openvswitch records
22 published records for vendor openvswitch.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 95.5%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-125 Out-of-bounds Read5
- CWE-400 Uncontrolled Resource Consumption3
- CWE-401 Missing Release of Memory after Effective Lifetime2
- CWE-617 Reachable Assertion2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-345 Insufficient Verification of Data Authenticity1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
22 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2016-2074No exploit | Buffer overflow in lib/flow.c in ovs-vswitchd in Open vSwitch 2.2.x and 2.3.x before 2.3.3 and 2.4.x before 2.4.1 allows remote attackers toopenvswitch · openvswitch · CWE-119 | Critical9.8 | — | 6.3% | Jul 3, 2016 |
40Plan | CVE-2017-9214No exploit | In Open vSwitch (OvS) 2.7.0, while parsing an OFPT_QUEUE_GET_CONFIG_REPLY type OFP 1.0 message, there is a buffer over-read that is caused bopenvswitch · openvswitch · CWE-191 | Critical9.8 | — | 2.9% | May 23, 2017 |
40Plan | CVE-2017-9265No exploit | In Open vSwitch (OvS) v2.7.0, there is a buffer over-read while parsing the group mod OpenFlow message sent from the controller in `lib/ofp-openvswitch · openvswitch · CWE-125 | Critical9.8 | — | 2.8% | May 29, 2017 |
40Plan | CVE-2017-9264No exploit | In lib/conntrack.c in the firewall implementation in Open vSwitch (OvS) 2.6.1, there is a buffer over-read while parsing malformed TCP, UDP,openvswitch · openvswitch · CWE-125 | Critical9.8 | — | 2.4% | May 29, 2017 |
39Monitor | CVE-2022-4338No exploit | An integer underflow in Organization Specific TLV was found in various versions of OpenvSwitch.openvswitch · openvswitch · CWE-125 | Critical9.8 | — | 1.3% | Jan 10, 2023 |
39Monitor | CVE-2022-4337No exploit | An out-of-bounds read in Organization Specific TLV was found in various versions of OpenvSwitch.openvswitch · openvswitch · CWE-125 | Critical9.8 | — | 1.3% | Jan 10, 2023 |
35Monitor | CVE-2016-10377No exploit | In Open vSwitch (OvS) 2.5.0, a malformed IP packet can cause the switch to read past the end of the packet buffer due to an unsigned integeropenvswitch · openvswitch · CWE-119 | High8.8 | — | 0.9% | May 29, 2017 |
32Monitor | CVE-2020-35498Proof of concept | A vulnerability was found in openvswitch.openvswitch · openvswitch · CWE-400 | High7.5 | — | 8.0% | Feb 11, 2021 |
31Monitor | CVE-2020-27827No exploit | A flaw was found in multiple versions of OpenvSwitch.openvswitch · openvswitch · CWE-400 | High7.5 | — | 3.2% | Mar 18, 2021 |
31Monitor | CVE-2018-17205No exploit | An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6, affecting ofproto_rule_insert__ in ofproto/ofproto.c.openvswitch · openvswitch · CWE-617 | High7.5 | — | 2.5% | Sep 19, 2018 |
31Monitor | CVE-2021-3905No exploit | A memory leak was found in Open vSwitch (OVS) during userspace IP fragmentation processing.openvswitch · openvswitch · CWE-401 | High7.5 | — | 2.0% | Aug 23, 2022 |
30Monitor | CVE-2023-3966No exploit | Openvswsitch: ovs-vswitch fails to recover after malformed geneve metadata packetopenvswitch · openvswitch · CWE-248 | High7.5 | — | 1.0% | Feb 22, 2024 |
30Monitor | CVE-2024-22563No exploit | openvswitch 2.17.8 was discovered to contain a memory leak via the function xmalloc__ in openvswitch-2.17.8/lib/util.c.openvswitch · openvswitch · CWE-401 | High7.5 | — | 0.6% | Jan 19, 2024 |
26Monitor | CVE-2017-9263No exploit | In Open vSwitch (OvS) 2.7.0, while parsing an OpenFlow role status message, there is a call to the abort() function for undefined role statuopenvswitch · openvswitch · CWE-20 | Medium6.5 | — | 1.0% | May 29, 2017 |
26Monitor | CVE-2022-0669No exploit | A flaw was found in dpdk.dpdk · data plane development kit · CWE-400 | Medium6.5 | — | 0.3% | Aug 29, 2022 |
24Monitor | CVE-2019-25076No exploit | The TSS (Tuple Space Search) algorithm in Open vSwitch 2.x through 2.17.2 and 3.0.0 allows remote attackers to cause a denial of service (deopenvswitch · openvswitch | Medium5.8 | — | 2.3% | Sep 8, 2022 |
23Monitor | CVE-2017-14970No exploit | In lib/ofp-util.c in Open vSwitch (OvS) before 2.8.1, there are multiple memory leaks while parsing malformed OpenFlow group mod messages.openvswitch · openvswitch · CWE-772 | Medium5.9 | — | 1.2% | Oct 1, 2017 |
22Monitor | CVE-2021-36980No exploit | Open vSwitch (aka openvswitch) 2.11.0 through 2.15.0 has a use-after-free in decode_NXAST_RAW_ENCAP (called from ofpact_decode and ofpacts_dopenvswitch · openvswitch · CWE-416 | Medium5.5 | — | 1.2% | Jul 20, 2021 |
22Monitor | CVE-2023-5366No exploit | Openvswitch don't match packets on nd_target fieldopenvswitch · openvswitch · CWE-345 | Medium5.5 | — | 0.4% | Oct 6, 2023 |
20Monitor | CVE-2018-17206No exploit | An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6.openvswitch · openvswitch · CWE-125 | Medium4.9 | — | 2.0% | Sep 19, 2018 |
18Monitor | CVE-2018-17204No exploit | An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6, affecting parse_group_prop_ntr_selection_method in lib/ofp-util.c.openvswitch · openvswitch · CWE-617 | Medium4.3 | — | 1.9% | Sep 19, 2018 |
14Monitor | CVE-2012-3449No exploit | Open vSwitch 1.4.2 uses world writable permissions for (1) /var/lib/openvswitch/pki/controllerca/incoming/ and (2) /var/lib/openvswitch/pki/openvswitch · openvswitch · CWE-264 | Low3.6 | — | 0.3% | Aug 7, 2012 |
- CVE-2016-207441Plan
Buffer overflow in lib/flow.c in ovs-vswitchd in Open vSwitch 2.2.x and 2.3.x before 2.3.3 and 2.4.x before 2.4.1 allows remote attackers to
CriticalCVSS 9.8No exploitEPSS 6%openvswitch · openvswitchJul 3, 2016
- CVE-2017-921440Plan
In Open vSwitch (OvS) 2.7.0, while parsing an OFPT_QUEUE_GET_CONFIG_REPLY type OFP 1.0 message, there is a buffer over-read that is caused b
CriticalCVSS 9.8No exploitEPSS 3%openvswitch · openvswitchMay 23, 2017
- CVE-2017-926540Plan
In Open vSwitch (OvS) v2.7.0, there is a buffer over-read while parsing the group mod OpenFlow message sent from the controller in `lib/ofp-
CriticalCVSS 9.8No exploitEPSS 3%openvswitch · openvswitchMay 29, 2017
- CVE-2017-926440Plan
In lib/conntrack.c in the firewall implementation in Open vSwitch (OvS) 2.6.1, there is a buffer over-read while parsing malformed TCP, UDP,
CriticalCVSS 9.8No exploitEPSS 2%openvswitch · openvswitchMay 29, 2017
- CVE-2022-433839Monitor
An integer underflow in Organization Specific TLV was found in various versions of OpenvSwitch.
CriticalCVSS 9.8No exploitEPSS 1%openvswitch · openvswitchJan 10, 2023
- CVE-2022-433739Monitor
An out-of-bounds read in Organization Specific TLV was found in various versions of OpenvSwitch.
CriticalCVSS 9.8No exploitEPSS 1%openvswitch · openvswitchJan 10, 2023
- CVE-2016-1037735Monitor
In Open vSwitch (OvS) 2.5.0, a malformed IP packet can cause the switch to read past the end of the packet buffer due to an unsigned integer
HighCVSS 8.8No exploitEPSS 1%openvswitch · openvswitchMay 29, 2017
- CVE-2020-3549832Monitor
A vulnerability was found in openvswitch.
HighCVSS 7.5Proof of conceptEPSS 8%openvswitch · openvswitchFeb 11, 2021
- CVE-2020-2782731Monitor
A flaw was found in multiple versions of OpenvSwitch.
HighCVSS 7.5No exploitEPSS 3%openvswitch · openvswitchMar 18, 2021
- CVE-2018-1720531Monitor
An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6, affecting ofproto_rule_insert__ in ofproto/ofproto.c.
HighCVSS 7.5No exploitEPSS 3%openvswitch · openvswitchSep 19, 2018
- CVE-2021-390531Monitor
A memory leak was found in Open vSwitch (OVS) during userspace IP fragmentation processing.
HighCVSS 7.5No exploitEPSS 2%openvswitch · openvswitchAug 23, 2022
- CVE-2023-396630Monitor
Openvswsitch: ovs-vswitch fails to recover after malformed geneve metadata packet
HighCVSS 7.5No exploitEPSS 1%openvswitch · openvswitchFeb 22, 2024
- CVE-2024-2256330Monitor
openvswitch 2.17.8 was discovered to contain a memory leak via the function xmalloc__ in openvswitch-2.17.8/lib/util.c.
HighCVSS 7.5No exploitEPSS 1%openvswitch · openvswitchJan 19, 2024
- CVE-2017-926326Monitor
In Open vSwitch (OvS) 2.7.0, while parsing an OpenFlow role status message, there is a call to the abort() function for undefined role statu
MediumCVSS 6.5No exploitEPSS 1%openvswitch · openvswitchMay 29, 2017
- CVE-2022-066926Monitor
A flaw was found in dpdk.
MediumCVSS 6.5No exploitEPSS 0%dpdk · data plane development kitAug 29, 2022
- CVE-2019-2507624Monitor
The TSS (Tuple Space Search) algorithm in Open vSwitch 2.x through 2.17.2 and 3.0.0 allows remote attackers to cause a denial of service (de
MediumCVSS 5.8No exploitEPSS 2%openvswitch · openvswitchSep 8, 2022
- CVE-2017-1497023Monitor
In lib/ofp-util.c in Open vSwitch (OvS) before 2.8.1, there are multiple memory leaks while parsing malformed OpenFlow group mod messages.
MediumCVSS 5.9No exploitEPSS 1%openvswitch · openvswitchOct 1, 2017
- CVE-2021-3698022Monitor
Open vSwitch (aka openvswitch) 2.11.0 through 2.15.0 has a use-after-free in decode_NXAST_RAW_ENCAP (called from ofpact_decode and ofpacts_d
MediumCVSS 5.5No exploitEPSS 1%openvswitch · openvswitchJul 20, 2021
- CVE-2023-536622Monitor
Openvswitch don't match packets on nd_target field
MediumCVSS 5.5No exploitEPSS 0%openvswitch · openvswitchOct 6, 2023
- CVE-2018-1720620Monitor
An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6.
MediumCVSS 4.9No exploitEPSS 2%openvswitch · openvswitchSep 19, 2018
- CVE-2018-1720418Monitor
An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6, affecting parse_group_prop_ntr_selection_method in lib/ofp-util.c.
MediumCVSS 4.3No exploitEPSS 2%openvswitch · openvswitchSep 19, 2018
- CVE-2012-344914Monitor
Open vSwitch 1.4.2 uses world writable permissions for (1) /var/lib/openvswitch/pki/controllerca/incoming/ and (2) /var/lib/openvswitch/pki/
LowCVSS 3.6No exploitEPSS 0%openvswitch · openvswitchAug 7, 2012