Skip to content
Noroxi

openvswitch records

22 published records for vendor openvswitch.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
95.5%
Median publish → KEV
No record has entered KEV

All records

22 records
  • Buffer overflow in lib/flow.c in ovs-vswitchd in Open vSwitch 2.2.x and 2.3.x before 2.3.3 and 2.4.x before 2.4.1 allows remote attackers to

    CriticalCVSS 9.8No exploitEPSS 6%

    openvswitch · openvswitchJul 3, 2016

  • In Open vSwitch (OvS) 2.7.0, while parsing an OFPT_QUEUE_GET_CONFIG_REPLY type OFP 1.0 message, there is a buffer over-read that is caused b

    CriticalCVSS 9.8No exploitEPSS 3%

    openvswitch · openvswitchMay 23, 2017

  • In Open vSwitch (OvS) v2.7.0, there is a buffer over-read while parsing the group mod OpenFlow message sent from the controller in `lib/ofp-

    CriticalCVSS 9.8No exploitEPSS 3%

    openvswitch · openvswitchMay 29, 2017

  • In lib/conntrack.c in the firewall implementation in Open vSwitch (OvS) 2.6.1, there is a buffer over-read while parsing malformed TCP, UDP,

    CriticalCVSS 9.8No exploitEPSS 2%

    openvswitch · openvswitchMay 29, 2017

  • CVE-2022-4338
    39Monitor

    An integer underflow in Organization Specific TLV was found in various versions of OpenvSwitch.

    CriticalCVSS 9.8No exploitEPSS 1%

    openvswitch · openvswitchJan 10, 2023

  • CVE-2022-4337
    39Monitor

    An out-of-bounds read in Organization Specific TLV was found in various versions of OpenvSwitch.

    CriticalCVSS 9.8No exploitEPSS 1%

    openvswitch · openvswitchJan 10, 2023

  • In Open vSwitch (OvS) 2.5.0, a malformed IP packet can cause the switch to read past the end of the packet buffer due to an unsigned integer

    HighCVSS 8.8No exploitEPSS 1%

    openvswitch · openvswitchMay 29, 2017

  • A vulnerability was found in openvswitch.

    HighCVSS 7.5Proof of conceptEPSS 8%

    openvswitch · openvswitchFeb 11, 2021

  • A flaw was found in multiple versions of OpenvSwitch.

    HighCVSS 7.5No exploitEPSS 3%

    openvswitch · openvswitchMar 18, 2021

  • An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6, affecting ofproto_rule_insert__ in ofproto/ofproto.c.

    HighCVSS 7.5No exploitEPSS 3%

    openvswitch · openvswitchSep 19, 2018

  • CVE-2021-3905
    31Monitor

    A memory leak was found in Open vSwitch (OVS) during userspace IP fragmentation processing.

    HighCVSS 7.5No exploitEPSS 2%

    openvswitch · openvswitchAug 23, 2022

  • CVE-2023-3966
    30Monitor

    Openvswsitch: ovs-vswitch fails to recover after malformed geneve metadata packet

    HighCVSS 7.5No exploitEPSS 1%

    openvswitch · openvswitchFeb 22, 2024

  • openvswitch 2.17.8 was discovered to contain a memory leak via the function xmalloc__ in openvswitch-2.17.8/lib/util.c.

    HighCVSS 7.5No exploitEPSS 1%

    openvswitch · openvswitchJan 19, 2024

  • CVE-2017-9263
    26Monitor

    In Open vSwitch (OvS) 2.7.0, while parsing an OpenFlow role status message, there is a call to the abort() function for undefined role statu

    MediumCVSS 6.5No exploitEPSS 1%

    openvswitch · openvswitchMay 29, 2017

  • CVE-2022-0669
    26Monitor

    A flaw was found in dpdk.

    MediumCVSS 6.5No exploitEPSS 0%

    dpdk · data plane development kitAug 29, 2022

  • The TSS (Tuple Space Search) algorithm in Open vSwitch 2.x through 2.17.2 and 3.0.0 allows remote attackers to cause a denial of service (de

    MediumCVSS 5.8No exploitEPSS 2%

    openvswitch · openvswitchSep 8, 2022

  • In lib/ofp-util.c in Open vSwitch (OvS) before 2.8.1, there are multiple memory leaks while parsing malformed OpenFlow group mod messages.

    MediumCVSS 5.9No exploitEPSS 1%

    openvswitch · openvswitchOct 1, 2017

  • Open vSwitch (aka openvswitch) 2.11.0 through 2.15.0 has a use-after-free in decode_NXAST_RAW_ENCAP (called from ofpact_decode and ofpacts_d

    MediumCVSS 5.5No exploitEPSS 1%

    openvswitch · openvswitchJul 20, 2021

  • CVE-2023-5366
    22Monitor

    Openvswitch don't match packets on nd_target field

    MediumCVSS 5.5No exploitEPSS 0%

    openvswitch · openvswitchOct 6, 2023

  • An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6.

    MediumCVSS 4.9No exploitEPSS 2%

    openvswitch · openvswitchSep 19, 2018

  • An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6, affecting parse_group_prop_ntr_selection_method in lib/ofp-util.c.

    MediumCVSS 4.3No exploitEPSS 2%

    openvswitch · openvswitchSep 19, 2018

  • CVE-2012-3449
    14Monitor

    Open vSwitch 1.4.2 uses world writable permissions for (1) /var/lib/openvswitch/pki/controllerca/incoming/ and (2) /var/lib/openvswitch/pki/

    LowCVSS 3.6No exploitEPSS 0%

    openvswitch · openvswitchAug 7, 2012