NetApp / Snap Creator Framework
42 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2022-22968 | Framework: Data Binding Rules Vulnerability | HIGH | 7.5 | Apr 14, 2022 |
| CVE-2020-36518 | jackson-databind: denial of service via a large depth of nested objects | HIGH | 7.5 | Mar 11, 2022 |
| CVE-2021-42550 | RCE from attacker with configuration edit priviledges through JNDI lookup | MEDIUM | 6.6 | Dec 16, 2021 |
| CVE-2021-22096 | springframework: malicious input leads to insertion of additional log entries | MEDIUM | 4.3 | Oct 28, 2021 |
| CVE-2021-34429 | jetty: crafted URIs allow bypassing security constraints | MEDIUM | 5.3 | Jul 15, 2021 |
| CVE-2021-34428 | jetty: SessionListener can prevent a session from being invalidated breaking logout | LOW | 3.5 | Jun 22, 2021 |
| CVE-2021-28169 | jetty: requests to the ConcatServlet and WelcomeFilter are able to access protected resources within the WEB-INF directory | MEDIUM | 5.3 | Jun 9, 2021 |
| CVE-2020-27223 | jetty: request containing multiple Accept headers with a large number of "quality" parameters may lead to DoS | MEDIUM | 5.3 | Feb 26, 2021 |
| CVE-2021-23901 | An XML external entity (XXE) injection vulnerability exists in the Nutch DmozParser | CRITICAL | 9.1 | Jan 25, 2021 |
| CVE-2021-23926 | XMLBeans XML Entity Expansion | CRITICAL | 9.1 | Jan 14, 2021 |
| CVE-2020-27218 | jetty: buffer not correctly recycled in Gzip Request inflation | MEDIUM | 4.8 | Nov 28, 2020 |
| CVE-2020-13954 | Apache CXF Reflected XSS in the services listing page via the styleSheetPath | MEDIUM | 6.1 | Nov 12, 2020 |
| CVE-2020-27216 | jetty: local temporary directory hijacking vulnerability | HIGH | 7.0 | Oct 23, 2020 |
| CVE-2020-5421 | RFD Protection Bypass via jsessionid | MEDIUM | 6.5 | Sep 19, 2020 |
| CVE-2020-12723 | perl: corruption of intermediate language state of compiled regular expression due to recursive S_study_chunk() calls leads to DoS | HIGH | 7.5 | Jun 5, 2020 |
| CVE-2020-10878 | perl: corruption of intermediate language state of compiled regular expression due to integer overflow leads to DoS | HIGH | 8.6 | Jun 5, 2020 |
| CVE-2020-7656 | jquery: Cross-site scripting (XSS) via <script> HTML tags containing whitespaces | MEDIUM | 5.3 | May 19, 2020 |
| CVE-2020-10683 | dom4j: XML External Entity vulnerability in default SAX parser | CRITICAL | 9.8 | May 1, 2020 |
| CVE-2020-11023 KEV | Potential XSS vulnerability in jQuery | MEDIUM | 6.9 | Apr 29, 2020 |
| CVE-2020-11022 | jQuery has a potential XSS vulnerability | MEDIUM | 6.9 | Apr 29, 2020 |
| CVE-2016-5710 | NetApp Snap Creator Framework before 4.3P1 allows remote authenticated users to conduct clickjacking attacks via unspecified vectors. | MEDIUM | 4.6 | Feb 10, 2020 |
| CVE-2019-10247 | jetty: error path information disclosure | MEDIUM | 5.3 | Apr 22, 2019 |
| CVE-2019-10246 | jetty: Directory Listing on Windows reveals Resource Base path | MEDIUM | 5.3 | Apr 22, 2019 |
| CVE-2018-18314 | perl: Heap-based buffer overflow in S_regatom() | CRITICAL | 9.8 | Dec 7, 2018 |
| CVE-2018-18313 | perl: Heap-based buffer read overflow in S_grok_bslash_N() | CRITICAL | 9.1 | Dec 7, 2018 |
Showing 1 to 25 of 42 CVEs