Home/Product/netapp bootstrap os
Product

netapp bootstrap os

55 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-30691
all versions
Vulnerability in Oracle Java SE (component: Compiler). Supported versions that are affected are Oracle Java SE: 21.0.6, 24; Oracl
4.8MEDIUM
CVE-2025-29768
all versions
Vim, a text editor, is vulnerable to potential data loss with zip.vim and special crafted zip files in versions prior to 9.1.1198.
4.4MEDIUM
CVE-2025-24813
all versions
Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious con
9.8CRITICAL
CVE-2025-1215
all versions
A vulnerability classified as problematic was found in vim up to 9.1.1096. This vulnerability affects unknown code of the file src
2.8LOW
CVE-2025-0665
all versions
libcurl would wrongly close the same eventfd file descriptor twice when taking down a connection channel after having completed a
7.0HIGH
CVE-2025-0167
all versions
When asked to use a .netrc file for credentials and to follow HTTP redirects, curl could leak the password used for the firs
3.4LOW
CVE-2025-21502
all versions
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (componen
4.8MEDIUM
CVE-2025-22134
all versions
When switching to other buffers using the :all command and visual mode still being active, this may cause a heap-buffer overflow,
4.2MEDIUM
CVE-2024-56337
all versions
Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M
9.8CRITICAL
CVE-2024-54677
all versions
Uncontrolled Resource Consumption vulnerability in the examples web application provided with Apache Tomcat leads to denial of ser
5.3MEDIUM
CVE-2024-50379
all versions
Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE on case ins
9.8CRITICAL
CVE-2024-11053
all versions
When asked to both use a .netrc file for credentials and to follow HTTP redirects, curl could leak the password used for the fir
3.4LOW
CVE-2024-21211
all versions
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (componen
3.7LOW
CVE-2024-9823
all versions
There exists a security vulnerability in Jetty's DosFilter which can be exploited by unauthorized users to cause remote denial-of-
5.3MEDIUM
CVE-2024-47814
all versions
Vim is an open source, command line text editor. A use-after-free was found in Vim < 9.1.0764. When closing a buffer (visible in a
3.9LOW
CVE-2024-8096
all versions
When curl is told to use the Certificate Status Request TLS extension, often referred to as OCSP stapling, to verify that the serv
6.5MEDIUM
CVE-2024-6119
all versions
Issue summary: Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to rea
7.5HIGH
CVE-2024-43790
all versions
Vim is an open source command line text editor. When performing a search and displaying the search-count message is disabled (:set
4.5MEDIUM
CVE-2024-43398
all versions
REXML is an XML toolkit for Ruby. The REXML gem before 3.3.6 has a DoS vulnerability when it parses an XML that has many deep elem
5.9MEDIUM
CVE-2024-43374
all versions
The UNIX editor Vim prior to version 9.1.0678 has a use-after-free error in argument list handling. When adding a new file to the
4.5MEDIUM
CVE-2024-21147
all versions
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (componen
7.4HIGH
CVE-2024-21140
all versions
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (componen
4.8MEDIUM
CVE-2024-39908
all versions
REXML is an XML toolkit for Ruby. The REXML gem before 3.3.1 has some DoS vulnerabilities when it parses an XML that has many spec
4.3MEDIUM
CVE-2024-6387
all versions
A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to
8.1HIGH
CVE-2024-26306
all versions
iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA authentication, allows a timing side channel in RSA d
5.9MEDIUM
CVE-2024-32487
all versions
less through 653 allows OS command execution via a newline character in the name of a file, because quoting is mishandled in filen
8.6HIGH
CVE-2023-29483
all versions
eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickl
7.0HIGH
CVE-2024-2312
all versions
GRUB2 does not call the module fini functions on exit, leading to Debian/Ubuntu's peimage GRUB2 module leaving UEFI system table h
6.7MEDIUM
CVE-2024-2466
all versions
libcurl did not check the server certificate of TLS connections done to a host specified as an IP address, when built to use mbedT
6.5MEDIUM
CVE-2024-2398
all versions
When an application tells libcurl it wants to allow HTTP/2 server push, and the amount of received headers for the push surpasses
8.6HIGH
CVE-2024-2379
all versions
libcurl skips the certificate verification for a QUIC connection under certain conditions, when built to use wolfSSL. If told to u
6.3MEDIUM
CVE-2024-2004
all versions
When a protocol selection parameter option disables all protocols without adding any then the default set of protocols would remai
3.5LOW
CVE-2023-50868
all versions
The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to c
7.5HIGH
CVE-2023-4911
all versions
A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment varia
7.8HIGH
CVE-2022-45061
all versions
An issue was discovered in Python before 3.11.1. An unnecessary quadratic algorithm exists in one path when processing some inputs
7.5HIGH
CVE-2022-35252
all versions
When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when later are s
3.7LOW
CVE-2022-32208
all versions
When curl < 7.84.0 does FTP transfers secured by krb5, it handles message verification failures wrongly. This flaw makes it possib
5.9MEDIUM
CVE-2022-32207
all versions
When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation
9.8CRITICAL
CVE-2022-32206
all versions
curl < 7.84.0 supports "chained" HTTP compression algorithms, meaning that a serverresponse can be compressed multiple times and p
6.5MEDIUM
CVE-2022-2068
all versions
In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script d
7.3HIGH
CVE-2022-22576
all versions
An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticate
8.1HIGH
CVE-2022-1678
all versions
An issue was discovered in the Linux Kernel from 4.18 to 4.19, an improper update of sock reference in TCP pacing can lead to memo
5.9MEDIUM
CVE-2022-21496
all versions
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JNDI). Supported vers
5.3MEDIUM
CVE-2022-21476
all versions
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported
7.5HIGH
CVE-2022-21443
all versions
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported
3.7LOW
CVE-2021-4203
all versions
A use-after-free read flaw was found in sock_getsockopt() in net/core/sock.c due to SO_PEERCRED and SO_PEERGROUPS race with listen
6.8MEDIUM
CVE-2022-23308
all versions
valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.
7.5HIGH
CVE-2020-36516
all versions
An issue was discovered in the Linux kernel through 5.16.11. The mixed IPID assignment method with the hash-based IPID assignment
5.9MEDIUM
CVE-2021-3753
all versions
A race problem was seen in the vt_k_ioctl in drivers/tty/vt/vt_ioctl.c in the Linux kernel, which may cause an out of bounds read
4.7MEDIUM
CVE-2021-36086
all versions
The CIL compiler in SELinux 3.2 has a use-after-free in cil_reset_classpermission (called from cil_reset_classperms_set and cil_re
3.3LOW
CVE-2020-13143
all versions
gadget_dev_desc_UDC_store in drivers/usb/gadget/configfs.c in the Linux kernel 3.16 through 5.6.13 relies on kstrdup without consi
6.5MEDIUM
CVE-2020-12888
all versions
The VFIO PCI driver in the Linux kernel through 5.6.13 mishandles attempts to access disabled memory space.
5.3MEDIUM
CVE-2020-12770
all versions
An issue was discovered in the Linux kernel through 5.6.11. sg_write lacks an sg_remove_request call in a certain failure case, ak
6.7MEDIUM
CVE-2020-11884
all versions
In the Linux kernel 4.19 through 5.6.7 on the s390 platform, code execution may occur because of a race condition, as demonstrated
7.0HIGH
CVE-2019-17498
all versions
In libssh2 v1.9.0 and earlier versions, the SSH_MSG_DISCONNECT logic in packet.c has an integer overflow in a bounds check, enabli
8.1HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin