İçeriğe atla
Noroxi

NetApp kayıtları

netapp üreticisine ait 2.519 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
40 · %1,6
Silahlaştırılmış
52 · %2,1
Pre-auth RCE
72
Düzeltme kaydı olan
%67,6
Yayından KEV’e ortanca
651 gün

Tüm kayıtlar

2.519 kayıt
  • Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints

    KritikCVSS 10,0KEVSilahlaştırılmışEPSS %100

    apache · log4j10 Ara 2021

  • The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-mes

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    apache · struts10 Mar 2017

  • Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    apache · http server5 Eki 2021

  • Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    apache · http server7 Eki 2021

  • Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    apache · tomcat10 Mar 2025

  • Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    apache · activemq27 Eki 2023

  • When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat.

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99

    apache · geode24 Şub 2020

  • Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to aff

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %92

    oracle · jdk21 Nis 2016

  • A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user.

    KritikCVSS 9,0KEVSilahlaştırılmışEPSS %100

    resf · rocky linux16 Eyl 2021

  • Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.

    KritikCVSS 9,1KEVSilahlaştırılmışEPSS %100

    apache · http server1 Tem 2024

  • Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %90

    apache · tomcat6 Nis 2017

  • Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bo

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %100

    google · chrome12 Eyl 2023

  • XStream is vulnerable to a Remote Command Execution attack

    YüksekCVSS 8,5KEVSilahlaştırılmışEPSS %98

    xstream · xstream23 Ağu 2021

  • Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (ei

    YüksekCVSS 8,1KEVSilahlaştırılmışEPSS %100

    apache · struts22 Ağu 2018

  • When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g.

    YüksekCVSS 8,1KEVSilahlaştırılmışEPSS %100

    apache · tomcat3 Eki 2017

  • When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g.

    YüksekCVSS 8,1KEVSilahlaştırılmışEPSS %100

    apache · tomcat19 Eyl 2017

  • The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStrea

    YüksekCVSS 8,1KEVSilahlaştırılmışEPSS %99

    apache · struts15 Eyl 2017

  • Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root

    YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %100

    sudo project · sudo26 Oca 2021

  • The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as

    YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %100

    siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware10 Eki 2023

  • JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, does not properly sanitize inputs for

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %83

    redhat · jboss enterprise application platform5 Ağu 2010

  • A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe

    YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %93

    linux · linux kernel10 Mar 2022

  • Redfish Authentication Bypass

    KritikCVSS 10,0KEVSilahlaştırılmışEPSS %61

    ami · megarac sp-x11 Mar 2025

  • Glibc: buffer overflow in ld.so leading to privilege escalation

    YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %81

    gnu · glibc3 Eki 2023

  • Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE

    YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %79

    linux · linux kernel7 Tem 2021

  • Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect ha

    YüksekCVSS 7,0KEVSilahlaştırılmışEPSS %84

    linux · linux kernel10 Kas 2016