onosproject records
15 published records for vendor onosproject.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 6.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-611 Improper Restriction of XML External Entity Reference2
- CWE-19 Data Processing Errors1
- CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')1
- CWE-125 Out-of-bounds Read1
- CWE-476 NULL Pointer Dereference1
The weakness classes this vendor ships most often: where to look.
CWEAll records
15 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2017-1000081No exploit | Linux foundation ONOS 1.9.0 is vulnerable to unauthenticated upload of applications (.oar) resulting in remote code execution.onosproject · onos · CWE-434 | Critical9.8 | — | 3.0% | Jul 17, 2017 |
40Plan | CVE-2019-13624No exploit | In ONOS 1.15.0, apps/yang/web/src/main/java/org/onosproject/yang/web/YangWebResource.java mishandles backquote characters within strings thaonosproject · onos · CWE-19 | Critical9.8 | — | 1.9% | Jul 16, 2019 |
39Monitor | CVE-2018-1000614No exploit | ONOS ONOS Controller version 1.13.1 and earlier contains a XML External Entity (XXE) vulnerability in providers/netconf/alarm/src/main/java/onosproject · onos · CWE-611 | Critical9.8 | — | 1.6% | Jul 9, 2018 |
39Monitor | CVE-2018-1000616No exploit | ONOS ONOS controller version 1.13.1 and earlier contains a XML External Entity (XXE) vulnerability in onos\drivers\utilities\src\main\java\oonosproject · onos · CWE-611 | Critical9.8 | — | 1.4% | Jul 9, 2018 |
31Monitor | CVE-2015-7516No exploit | ONOS before 1.5.0 when using the ifwd app allows remote attackers to cause a denial of service (NULL pointer dereference and switch disconneonosproject · onos · CWE-476 | High7.5 | — | 3.7% | Aug 24, 2017 |
30Monitor | CVE-2017-1000079No exploit | Linux foundation ONOS 1.9.0 is vulnerable to a DoS.onosproject · onos | High7.5 | — | 1.3% | Jul 17, 2017 |
30Monitor | CVE-2018-1000615No exploit | ONOS ONOS Controller version 1.13.1 and earlier contains a Denial of Service (Service crash) vulnerability in OVSDB component in ONOS that conosproject · onos | High7.5 | — | 1.2% | Jul 9, 2018 |
30Monitor | CVE-2017-13763No exploit | ONOS versions 1.8.0, 1.9.0, and 1.10.0 do not restrict the amount of memory allocated.onosproject · onos · CWE-770 | High7.5 | — | 1.1% | Aug 29, 2017 |
30Monitor | CVE-2017-1000080No exploit | Linux foundation ONOS 1.9.0 allows unauthenticated use of websockets.onosproject · onos | High7.5 | — | 1.0% | Jul 17, 2017 |
30Monitor | CVE-2024-34049No exploit | Open Networking Foundation SD-RAN Rimedo rimedo-ts 0.1.1 has a slice bounds out-of-range panic in "return plmnIdString[0:3], plmnIdString[3:onosproject · traffic steering xapplication · CWE-125 | High7.5 | — | 0.5% | Apr 29, 2024 |
30Monitor | CVE-2024-34050No exploit | Open Networking Foundation SD-RAN Rimedo rimedo-ts 0.1.1 has a slice bounds out-of-range panic in "return uint64(b[2])<<16 | uint64(b[1])<<8onosproject · traffic steering xapplication · CWE-129 | High7.5 | — | 0.5% | Apr 29, 2024 |
27Monitor | CVE-2018-12691No exploit | Time-of-check to time-of-use (TOCTOU) race condition in org.onosproject.acl (aka the access control application) in ONOS v1.13 and earlier aonosproject · onos · CWE-362 | Medium6.8 | — | 0.7% | Jul 5, 2018 |
24Monitor | CVE-2017-13762No exploit | ONOS versions 1.8.0, 1.9.0, and 1.10.0 are vulnerable to XSS.onosproject · onos · CWE-79 | Medium6.1 | — | 1.2% | Aug 29, 2017 |
24Monitor | CVE-2017-1000078No exploit | Linux foundation ONOS 1.9 is vulnerable to XSS in the device.onosproject · onos · CWE-79 | Medium6.1 | — | 0.7% | Jul 17, 2017 |
24Monitor | CVE-2023-30093No exploit | A cross-site scripting (XSS) vulnerability in Open Networking Foundation ONOS from version v1.9.0 to v2.7.0 allows attackers to execute arbionosproject · onos · CWE-79 | Medium6.1 | — | 0.5% | May 4, 2023 |
- CVE-2017-100008140Plan
Linux foundation ONOS 1.9.0 is vulnerable to unauthenticated upload of applications (.oar) resulting in remote code execution.
CriticalCVSS 9.8No exploitEPSS 3%onosproject · onosJul 17, 2017
- CVE-2019-1362440Plan
In ONOS 1.15.0, apps/yang/web/src/main/java/org/onosproject/yang/web/YangWebResource.java mishandles backquote characters within strings tha
CriticalCVSS 9.8No exploitEPSS 2%onosproject · onosJul 16, 2019
- CVE-2018-100061439Monitor
ONOS ONOS Controller version 1.13.1 and earlier contains a XML External Entity (XXE) vulnerability in providers/netconf/alarm/src/main/java/
CriticalCVSS 9.8No exploitEPSS 2%onosproject · onosJul 9, 2018
- CVE-2018-100061639Monitor
ONOS ONOS controller version 1.13.1 and earlier contains a XML External Entity (XXE) vulnerability in onos\drivers\utilities\src\main\java\o
CriticalCVSS 9.8No exploitEPSS 1%onosproject · onosJul 9, 2018
- CVE-2015-751631Monitor
ONOS before 1.5.0 when using the ifwd app allows remote attackers to cause a denial of service (NULL pointer dereference and switch disconne
HighCVSS 7.5No exploitEPSS 4%onosproject · onosAug 24, 2017
- CVE-2017-100007930Monitor
Linux foundation ONOS 1.9.0 is vulnerable to a DoS.
HighCVSS 7.5No exploitEPSS 1%onosproject · onosJul 17, 2017
- CVE-2018-100061530Monitor
ONOS ONOS Controller version 1.13.1 and earlier contains a Denial of Service (Service crash) vulnerability in OVSDB component in ONOS that c
HighCVSS 7.5No exploitEPSS 1%onosproject · onosJul 9, 2018
- CVE-2017-1376330Monitor
ONOS versions 1.8.0, 1.9.0, and 1.10.0 do not restrict the amount of memory allocated.
HighCVSS 7.5No exploitEPSS 1%onosproject · onosAug 29, 2017
- CVE-2017-100008030Monitor
Linux foundation ONOS 1.9.0 allows unauthenticated use of websockets.
HighCVSS 7.5No exploitEPSS 1%onosproject · onosJul 17, 2017
- CVE-2024-3404930Monitor
Open Networking Foundation SD-RAN Rimedo rimedo-ts 0.1.1 has a slice bounds out-of-range panic in "return plmnIdString[0:3], plmnIdString[3:
HighCVSS 7.5No exploitEPSS 1%onosproject · traffic steering xapplicationApr 29, 2024
- CVE-2024-3405030Monitor
Open Networking Foundation SD-RAN Rimedo rimedo-ts 0.1.1 has a slice bounds out-of-range panic in "return uint64(b[2])<<16 | uint64(b[1])<<8
HighCVSS 7.5No exploitEPSS 1%onosproject · traffic steering xapplicationApr 29, 2024
- CVE-2018-1269127Monitor
Time-of-check to time-of-use (TOCTOU) race condition in org.onosproject.acl (aka the access control application) in ONOS v1.13 and earlier a
MediumCVSS 6.8No exploitEPSS 1%onosproject · onosJul 5, 2018
- CVE-2017-1376224Monitor
ONOS versions 1.8.0, 1.9.0, and 1.10.0 are vulnerable to XSS.
MediumCVSS 6.1No exploitEPSS 1%onosproject · onosAug 29, 2017
- CVE-2017-100007824Monitor
Linux foundation ONOS 1.9 is vulnerable to XSS in the device.
MediumCVSS 6.1No exploitEPSS 1%onosproject · onosJul 17, 2017
- CVE-2023-3009324Monitor
A cross-site scripting (XSS) vulnerability in Open Networking Foundation ONOS from version v1.9.0 to v2.7.0 allows attackers to execute arbi
MediumCVSS 6.1No exploitEPSS 0%onosproject · onosMay 4, 2023