcv() c NVD ↗ · NTAP-20241108-0008
CVE-2024-26733——— NVD ↗ · NTAP-20241101-0013
CVE-2024-26735——— NVD ↗ · NTAP-20241101-0012
CVE-2024-268822024-04-17HIGH7.3In the Linux kernel, the following vulnerability has been resolved: net: ip_tunnel: make sure to pull inner header in ip_tunnel_rcv() Apply the same fix than on NVD ↗ · NTAP-20241220-0002
CVE-2024-26900——— NVD ↗ · NTAP-20240912-0011
CVE-2024-27012——— NVD ↗ · NTAP-20260911-0020
CVE-2024-27137——— NVD ↗ · NTAP-20250214-0004
CVE-2024-27254——— NVD ↗ · NTAP-20240517-0004
CVE-2024-272802024-05-14CRITICAL9.8A buffer-overread issue was discovered in StringIO 3.0.1, as distributed in Ruby 3.0.x through 3.0.6 and 3.1.x through 3.1.4. The ungetbyte and ungetc methods o NVD ↗ · NTAP-20250502-0003
CVE-2024-27281——— NVD ↗ · NTAP-20260102-0006
CVE-2024-27282——— NVD ↗ · NTAP-20241011-0007
CVE-2024-27309——— NVD ↗ · NTAP-20240705-0002
CVE-2024-273162024-04-04HIGH7.5HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a client does not stop NVD ↗ · NTAP-20240415-0013
CVE-2024-273982024-05-14HIGH8.0In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Fix use-after-free bugs caused by sco_sock_timeout When the sco connection is est NVD ↗ · NTAP-20240912-0012
CVE-2024-273992024-05-14MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: Bluetooth: l2cap: fix null-ptr-deref in l2cap_chan_timeout There is a race condition between NVD ↗ · NTAP-20240926-0001
CVE-2024-27562024-04-29MEDIUM6.5Due to an incomplete fix to CVE-2022-31629 https://github.com/advisories/GHSA-c43m-486j-j32p , network and same-site attackers can set a standard insecure cooki NVD ↗ · NTAP-20240510-0008
CVE-2024-2757——— NVD ↗ · NTAP-20240510-0011
CVE-2024-27982——— NVD ↗ · NTAP-20250418-0001
CVE-2024-27983——— NVD ↗ · NTAP-20240510-0002
CVE-2024-28047——— NVD ↗ · NTAP-20250919-0011
CVE-2024-28085——— NVD ↗ · NTAP-20240531-0003
CVE-2024-28103——— NVD ↗ · NTAP-20241206-0002
CVE-2024-28180——— NVD ↗ · NTAP-20250808-0010
CVE-2024-2859——— NVD ↗ · NTAP-20240628-0003
CVE-2024-287522024-03-15CRITICAL9.3A SSRF vulnerability using the Aegis DataBinding in versions of Apache CXF before 4.0.4, 3.6.3 and 3.5.8 allows an attacker to perform SSRF style attacks on web NVD ↗ · NTAP-20240517-0001
CVE-2024-287572024-03-10HIGH7.5libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityParserCreate). NVD ↗ · NTAP-20240322-0001
CVE-2024-28762——— NVD ↗ · NTAP-20240912-0005
CVE-2024-2877——— NVD ↗ · NTAP-20240614-0002
CVE-2024-288342024-03-21MEDIUM5.3A flaw was found in GnuTLS. The Minerva attack is a cryptographic vulnerability that exploits deterministic behavior in systems like GnuTLS, leading to side-cha NVD ↗ · NTAP-20240524-0004
CVE-2024-28835——— NVD ↗ · NTAP-20241122-0009
CVE-2024-28863——— NVD ↗ · NTAP-20240524-0005
CVE-2024-28956——— NVD ↗ · NTAP-20250926-0008
CVE-2024-291312024-03-21HIGH7.3Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: from 2.0 before 2.10.1. Users are recommended NVD ↗ · NTAP-20241213-0001
CVE-2024-291332024-03-21MEDIUM5.4Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: from 2.0 before 2.10.1. Users are recommended NVD ↗ · NTAP-20250605-0002
CVE-2024-29415——— NVD ↗ · NTAP-20250117-0010
CVE-2024-29612024-04-17HIGH7.3The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the IS NVD ↗ · NTAP-20240531-0002
CVE-2024-297362024-07-19CRITICAL9.1A SSRF vulnerability in WADL service description in versions of Apache CXF before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform SSRF style attacks on RES NVD ↗ · NTAP-20241115-0003
CVE-2024-298572024-05-14HIGH7.5An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC Java) before 1.78, BC Java LTS before 2.73.6, BC-FJA before 1.0.2.5, and BC C# NVD ↗ · NTAP-20241206-0008
CVE-2024-29937——— NVD ↗ · NTAP-20250530-0007
CVE-2024-29953——— NVD ↗ · NTAP-20240822-0009
CVE-2024-29954——— NVD ↗ · NTAP-20240822-0010
CVE-2024-30045——— NVD ↗ · NTAP-20241122-0001
CVE-2024-301712024-05-14MEDIUM5.9An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of exception NVD ↗ · NTAP-20240614-0008
CVE-2024-30172——— NVD ↗ · NTAP-20240614-0007
CVE-2024-30260——— NVD ↗ · NTAP-20240905-0008
CVE-2024-30261——— NVD ↗ · NTAP-20240905-0008
CVE-2024-3056——— NVD ↗ · NTAP-20241227-0002
CVE-2024-3094——— NVD ↗ · NTAP-20240402-0001
CVE-2024-3096——— NVD ↗ · NTAP-20240510-0010
CVE-2024-31068——— NVD ↗ · NTAP-20250919-0015
CVE-2024-31141——— NVD ↗ · NTAP-20250131-0001
CVE-2024-31155——— NVD ↗ · NTAP-20250926-0003
CVE-2024-31157——— NVD ↗ · NTAP-20250926-0004
CVE-2024-31870——— NVD ↗ · NTAP-20240822-0006
CVE-2024-31880——— NVD ↗ · NTAP-20240912-0005
CVE-2024-31881——— NVD ↗ · NTAP-20240912-0005
CVE-2024-31882——— NVD ↗ · NTAP-20240912-0003
CVE-2024-320072024-07-19HIGH7.5An improper input validation of the p2c parameter in the Apache CXF JOSE code before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform a denial of service at NVD ↗ · NTAP-20240808-0009
CVE-2024-3219——— NVD ↗ · NTAP-20250502-0004
CVE-2024-3220——— NVD ↗ · NTAP-20250314-0001
CVE-2024-32487——— NVD ↗ · NTAP-20240605-0009
CVE-2024-32668——— NVD ↗ · NTAP-20240920-0007
CVE-2024-32760——— NVD ↗ · NTAP-20250814-0004
CVE-2024-32962——— NVD ↗ · NTAP-20240705-0003
CVE-2024-33599——— NVD ↗ · NTAP-20240524-0011
CVE-2024-33600——— NVD ↗ · NTAP-20240524-0013
CVE-2024-33601——— NVD ↗ · NTAP-20240524-0014
CVE-2024-33602——— NVD ↗ · NTAP-20240524-0012
CVE-2024-33607——— NVD ↗ · NTAP-20260403-0013
CVE-2024-33883——— NVD ↗ · NTAP-20240605-0003
CVE-2024-34069——— NVD ↗ · NTAP-20240614-0004
CVE-2024-34155——— NVD ↗ · NTAP-20240926-0005
CVE-2024-34156——— NVD ↗ · NTAP-20240926-0004
CVE-2024-34158——— NVD ↗ · NTAP-20241004-0003
CVE-2024-34161——— NVD ↗ · NTAP-20251010-0007
CVE-2024-34397——— NVD ↗ · NTAP-20240531-0008
CVE-2024-34447——— NVD ↗ · NTAP-20240614-0007
CVE-2024-34459——— NVD ↗ · NTAP-20251024-0012
CVE-2024-3446——— NVD ↗ · NTAP-20250502-0007
CVE-2024-3447——— NVD ↗ · NTAP-20250425-0005
CVE-2024-347502024-07-03HIGH7.5Improper Handling of Exceptional Conditions, Uncontrolled Resource Consumption vulnerability in Apache Tomcat. When processing an HTTP/2 stream, Tomcat did not NVD ↗ · NTAP-20240816-0004
CVE-2024-35136——— NVD ↗ · NTAP-20240912-0003
CVE-2024-35152——— NVD ↗ · NTAP-20240912-0003
CVE-2024-35176——— NVD ↗ · NTAP-20250306-0001
CVE-2024-35195——— NVD ↗ · NTAP-20260522-0001
CVE-2024-35200——— NVD ↗ · NTAP-20251010-0008
CVE-2024-3566——— NVD ↗ · NTAP-20251121-0015
CVE-2024-3567——— NVD ↗ · NTAP-20240822-0007
CVE-2024-358902024-05-19HIGH7.8In the Linux kernel, the following vulnerability has been resolved: gro: fix ownership transfer If packets are GROed with fraglist they might be segmented later NVD ↗ · NTAP-20250509-0008
CVE-2024-35894——— NVD ↗ · NTAP-20250321-0002
CVE-2024-358962024-05-19HIGH7.1In the Linux kernel, the following vulnerability has been resolved: netfilter: validate user input for expected length I got multiple syzbot reports showing old NVD ↗ · NTAP-20250321-0004
CVE-2024-3596——— NVD ↗ · NTAP-20240822-0001
CVE-2024-35962——— NVD ↗ · NTAP-20250801-0007
CVE-2024-36137——— NVD ↗ · NTAP-20241122-0005
CVE-2024-36138——— NVD ↗ · NTAP-20241108-0010
CVE-2024-36293——— NVD ↗ · NTAP-20250919-0012
CVE-2024-36350——— NVD ↗ · NTAP-20260116-0015
CVE-2024-36357——— NVD ↗ · NTAP-20260116-0016
CVE-2024-363872024-07-01MEDIUM5.4Serving WebSocket protocol upgrades over a HTTP/2 connection could result in a Null Pointer dereference, leading to a crash of the server process, degrading per NVD ↗ · NTAP-20240712-0001
CVE-2024-3653——— NVD ↗ · NTAP-20240828-0002
CVE-2024-368832024-05-30HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net: fix out-of-bounds access in ops_init net_alloc_generic is called by net_alloc, which is NVD ↗ · NTAP-20241018-0001
CVE-2024-368862024-05-30CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: tipc: fix UAF in error path Sam Page (sam4k) working with Trend Micro Zero Day Initiative re NVD ↗ · NTAP-20241018-0002
CVE-2024-36899——— NVD ↗ · NTAP-20260513-0003
CVE-2024-36902——— NVD ↗ · NTAP-20240926-0002
CVE-2024-36903——— NVD ↗ · NTAP-20260121-0002
CVE-2024-36904——— NVD ↗ · NTAP-20240905-0004
CVE-2024-369052024-05-30MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: tcp: defer shutdown(SEND_SHUTDOWN) for TCP_SYN_RECV sockets TCP_SYN_RECV state is really spe NVD ↗ · NTAP-20240905-0005
CVE-2024-36913——— NVD ↗ · NTAP-20260116-0018
CVE-2024-36916——— NVD ↗ · NTAP-20240905-0006
CVE-2024-36919——— NVD ↗ · NTAP-20240905-0009
CVE-2024-369222024-05-30HIGH8.8In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: read txq->read_ptr under lock If we read txq->read_ptr without lock, we can r NVD ↗ · NTAP-20260925-0002
CVE-2024-36927——— NVD ↗ · NTAP-20260121-0001
CVE-2024-369292024-05-30HIGH7.5In the Linux kernel, the following vulnerability has been resolved: net: core: reject skb_copy(_expand) for fraglist GSO skbs SKB_GSO_FRAGLIST skbs must not be NVD ↗ · NTAP-20240905-0010
CVE-2024-369332024-05-30HIGH7.8In the Linux kernel, the following vulnerability has been resolved: nsh: Restore skb->{protocol,data,mac_header} for outer header in nsh_gso_segment(). syzbot t NVD ↗ · NTAP-20240912-0006
CVE-2024-36934——— NVD ↗ · NTAP-20240912-0007
CVE-2024-369452024-05-30HIGH7.5In the Linux kernel, the following vulnerability has been resolved: net/smc: fix neighbour and rtable leak in smc_ib_find_route() In smc_ib_find_route(), the ne NVD ↗ · NTAP-20250404-0006
CVE-2024-36946——— NVD ↗ · NTAP-20241004-0002
CVE-2024-36958——— NVD ↗ · NTAP-20250404-0007
CVE-2024-37051——— NVD ↗ · NTAP-20240705-0004
CVE-2024-37280——— NVD ↗ · NTAP-20240816-0003
CVE-2024-373702024-06-28HIGH7.5In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can modify the plaintext Extra Count field of a confidential GSS krb5 wrap token, causing the unwrapped NVD ↗ · NTAP-20241108-0007
CVE-2024-373712024-06-28CRITICAL9.1In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can cause invalid memory reads during GSS message token handling by sending message tokens with invalid NVD ↗ · NTAP-20250124-0010 · NTAP-20241108-0009
CVE-2024-37372——— NVD ↗ · NTAP-20250502-0010
CVE-2024-37529——— NVD ↗ · NTAP-20240912-0003
CVE-2024-37891——— NVD ↗ · NTAP-20240822-0003
CVE-2024-37894——— NVD ↗ · NTAP-20240719-0001
CVE-2024-38286——— NVD ↗ · NTAP-20241101-0010
CVE-2024-38372——— NVD ↗ · NTAP-20240828-0009
CVE-2024-384282024-06-16CRITICAL9.1url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be insecure behavior in which data that was sup NVD ↗ · NTAP-20241115-0005
CVE-2024-384722024-07-01HIGH7.5SSRF in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or content Users are recommen NVD ↗ · NTAP-20240712-0001
CVE-2024-384732024-07-01HIGH8.1Encoding problem in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows request URLs with incorrect encoding to be sent to backend services, potentially b NVD ↗ · NTAP-20240712-0001
CVE-2024-384742024-07-01CRITICAL9.8Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in directories permitted by the configura NVD ↗ · NTAP-20240712-0001
CVE-2024-384752024-07-01CRITICAL9.1Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are permitted to NVD ↗ · NTAP-20240712-0001
CVE-2024-384762024-07-01CRITICAL9.8Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications NVD ↗ · NTAP-20240712-0001
CVE-2024-384772024-07-01HIGH7.5null pointer dereference in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows an attacker to crash the server via a malicious request. Users are recomme NVD ↗ · NTAP-20240712-0001
CVE-2024-38517——— NVD ↗ · NTAP-20240905-0001
CVE-2024-38796——— NVD ↗ · NTAP-20241206-0006
CVE-2024-38807——— NVD ↗ · NTAP-20250117-0006
CVE-2024-38808——— NVD ↗ · NTAP-20240920-0002
CVE-2024-388092024-09-27MEDIUM5.3Applications that parse ETags from "If-Match" or "If-None-Match" request headers are vulnerable to DoS attack. Users of affected versions should upgrade to the NVD ↗ · NTAP-20240920-0003
CVE-2024-38816——— NVD ↗ · NTAP-20241227-0001
CVE-2024-38819——— NVD ↗ · NTAP-20250110-0010
CVE-2024-388202024-10-18LOW3.1The fix for CVE-2022-22968 made disallowedFields patterns in DataBinder case insensitive. However, String.toLowerCase() has some Locale dependent exceptions tha NVD ↗ · NTAP-20241129-0003
CVE-2024-38821——— NVD ↗ · NTAP-20250124-0006
CVE-2024-38827——— NVD ↗ · NTAP-20250124-0007
CVE-2024-38828——— NVD ↗ · NTAP-20250509-0009
CVE-2024-3884——— NVD ↗ · NTAP-20260130-0004
CVE-2024-38875——— NVD ↗ · NTAP-20240808-0005
CVE-2024-39279——— NVD ↗ · NTAP-20250926-0004
CVE-2024-39281——— NVD ↗ · NTAP-20250110-0002
CVE-2024-39329——— NVD ↗ · NTAP-20240808-0005
CVE-2024-39330——— NVD ↗ · NTAP-20240808-0005
CVE-2024-395732024-07-01HIGH7.5Potential SSRF in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to cause unsafe RewriteRules to unexpectedly setup URL's to be handled NVD ↗ · NTAP-20240712-0001
CVE-2024-39614——— NVD ↗ · NTAP-20240808-0005
CVE-2024-39684——— NVD ↗ · NTAP-20240905-0003
CVE-2024-396892024-07-05HIGH7.5Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi s NVD ↗ · NTAP-20241206-0001
CVE-2024-398842024-07-04MEDIUM6.2A regression in the core of Apache HTTP Server 2.4.60 ignores some use of the legacy content-type based configuration of handlers. "AddType" and similar configu NVD ↗ · NTAP-20240712-0002
CVE-2024-39894——— NVD ↗ · NTAP-20240712-0004
CVE-2024-39908——— NVD ↗ · NTAP-20250117-0008
CVE-2024-4027——— NVD ↗ · NTAP-20260311-0005
CVE-2024-4030——— NVD ↗ · NTAP-20240705-0005
CVE-2024-40322024-06-17HIGH7.5The “ipaddress” module contained incorrect information about whether certain IPv4 and IPv6 addresses were designated as “globally reachable” or “private”. This NVD ↗ · NTAP-20240726-0004
CVE-2024-4068——— NVD ↗ · NTAP-20251121-0014
CVE-2024-407252024-07-18MEDIUM5.3A partial fix for CVE-2024-39884 in the core of Apache HTTP Server 2.4.61 ignores some use of the legacy content-type based configuration of handlers. "AddType" NVD ↗ · NTAP-20240808-0007
CVE-2024-40762024-07-23HIGH7.5Client queries that trigger serving stale data and that also require lookups in local authoritative zone data may result in an assertion failure. This issue aff NVD ↗ · NTAP-20240731-0001
CVE-2024-40896——— NVD ↗ · NTAP-20250228-0004
CVE-2024-40898——— NVD ↗ · NTAP-20240808-0006
CVE-2024-41110——— NVD ↗ · NTAP-20240802-0001
CVE-2024-41123——— NVD ↗ · NTAP-20241227-0005
CVE-2024-41172——— NVD ↗ · NTAP-20240808-0008
CVE-2024-41721——— NVD ↗ · NTAP-20240926-0009
CVE-2024-41909——— NVD ↗ · NTAP-20241011-0006
CVE-2024-41928——— NVD ↗ · NTAP-20240920-0009
CVE-2024-41946——— NVD ↗ · NTAP-20250117-0007
CVE-2024-41957——— NVD ↗ · NTAP-20241129-0007
CVE-2024-41965——— NVD ↗ · NTAP-20241115-0002
CVE-2024-41989——— NVD ↗ · NTAP-20240905-0007
CVE-2024-41990——— NVD ↗ · NTAP-20240905-0007
CVE-2024-41991——— NVD ↗ · NTAP-20240905-0007
CVE-2024-419962024-08-26HIGH7.5Validating the order of the public keys in the Diffie-Hellman Key Agreement Protocol, when an approved safe prime is used, allows remote attackers (from the cli NVD ↗ · NTAP-20260227-0009
CVE-2024-42005——— NVD ↗ · NTAP-20240905-0007
CVE-2024-421542024-07-30MEDIUM4.4In the Linux kernel, the following vulnerability has been resolved: tcp_metrics: validate source addr length I don't see anything checking that TCP_METRICS_ATTR NVD ↗ · NTAP-20240828-0010
CVE-2024-422562024-08-08HIGH7.5In the Linux kernel, the following vulnerability has been resolved: cifs: Fix server re-repick on subrequest retry When a subrequest is marked for needing retry NVD ↗ · NTAP-20250627-0004
CVE-2024-42416——— NVD ↗ · NTAP-20240920-0010
CVE-2024-42459——— NVD ↗ · NTAP-20241004-0005
CVE-2024-42460——— NVD ↗ · NTAP-20241004-0005
CVE-2024-42461——— NVD ↗ · NTAP-20241004-0005
CVE-2024-425162025-07-10HIGH7.5HTTP response splitting in the core of Apache HTTP Server allows an attacker who can manipulate the Content-Type response headers of applications hosted or prox NVD ↗ · NTAP-20250718-0013
CVE-2024-43102——— NVD ↗ · NTAP-20240916-0001
CVE-2024-43110——— NVD ↗ · NTAP-20240920-0010
CVE-2024-4317——— NVD ↗ · NTAP-20250328-0001
CVE-2024-432042025-07-10HIGH7.5SSRF in Apache HTTP Server with mod_proxy loaded allows an attacker to send outbound proxy requests to a URL controlled by the attacker. Requires an unlikely co NVD ↗ · NTAP-20250718-0013
CVE-2024-43374——— NVD ↗ · NTAP-20240920-0004
CVE-2024-433942025-07-10HIGH7.5Server-Side Request Forgery (SSRF) in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via mod_rewrite or apache expre NVD ↗ · NTAP-20250718-0013
CVE-2024-43398——— NVD ↗ · NTAP-20250103-0006
CVE-2024-43484——— NVD ↗ · NTAP-20250328-0007
CVE-2024-43590——— NVD ↗ · NTAP-20260320-0009
CVE-2024-43709——— NVD ↗ · NTAP-20250221-0007
CVE-2024-43790——— NVD ↗ · NTAP-20240920-0005
CVE-2024-43802——— NVD ↗ · NTAP-20241004-0008
CVE-2024-4418——— NVD ↗ · NTAP-20250411-0002
CVE-2024-4467——— NVD ↗ · NTAP-20240822-0005
CVE-2024-45063——— NVD ↗ · NTAP-20240920-0010
CVE-2024-45217——— NVD ↗ · NTAP-20260102-0007
CVE-2024-452872024-09-05HIGH7.5A malicious value of size in a structure of packed libnv can cause an integer overflow, leading to the allocation of a smaller buffer than required for the pars NVD ↗ · NTAP-20240926-0010
CVE-2024-452882024-09-05HIGH8.4A missing null-termination character in the last element of an nvlist array string can lead to writing outside the allocated buffer. NVD ↗ · NTAP-20240920-0008
CVE-2024-45289——— NVD ↗ · NTAP-20250110-0001
CVE-2024-45296——— NVD ↗ · NTAP-20250124-0001
CVE-2024-45306——— NVD ↗ · NTAP-20241004-0007
CVE-2024-45310——— NVD ↗ · NTAP-20250221-0008
CVE-2024-45332——— NVD ↗ · NTAP-20260403-0008
CVE-2024-45336——— NVD ↗ · NTAP-20250221-0003
CVE-2024-45337——— NVD ↗ · NTAP-20250131-0007
CVE-2024-45338——— NVD ↗ · NTAP-20250221-0001
CVE-2024-45339——— NVD ↗ · NTAP-20251128-0001
CVE-2024-45341——— NVD ↗ · NTAP-20250221-0004
CVE-2024-45409——— NVD ↗ · NTAP-20240926-0008
CVE-2024-454902024-08-30HIGH7.5An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a negative length for XML_ParseBuffer. NVD ↗ · NTAP-20241018-0004
CVE-2024-45491——— NVD ↗ · NTAP-20241018-0003
CVE-2024-45492——— NVD ↗ · NTAP-20241018-0005
CVE-2024-45663——— NVD ↗ · NTAP-20241220-0003
CVE-2024-4577——— NVD ↗ · NTAP-20240621-0008
CVE-2024-45778——— NVD ↗ · NTAP-20250627-0007
CVE-2024-45782——— NVD ↗ · NTAP-20251114-0008
CVE-2024-45802——— NVD ↗ · NTAP-20250103-0004
CVE-2024-46032024-05-16MEDIUM5.3Issue summary: Checking excessively long DSA keys or parameters may be very slow. Impact summary: Applications that use the functions EVP_PKEY_param_check() or NVD ↗ · NTAP-20240621-0001
CVE-2024-4693——— NVD ↗ · NTAP-20240828-0007
CVE-2024-47076——— NVD ↗ · NTAP-20241011-0001
CVE-2024-47118——— NVD ↗ · NTAP-20260220-0006
CVE-2024-47175——— NVD ↗ · NTAP-20241011-0001
CVE-2024-47176——— NVD ↗ · NTAP-20241011-0001
CVE-2024-47177——— NVD ↗ · NTAP-20241011-0001
CVE-2024-47220——— NVD ↗ · NTAP-20250814-0010
CVE-2024-472522025-07-10HIGH7.5Insufficient escaping of user-supplied data in mod_ssl in Apache HTTP Server 2.4.63 and earlier allows an untrusted SSL/TLS client to insert escape characters i NVD ↗ · NTAP-20250718-0013
CVE-2024-47412024-11-13HIGH7.5Issue summary: Calling the OpenSSL API function SSL_free_buffers may cause memory to be accessed that was previously freed in some situations Impact summary: A NVD ↗ · NTAP-20240621-0004
CVE-2024-475352024-11-12MEDIUM5.5Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. An unsafe NVD ↗ · NTAP-20260917-0001
CVE-2024-475542024-10-03MEDIUM4.3Uncontrolled Resource Consumption vulnerability in Apache Commons IO. The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resource NVD ↗ · NTAP-20250131-0010
CVE-2024-47561——— NVD ↗ · NTAP-20241011-0003
CVE-2024-47606——— NVD ↗ · NTAP-20250418-0003
CVE-2024-47611——— NVD ↗ · NTAP-20250605-0006
CVE-2024-476852024-10-21CRITICAL9.1In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_reject_ipv6: fix nf_reject_ip6_tcphdr_put() syzbot reported that nf_reject_ip6 NVD ↗ · NTAP-20250613-0011
CVE-2024-47689——— NVD ↗ · NTAP-20250627-0001
CVE-2024-476932024-10-21MEDIUM6.5In the Linux kernel, the following vulnerability has been resolved: IB/core: Fix ib_cache_setup_one error flow cleanup When ib_cache_update return an error, we NVD ↗ · NTAP-20250627-0002
CVE-2024-477642024-10-04MEDIUM6.9cookie is a basic HTTP cookie parser and serializer for HTTP servers. The cookie name could be used to set other fields of the cookie, resulting in an unexpecte NVD ↗ · NTAP-20260917-0001
CVE-2024-47814——— NVD ↗ · NTAP-20250411-0009
CVE-2024-478502024-10-04HIGH7.5CUPS cups-browsed before 2.5b1 will send an HTTP POST request to an arbitrary destination and port in response to a single IPP UDP packet requesting a printer t NVD ↗ · NTAP-20241011-0002
CVE-2024-48869——— NVD ↗ · NTAP-20260403-0012
CVE-2024-48948——— NVD ↗ · NTAP-20241220-0004
CVE-2024-48949——— NVD ↗ · NTAP-20241227-0003
CVE-2024-49350——— NVD ↗ · NTAP-20250620-0004
CVE-2024-49761——— NVD ↗ · NTAP-20241227-0004
CVE-2024-49766——— NVD ↗ · NTAP-20250131-0005
CVE-2024-49767——— NVD ↗ · NTAP-20250103-0007
CVE-2024-49828——— NVD ↗ · NTAP-20250829-0013
CVE-2024-49861——— NVD ↗ · NTAP-20260227-0007
CVE-2024-499972024-10-21HIGH7.5In the Linux kernel, the following vulnerability has been resolved: net: ethernet: lantiq_etop: fix memory disclosure When applying padding, the buffer is not z NVD ↗ · NTAP-20250627-0005
CVE-2024-50076——— NVD ↗ · NTAP-20250627-0003
CVE-2024-500832024-10-29HIGH7.5In the Linux kernel, the following vulnerability has been resolved: tcp: fix mptcp DSS corruption due to large pmtu xmit Syzkaller was able to trigger a DSS cor NVD ↗ · NTAP-20250523-0010
CVE-2024-50379——— NVD ↗ · NTAP-20250103-0003
CVE-2024-50602——— NVD ↗ · NTAP-20250404-0008
CVE-2024-51473——— NVD ↗ · NTAP-20250829-0012
CVE-2024-51504——— NVD ↗ · NTAP-20250530-0002
CVE-2024-51562——— NVD ↗ · NTAP-20250207-0008
CVE-2024-51563——— NVD ↗ · NTAP-20250207-0008
CVE-2024-51564——— NVD ↗ · NTAP-20250207-0008
CVE-2024-51565——— NVD ↗ · NTAP-20250207-0008
CVE-2024-51566——— NVD ↗ · NTAP-20250207-0008
CVE-2024-51744——— NVD ↗ · NTAP-20251024-0003
CVE-2024-52046——— NVD ↗ · NTAP-20250103-0001
CVE-2024-52316——— NVD ↗ · NTAP-20250124-0003
CVE-2024-52317——— NVD ↗ · NTAP-20250124-0004
CVE-2024-52318——— NVD ↗ · NTAP-20250131-0009
CVE-2024-525332024-11-11CRITICAL9.8gio/gsocks4aproxy.c in GNOME GLib before 2.82.1 has an off-by-one error and resultant buffer overflow because SOCKS4_CONN_MSG_LEN is not sufficient for a traili NVD ↗ · NTAP-20241206-0009
CVE-2024-52798——— NVD ↗ · NTAP-20250124-0002
CVE-2024-52894——— NVD ↗ · NTAP-20250829-0011
CVE-2024-52979——— NVD ↗ · NTAP-20250904-0003
CVE-2024-52981——— NVD ↗ · NTAP-20250605-0009
CVE-2024-532212024-12-27MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: f2fs: fix null-ptr-deref in f2fs_submit_page_bio() There's issue as follows when concurrentl NVD ↗ · NTAP-20260925-0009
CVE-2024-535802024-12-18HIGH7.5iperf v3.17.1 was discovered to contain a segmentation violation via the iperf_exchange_parameters() function. NVD ↗ · NTAP-20250404-0009
CVE-2024-53589——— NVD ↗ · NTAP-20250314-0006
CVE-2024-53677——— NVD ↗ · NTAP-20250103-0005
CVE-2024-53846——— NVD ↗ · NTAP-20250620-0010
CVE-2024-53899——— NVD ↗ · NTAP-20260123-0001
CVE-2024-53900——— NVD ↗ · NTAP-20250613-0005
CVE-2024-54085——— NVD ↗ · NTAP-20250328-0003
CVE-2024-54133——— NVD ↗ · NTAP-20250306-0010
CVE-2024-54534——— NVD ↗ · NTAP-20250418-0002
CVE-2024-54582024-06-09MEDIUM5.3In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, due to a code logic error, filtering functions such as filter_var when validating NVD ↗ · NTAP-20240726-0001
CVE-2024-54677——— NVD ↗ · NTAP-20250131-0006
CVE-2024-55352024-06-27CRITICAL9.1Issue summary: Calling the OpenSSL API function SSL_select_next_proto with an empty supported client protocols buffer may cause a crash or memory contents to be NVD ↗ · NTAP-20260522-0001 · NTAP-20241025-0006 +3
CVE-2024-555492025-03-14HIGH7.8xsltGetInheritedNsList in libxslt before 1.1.43 has a use-after-free issue related to exclusion of result prefixes. NVD ↗ · NTAP-20250613-0007

Years: 2026 · 2025 · 2024 · 2023 · 2022 · 2021 · 2020 · 2019 · 2018 · 2017 · 2016 · 2015 · 2014 · 2013 · 2012 · 2011 · 2010 · 2009 · 2008 · 2007 · 2006 · 2005 · 2004 · 2003 · 2002 · 1999

← CVE index · Security hub