Netapp
Netapp Bootstrap OS: vulnerabilidades y CVE
Netapp Bootstrap OS tiene 57 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 4 son críticas y 4 figuran en el catálogo de explotación activa de CISA.
CVE57
Últimos 12 meses0
Críticas4
Explotadas activamente4
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-0492 | Alta (7.8) | 5.5% | ⚠ Explotación activa | 3 mar 2022 | A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to… |
| CVE-2025-24813 | Crítica (9.8) | 100% | ⚠ Explotación activa | 10 mar 2025 | Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded files via write enabled Default Servlet in Apache Tomcat. This issue… |
| CVE-2024-1086 | Alta (7.8) | 28% | ⚠ Explotación activa | 31 ene 2024 | A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the… |
| CVE-2023-4911 | Alta (7.8) | 81% | ⚠ Explotación activa | 3 oct 2023 | A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-30691 | Media (4.8) | 0.58% | — | 15 abr 2025 | Vulnerability in Oracle Java SE (component: Compiler). Supported versions that are affected are Oracle Java SE: 21.0.6, 24; Oracle GraalVM for JDK: 21.0.6 and 24. Difficult to exploit vulnerability allows… |
| CVE-2025-29768 | Media (4.4) | 0.39% | — | 13 mar 2025 | Vim, a text editor, is vulnerable to potential data loss with zip.vim and special crafted zip files in versions prior to 9.1.1198. The impact is medium because a user must be made to view such an archive with Vim and… |
| CVE-2025-24813 | Crítica (9.8) | 100% | ⚠ Explotación activa | 10 mar 2025 | Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded files via write enabled Default Servlet in Apache Tomcat. This issue… |
| CVE-2025-1215 | Baja (2.4) | 0.54% | — | 12 feb 2025 | A vulnerability classified as problematic was found in vim up to 9.1.1096. This vulnerability affects unknown code of the file src/main.c. The manipulation of the argument --log leads to memory corruption. It is… |
| CVE-2025-0665 | Alta (7) | 1.3% | — | 5 feb 2025 | libcurl would wrongly close the same eventfd file descriptor twice when taking down a connection channel after having completed a threaded name resolve. |
| CVE-2025-0167 | Baja (3.4) | 0.69% | — | 5 feb 2025 | When asked to use a `.netrc` file for credentials **and** to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests… |
| CVE-2025-21502 | Media (4.8) | 1.0% | — | 21 ene 2025 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u431-perf,… |
| CVE-2025-22134 | Media (5.5) | 0.37% | — | 13 ene 2025 | When switching to other buffers using the :all command and visual mode still being active, this may cause a heap-buffer overflow, because Vim does not properly end visual mode and therefore may try to access beyond the… |
| CVE-2024-56337 | Crítica (9.8) | 9.0% | — | 20 dic 2024 | Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.0.97. The… |
| CVE-2024-54677 | Media (5.3) | 1.9% | — | 17 dic 2024 | Uncontrolled Resource Consumption vulnerability in the examples web application provided with Apache Tomcat leads to denial of service. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1… |
| CVE-2024-50379 | Crítica (9.8) | 32% | — | 17 dic 2024 | Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE on case insensitive file systems when the default servlet is enabled for write (non-default… |
| CVE-2024-11053 | Baja (3.4) | 1.3% | — | 11 dic 2024 | When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests… |
| CVE-2024-21211 | Baja (3.7) | 0.67% | — | 15 oct 2024 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Compiler). Supported versions that are affected are Oracle Java SE: 23; Oracle GraalVM… |
| CVE-2024-9823 | Alta (7.5) | 0.94% | — | 14 oct 2024 | There exists a security vulnerability in Jetty's DosFilter which can be exploited by unauthorized users to cause remote denial-of-service (DoS) attack on the server using DosFilter. By repeatedly sending crafted… |
| CVE-2024-47814 | Media (4.7) | 0.29% | — | 7 oct 2024 | Vim is an open source, command line text editor. A use-after-free was found in Vim < 9.1.0764. When closing a buffer (visible in a window) a BufWinLeave auto command can cause an use-after-free if this auto command… |
| CVE-2024-8096 | Media (6.5) | 0.73% | — | 11 sept 2024 | When curl is told to use the Certificate Status Request TLS extension, often referred to as OCSP stapling, to verify that the server certificate is valid, it might fail to detect some OCSP problems and instead wrongly… |
| CVE-2024-6119 | Alta (7.5) | 67% | — | 3 sept 2024 | Issue summary: Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address resulting in abnormal termination of the application process.… |
| CVE-2024-43790 | Media (5.5) | 0.31% | — | 22 ago 2024 | Vim is an open source command line text editor. When performing a search and displaying the search-count message is disabled (:set shm+=S), the search pattern is displayed at the bottom of the screen in a buffer… |
| CVE-2024-43398 | Media (5.9) | 1.2% | — | 22 ago 2024 | REXML is an XML toolkit for Ruby. The REXML gem before 3.3.6 has a DoS vulnerability when it parses an XML that has many deep elements that have same local name attributes. If you need to parse untrusted XMLs with tree… |
| CVE-2024-43374 | Media (4.7) | 0.35% | — | 16 ago 2024 | The UNIX editor Vim prior to version 9.1.0678 has a use-after-free error in argument list handling. When adding a new file to the argument list, this triggers `Buf*` autocommands. If in such an autocommand the buffer… |
| CVE-2024-21147 | Alta (7.4) | 1.1% | — | 16 jul 2024 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u411, 8u411-perf,… |
| CVE-2024-21140 | Media (4.8) | 0.94% | — | 16 jul 2024 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u411, 8u411-perf,… |
| CVE-2024-39908 | Media (4.3) | 1.5% | — | 16 jul 2024 | REXML is an XML toolkit for Ruby. The REXML gem before 3.3.1 has some DoS vulnerabilities when it parses an XML that has many specific characters such as `<`, `0` and `%>`. If you need to parse untrusted XMLs, you many… |
| CVE-2024-6387 | Alta (8.1) | 100% | — | 1 jul 2024 | A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able… |
| CVE-2024-26306 | Media (5.9) | 1.1% | — | 14 may 2024 | iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA authentication, allows a timing side channel in RSA decryption operations. This side channel could be sufficient for an attacker to recover… |
| CVE-2024-32487 | Alta (8.6) | 0.63% | — | 13 abr 2024 | less through 653 allows OS command execution via a newline character in the name of a file, because quoting is mishandled in filename.c. Exploitation typically requires use with attacker-controlled file names, such as… |
| CVE-2023-29483 | Alta (7) | 1.9% | — | 11 abr 2024 | eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a "TuDoor"… |
| CVE-2024-2312 | Media (6.7) | 0.38% | — | 5 abr 2024 | GRUB2 does not call the module fini functions on exit, leading to Debian/Ubuntu's peimage GRUB2 module leaving UEFI system table hooks after exit. This lead to a use-after-free condition, and could possibly lead to… |
| CVE-2024-2466 | Media (6.5) | 1.3% | — | 27 mar 2024 | libcurl did not check the server certificate of TLS connections done to a host specified as an IP address, when built to use mbedTLS. libcurl would wrongly avoid using the set hostname function when the specified… |
| CVE-2024-2398 | Alta (8.6) | 36% | — | 27 mar 2024 | When an application tells libcurl it wants to allow HTTP/2 server push, and the amount of received headers for the push surpasses the maximum allowed limit (1000), libcurl aborts the server push. When aborting, libcurl… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Netapp
Oncommand Insight · 971Active IQ Unified Manager · 848Oncommand Workflow Automation · 743Snapcenter · 575Cloud Backup · 349H700s Firmware · 293H500s Firmware · 292H410s Firmware · 292H300s Firmware · 292E-series Santricity OS Controller · 242H410c Firmware · 240Steelstore Cloud Integrated Storage · 211