Home / Security / CVE index / 2024
2024 NetApp CVEs (page 3)
Showing 76 CVEs with a 2024 identifier — page 3 of 3. Sorted by CVE id.
Always verify. NetApp's advisory is authoritative for affected versions and fixes; NVD carries the CVSS record.
Showing 76 of 76
| CVE | Published | Severity | CVSS | Summary / Sources |
|---|---|---|---|---|
CVE-2024-5585 | — | — | — | NVD ↗ · NTAP-20240726-0002 |
CVE-2024-56128 | — | — | — | NVD ↗ · NTAP-20250711-0005 |
CVE-2024-56171 | 2025-02-18 | HIGH | 7.8 | libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlschemas.c. To exploit NVD ↗ · NTAP-20250328-0010 |
CVE-2024-56337 | — | — | — | NVD ↗ · NTAP-20250103-0002 |
CVE-2024-56339 | — | — | — | NVD ↗ · NTAP-20260522-0001 |
CVE-2024-56344 | 2026-09-18 | MEDIUM | 5.9 | IBM Cognos Analytics 12.0.4 through 12.0.4 FP2, and 12.1.0 through 12.1.3 FP1 could allow a remote attacker to obtain sensitive information, caused by the failu NVD ↗ · NTAP-20260917-0001 |
CVE-2024-56406 | — | — | — | NVD ↗ · NTAP-20250613-0010 |
CVE-2024-5642 | — | — | — | NVD ↗ · NTAP-20240726-0005 |
CVE-2024-56779 | — | — | — | NVD ↗ · NTAP-20260204-0001 |
CVE-2024-57360 | — | — | — | NVD ↗ · NTAP-20250926-0001 |
CVE-2024-57699 | — | — | — | NVD ↗ · NTAP-20260605-0001 · NTAP-20260213-0003 |
CVE-2024-58251 | — | — | — | NVD ↗ · NTAP-20260422-0016 |
CVE-2024-5971 | — | — | — | NVD ↗ · NTAP-20240828-0001 |
CVE-2024-6096 | — | — | — | NVD ↗ · NTAP-20250425-0003 |
CVE-2024-6119 | 2024-09-03 | HIGH | 7.5 | Issue summary: Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address re NVD ↗ · NTAP-20240912-0001 |
CVE-2024-6162 | — | — | — | NVD ↗ · NTAP-20241129-0009 |
CVE-2024-6197 | — | — | — | NVD ↗ · NTAP-20241129-0008 |
CVE-2024-6232 | 2024-09-03 | HIGH | 7.5 | There is a MEDIUM severity vulnerability affecting CPython. Regular expressions that allowed excessive backtracking during tarfile.TarFile header parsing are vu NVD ↗ · NTAP-20241018-0007 |
CVE-2024-6322 | — | — | — | NVD ↗ · NTAP-20251010-0004 |
CVE-2024-6345 | — | — | — | NVD ↗ · NTAP-20251017-0006 |
CVE-2024-6375 | — | — | — | NVD ↗ · NTAP-20250822-0002 |
CVE-2024-6383 | — | — | — | NVD ↗ · NTAP-20241004-0001 |
CVE-2024-6384 | — | — | — | NVD ↗ · NTAP-20241115-0001 |
CVE-2024-6387 | 2024-07-01 | HIGH | 8.1 | A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsa NVD ↗ · NTAP-20240701-0001 |
CVE-2024-6409 | 2024-07-08 | HIGH | 7.0 | A race condition vulnerability was discovered in how signals are handled by OpenSSH's server (sshd). If a remote attacker does not authenticate within a set tim NVD ↗ · NTAP-20240712-0003 |
CVE-2024-6505 | — | — | — | NVD ↗ · NTAP-20240816-0006 |
CVE-2024-6640 | — | — | — | NVD ↗ · NTAP-20240816-0008 |
CVE-2024-6716 | — | — | — | NVD ↗ · NTAP-20240808-0010 |
CVE-2024-6759 | — | — | — | NVD ↗ · NTAP-20240816-0009 |
CVE-2024-6760 | — | — | — | NVD ↗ · NTAP-20240816-0010 |
CVE-2024-6763 | 2024-10-14 | LOW | 3.7 | Eclipse Jetty is a lightweight, highly scalable, Java-based web server and Servlet engine . It includes a utility class, HttpURI, for URI/URL parsing. The HttpU NVD ↗ · NTAP-20250306-0005 |
CVE-2024-6839 | — | — | — | NVD ↗ · NTAP-20260522-0001 |
CVE-2024-6844 | — | — | — | NVD ↗ · NTAP-20260522-0001 |
CVE-2024-6866 | — | — | — | NVD ↗ · NTAP-20260522-0001 |
CVE-2024-6874 | — | — | — | NVD ↗ · NTAP-20240822-0004 |
CVE-2024-6923 | 2024-08-01 | MEDIUM | 5.5 | There is a MEDIUM severity vulnerability affecting CPython. The email module didn’t properly quote newlines for email headers when serializing an email message NVD ↗ · NTAP-20240926-0003 |
CVE-2024-7006 | 2024-08-12 | HIGH | 7.5 | A null pointer dereference flaw was found in Libtiff via `tif_dirinfo.c`. This issue may allow an attacker to trigger memory allocation failures through certain NVD ↗ · NTAP-20240920-0001 |
CVE-2024-7254 | 2024-09-19 | HIGH | 7.5 | Any project that parses untrusted Protocol Buffers data containing an arbitrary number of nested groups / series of SGROUP tags can corrupted by exceeding the s NVD ↗ · NTAP-20250418-0006 · NTAP-20241213-0010 |
CVE-2024-7264 | 2024-07-31 | MEDIUM | 6.5 | libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an ASN.1 Generalized Time field. If given an syntactically incorrect field, the pars NVD ↗ · NTAP-20241025-0006 · NTAP-20241025-0010 +1 |
CVE-2024-7347 | — | — | — | NVD ↗ · NTAP-20250814-0003 |
CVE-2024-7348 | — | — | — | NVD ↗ · NTAP-20240822-0002 |
CVE-2024-7409 | — | — | — | NVD ↗ · NTAP-20250502-0008 |
CVE-2024-7589 | — | — | — | NVD ↗ · NTAP-20240816-0002 |
CVE-2024-7592 | 2024-08-19 | HIGH | 7.5 | There is a LOW severity vulnerability affecting CPython, specifically the 'http.cookies' standard library module. When parsing cookies that contained backslashe NVD ↗ · NTAP-20241018-0006 |
CVE-2024-7594 | — | — | — | NVD ↗ · NTAP-20250110-0007 |
CVE-2024-7840 | — | — | — | NVD ↗ · NTAP-20250425-0004 |
CVE-2024-7885 | — | — | — | NVD ↗ · NTAP-20241011-0004 |
CVE-2024-8014 | — | — | — | NVD ↗ · NTAP-20250425-0004 |
CVE-2024-8048 | — | — | — | NVD ↗ · NTAP-20250425-0004 |
CVE-2024-8088 | 2024-08-22 | HIGH | 8.7 | There is a HIGH severity vulnerability affecting the CPython "zipfile" module affecting "zipfile.Path". Note that the more common API "zipfile.ZipFile" class is NVD ↗ · NTAP-20241011-0010 |
CVE-2024-8096 | 2024-09-11 | MEDIUM | 6.5 | When curl is told to use the Certificate Status Request TLS extension, often referred to as OCSP stapling, to verify that the server certificate is valid, it mi NVD ↗ · NTAP-20241011-0005 |
CVE-2024-8118 | — | — | — | NVD ↗ · NTAP-20250808-0011 |
CVE-2024-8176 | 2025-03-14 | HIGH | 7.5 | A stack overflow vulnerability exists in the libexpat library due to the way it handles recursive entity expansion in XML documents. When parsing an XML documen NVD ↗ · NTAP-20250328-0009 |
CVE-2024-8178 | — | — | — | NVD ↗ · NTAP-20240920-0010 |
CVE-2024-8207 | — | — | — | NVD ↗ · NTAP-20250516-0009 |
CVE-2024-8235 | — | — | — | NVD ↗ · NTAP-20240920-0006 |
CVE-2024-8244 | — | — | — | NVD ↗ · NTAP-20260206-0006 |
CVE-2024-8354 | — | — | — | NVD ↗ · NTAP-20241011-0008 |
CVE-2024-8372 | — | — | — | NVD ↗ · NTAP-20241122-0002 |
CVE-2024-8373 | — | — | — | NVD ↗ · NTAP-20241122-0003 |
CVE-2024-8612 | — | — | — | NVD ↗ · NTAP-20241108-0006 |
CVE-2024-8654 | — | — | — | NVD ↗ · NTAP-20250516-0008 |
CVE-2024-8925 | 2024-10-08 | LOW | 3.1 | In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, erroneous parsing of multipart form data contained in an HTTP POST request could NVD ↗ · NTAP-20241101-0003 |
CVE-2024-8926 | 2024-10-08 | HIGH | 8.1 | In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, when using a certain non-standard configurations of Windows codepages, the fixes NVD ↗ · NTAP-20241101-0003 |
CVE-2024-8927 | 2024-10-08 | HIGH | 7.5 | In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, HTTP_REDIRECT_STATUS variable is used to check whether or not CGI binary is being NVD ↗ · NTAP-20241101-0003 |
CVE-2024-8929 | — | — | — | NVD ↗ · NTAP-20250110-0008 |
CVE-2024-8932 | 2024-11-22 | CRITICAL | 9.8 | In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, uncontrolled long string inputs to ldap_escape() function on 32-bit systems can c NVD ↗ · NTAP-20250110-0009 |
CVE-2024-9026 | 2024-10-08 | LOW | 3.3 | In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, when using PHP-FPM SAPI and it is configured to catch workers output through catc NVD ↗ · NTAP-20241101-0003 |
CVE-2024-9143 | 2024-10-16 | MEDIUM | 4.3 | Issue summary: Use of the low-level GF(2^m) elliptic curve APIs with untrusted explicit values for the field polynomial can lead to out-of-bounds memory reads o NVD ↗ · NTAP-20241101-0001 |
CVE-2024-9264 | — | — | — | NVD ↗ · NTAP-20250314-0007 |
CVE-2024-9287 | 2024-10-22 | HIGH | 7.8 | A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allo NVD ↗ · NTAP-20250425-0006 |
CVE-2024-9407 | — | — | — | NVD ↗ · NTAP-20241220-0010 |
CVE-2024-9622 | — | — | — | NVD ↗ · NTAP-20250704-0004 |
CVE-2024-9632 | — | — | — | NVD ↗ · NTAP-20250605-0001 |
CVE-2024-9681 | 2024-11-06 | MEDIUM | 6.5 | When curl is asked to use HSTS, the expiry time for a subdomain might overwrite a parent domain's cache entry, making it end sooner or later than otherwise inte NVD ↗ · NTAP-20241213-0006 |
CVE-2024-9823 | — | — | — | NVD ↗ · NTAP-20250306-0006 |
Years: 2026 · 2025 · 2024 · 2023 · 2022 · 2021 · 2020 · 2019 · 2018 · 2017 · 2016 · 2015 · 2014 · 2013 · 2012 · 2011 · 2010 · 2009 · 2008 · 2007 · 2006 · 2005 · 2004 · 2003 · 2002 · 1999