Metrics
Affected Vendors & Products
Mon, 08 Sep 2025 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-400 CWE-674 |
Wed, 13 Aug 2025 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:google:protobuf-java:4.27.5:*:*:*:*:*:*:* cpe:2.3:a:google:protobuf-java:4.28.2:*:*:*:*:*:*:* cpe:2.3:a:google:protobuf-javalite:3.25.5:*:*:*:*:*:*:* cpe:2.3:a:google:protobuf-javalite:4.27.5:*:*:*:*:*:*:* cpe:2.3:a:google:protobuf-javalite:4.28.2:*:*:*:*:*:*:* cpe:2.3:a:google:protobuf-kotlin-lite:3.25.5:*:*:*:*:*:*:* cpe:2.3:a:google:protobuf-kotlin-lite:4.27.5:*:*:*:*:*:*:* cpe:2.3:a:google:protobuf-kotlin-lite:4.28.2:*:*:*:*:*:*:* cpe:2.3:a:google:protobuf-kotlin:3.25.5:*:*:*:*:*:*:* cpe:2.3:a:google:protobuf-kotlin:4.27.5:*:*:*:*:*:*:* cpe:2.3:a:google:protobuf-kotlin:4.28.2:*:*:*:*:*:*:* cpe:2.3:a:google:protobuf:28.2:*:*:*:*:*:*:* cpe:2.3:a:google:protobuf:3.25.5:*:*:*:*:ruby:*:* cpe:2.3:a:google:protobuf:4.27.5:*:*:*:*:ruby:*:* cpe:2.3:a:google:protobuf:4.28.2:*:*:*:*:ruby:*:* |
cpe:2.3:a:google:protobuf:*:*:*:*:*:ruby:*:* |
Wed, 30 Jul 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Netapp
Netapp active Iq Unified Manager Netapp bluexp Netapp ontap Tools |
|
| Weaknesses | CWE-787 | |
| CPEs | cpe:2.3:a:google:protobuf-java:3.25.5:*:*:*:*:*:*:* cpe:2.3:a:google:protobuf-java:4.27.5:*:*:*:*:*:*:* cpe:2.3:a:google:protobuf-java:4.28.2:*:*:*:*:*:*:* cpe:2.3:a:google:protobuf-javalite:3.25.5:*:*:*:*:*:*:* cpe:2.3:a:google:protobuf-javalite:4.27.5:*:*:*:*:*:*:* cpe:2.3:a:google:protobuf-javalite:4.28.2:*:*:*:*:*:*:* cpe:2.3:a:google:protobuf-kotlin-lite:3.25.5:*:*:*:*:*:*:* cpe:2.3:a:google:protobuf-kotlin-lite:4.27.5:*:*:*:*:*:*:* cpe:2.3:a:google:protobuf-kotlin-lite:4.28.2:*:*:*:*:*:*:* cpe:2.3:a:google:protobuf-kotlin:3.25.5:*:*:*:*:*:*:* cpe:2.3:a:google:protobuf-kotlin:4.27.5:*:*:*:*:*:*:* cpe:2.3:a:google:protobuf-kotlin:4.28.2:*:*:*:*:*:*:* cpe:2.3:a:google:protobuf:28.2:*:*:*:*:*:*:* cpe:2.3:a:google:protobuf:3.25.5:*:*:*:*:ruby:*:* cpe:2.3:a:google:protobuf:4.27.5:*:*:*:*:ruby:*:* cpe:2.3:a:google:protobuf:4.28.2:*:*:*:*:ruby:*:* cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:* cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:* cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:* cpe:2.3:a:netapp:bluexp:-:*:*:*:*:*:*:* cpe:2.3:a:netapp:ontap_tools:10:*:*:*:*:vmware_vsphere:*:* |
|
| Vendors & Products |
Netapp
Netapp active Iq Unified Manager Netapp bluexp Netapp ontap Tools |
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Thu, 15 May 2025 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat jboss Enterprise Application Platform
|
|
| CPEs | cpe:/a:redhat:jboss_enterprise_application_platform:8.0 | |
| Vendors & Products |
Redhat jboss Enterprise Application Platform
|
Tue, 06 May 2025 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat apache Camel Spring Boot
|
|
| CPEs | cpe:/a:redhat:apache_camel_spring_boot:4.4.3 cpe:/a:redhat:apache_camel_spring_boot:4.8 |
|
| Vendors & Products |
Redhat apache Camel Spring Boot
|
Sat, 19 Apr 2025 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 28 Mar 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:quarkus:3.8::el8 |
Tue, 17 Dec 2024 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat trusted Profile Analyzer
|
|
| CPEs | cpe:/a:redhat:trusted_profile_analyzer:1.2::el9 | |
| Vendors & Products |
Redhat trusted Profile Analyzer
|
Fri, 13 Dec 2024 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 05 Dec 2024 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat quarkus
|
|
| CPEs | cpe:/a:redhat:quarkus:3.2::el8 | |
| Vendors & Products |
Redhat quarkus
|
Thu, 14 Nov 2024 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat amq Streams
|
|
| CPEs | cpe:/a:redhat:amq_streams:2 | |
| Vendors & Products |
Redhat amq Streams
|
Fri, 11 Oct 2024 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat
Redhat camel Quarkus |
|
| CPEs | cpe:/a:redhat:camel_quarkus:3.8 | |
| Vendors & Products |
Redhat
Redhat camel Quarkus |
Thu, 19 Sep 2024 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Google
Google google-protobuf Google protobuf Google protobuf-java Google protobuf-javalite Google protobuf-kotlin Google protobuf-kotlin-lite |
|
| CPEs | cpe:2.3:a:google:google-protobuf:*:*:*:*:*:ruby:*:* cpe:2.3:a:google:protobuf-java:*:*:*:*:*:*:*:* cpe:2.3:a:google:protobuf-javalite:*:*:*:*:*:*:*:* cpe:2.3:a:google:protobuf-kotlin-lite:*:*:*:*:*:*:*:* cpe:2.3:a:google:protobuf-kotlin:*:*:*:*:*:*:*:* cpe:2.3:a:google:protobuf:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Google
Google google-protobuf Google protobuf Google protobuf-java Google protobuf-javalite Google protobuf-kotlin Google protobuf-kotlin-lite |
|
| Metrics |
ssvc
|
Thu, 19 Sep 2024 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Thu, 19 Sep 2024 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Any project that parses untrusted Protocol Buffers data containing an arbitrary number of nested groups / series of SGROUP tags can corrupted by exceeding the stack limit i.e. StackOverflow. Parsing nested groups as unknown fields with DiscardUnknownFieldsParser or Java Protobuf Lite parser, or against Protobuf map fields, creates unbounded recursions that can be abused by an attacker. | |
| Title | Stack overflow in Protocol Buffers Java Lite | |
| Weaknesses | CWE-20 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Google
Published: 2024-09-19T00:18:45.824Z
Updated: 2025-09-08T09:37:53.702Z
Reserved: 2024-07-29T21:41:56.116Z
Link: CVE-2024-7254
Updated: 2025-04-19T00:11:07.841Z
Status : Analyzed
Published: 2024-09-19T01:15:10.963
Modified: 2025-09-26T17:10:19.847
Link: CVE-2024-7254