Netapp Ontap Tools vulnerabilities
24 known vulnerabilities affecting netapp/ontap_tools.
Total CVEs
24
CISA KEV
1
actively exploited
Public exploits
3
Exploited in wild
2
Severity breakdown
CRITICAL3HIGH13MEDIUM7LOW1
Vulnerabilities
Page 2 of 2
CVE-2024-26633P4MEDIUMCVSS 5.5v92024-03-18
CVE-2024-26633 [MEDIUM] CVE-2024-26633: In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: fix NEXTHDR_FRAGMEN
In the Linux kernel, the following vulnerability has been resolved:
ip6_tunnel: fix NEXTHDR_FRAGMENT handling in ip6_tnl_parse_tlv_enc_lim()
syzbot pointed out [1] that NEXTHDR_FRAGMENT handling is broken.
Reading frag_off can only be done if we pulled enough bytes
to skb->head. Currently we might access garbage.
[1]
BUG: KMSAN: uninit-value in ip6_tnl_p
nvd
CVE-2024-47554P4MEDIUMCVSS 4.3v9v102024-10-03
CVE-2024-47554 [MEDIUM] CWE-400 CVE-2024-47554: Uncontrolled Resource Consumption vulnerability in Apache Commons IO. The org.apache.commons.io.inp
Uncontrolled Resource Consumption vulnerability in Apache Commons IO.
The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input.
This issue affects Apache Commons IO: from 2.0 before 2.14.0.
Users are recommended to upgrade to version 2.14.0 or later, which fixes the issu
nvd
CVE-2025-0167P4LOWCVSS 3.4v92025-02-05
CVE-2025-0167 [LOW] CVE-2025-0167: When asked to use a `.netrc` file for credentials **and** to follow HTTP redirects, curl could leak
When asked to use a `.netrc` file for credentials **and** to follow HTTP
redirects, curl could leak the password used for the first host to the
followed-to host under certain circumstances.
This flaw only manifests itself if the netrc file has a `default` entry that
omits both login and password. A rare circumstance.
nvd
CVE-2023-52433P4MEDIUMCVSS 4.4v9v102024-02-20
CVE-2023-52433 [MEDIUM] CWE-273 CVE-2023-52433: In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_rbtree: skip
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nft_set_rbtree: skip sync GC for new elements in this transaction
New elements in this transaction might expired before such transaction
ends. Skip sync GC for such elements otherwise commit path might walk
over an already released object. Once transaction is finished, a
nvd
← Previous2 / 2