Skip to content
Noroxi

arista records

105 published records for vendor arista.

All records

105 records
  • GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attac

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    gnu · bashSep 24, 2014

  • GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variabl

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    gnu · bashSep 24, 2014

  • CVE-2026-16812
    70This week

    VeloCloud Orchestrator OS Command Injection

    CriticalCVSS 10.0KEVWeaponizedEPSS 1%

    arista · velocloud orchestratorJul 27, 2026

  • CVE-2026-93952
    68This week

    Security Advisory 0183

    CriticalCVSS 9.5KEVWeaponizedEPSS 1%

    arista · velocloud orchestratorSep 22, 2026

  • CVE-2017-14491
    64This week

    Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via

    CriticalCVSS 9.8Proof of conceptEPSS 85%

    thekelleys · dnsmasqOct 3, 2017

  • CVE-2024-6387
    62This week

    Openssh: regresshion - race condition in ssh allows rce/dos

    HighCVSS 8.1Proof of conceptEPSS 100%

    sonicwall · sma 6200 firmwareJul 1, 2024

  • CVE-2026-31431
    62This week

    crypto: algif_aead - Revert to operating out-of-place

    HighCVSS 7.8KEVWeaponizedEPSS 3%

    linux · linux kernelApr 22, 2026

  • CVE-2020-10188
    61This week

    utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code via short writes or urgent data, becaus

    CriticalCVSS 9.8No exploitEPSS 74%

    netkit telnet project · netkit telnetMar 6, 2020

  • Arista EOS Unexpected Tunnel Protocol Decapsulation and Forwarding Bypass

    MediumCVSS 6.9KEVWeaponizedEPSS 1%

    arista · eosJun 5, 2026

  • The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11, and 4.9.x before 4.9.36, allows remote attac

    CriticalCVSS 9.8No exploitEPSS 53%

    linux · linux kernelJan 3, 2018

  • Arista DCS-7050QX-32S-R 4.20.9M, DCS-7050CX3-32S-R 4.20.11M, and DCS-7280SRAM-48C6-R 4.22.0.1F devices (and possibly other products) allow a

    CriticalCVSS 9.8WeaponizedEPSS 16%

    arista · dcs-7050qx-32s-r firmwareFeb 20, 2020

  • The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4.5.x and earlier, allows remote attackers to

    CriticalCVSS 9.3No exploitEPSS 13%

    xen · xenAug 12, 2015

  • Arista EOS before 4.11.12, 4.12 before 4.12.11, 4.13 before 4.13.14M, 4.14 before 4.14.5FX.5, and 4.15 before 4.15.0FX1.1 allows remote atta

    CriticalCVSS 10.0No exploitEPSS 4%

    arista · eosNov 19, 2015

  • In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, user authenticat

    CriticalCVSS 9.8No exploitEPSS 1%

    arista · metamako operating systemSep 9, 2021

  • In Arista's EOS software affected releases, eAPI might skip re-evaluating user credentials when certificate based authentication is used, which allows remote at

    CriticalCVSS 9.8No exploitEPSS 1%

    arista · eosFeb 4, 2022

  • CVE-2024-9132
    39Monitor

    The administrator is able to configure an insecure captive portal script

    CriticalCVSS 9.8No exploitEPSS 1%

    arista · ng firewallJan 10, 2025

  • Multiple SQL Injection vulnerabilities exist in the reporting application of the Arista Edge Threat Management - Arista NG Firewall (NGFW).

    HighCVSS 8.8No exploitEPSS 9%

    arista · ng firewallMar 4, 2024

  • CVE-2025-2767
    38Monitor

    Arista NG Firewall User-Agent Cross-Site Scripting Remote Code Execution Vulnerability

    CriticalCVSS 9.6No exploitEPSS 1%

    arista · ng firewallApr 23, 2025

  • An issue has recently been discovered in Arista EOS where certain gNOI APIs incorrectly skip authorization and authentication which could potentially allow a fa

    CriticalCVSS 9.1No exploitEPSS 1%

    arista · eosJan 14, 2022

  • CVE-2016-9012
    35Monitor

    CloudVision Portal (CVP) before 2016.1.2.1 allows remote authenticated users to gain access to the internal configuration mechanisms via the

    HighCVSS 8.8No exploitEPSS 2%

    arista · cloudvision portalJan 23, 2017

  • Arista NG Firewall ExecManagerImpl Command Injection Remote Code Execution Vulnerability

    HighCVSS 8.8No exploitEPSS 1%

    arista · ng firewallDec 19, 2024

  • CVE-2020-3973
    35Monitor

    The VeloCloud Orchestrator does not apply correct input validation which allows for blind SQL-injection.

    HighCVSS 8.8No exploitEPSS 1%

    arista · velocloud orchestratorJul 8, 2020

  • In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, authentication i

    HighCVSS 8.8No exploitEPSS 1%

    arista · metamako operating systemSep 9, 2021

  • CVE-2024-9188
    35Monitor

    Specially constructed queries cause cross platform scripting leaking administrator tokens

    HighCVSS 8.8No exploitEPSS 0%

    arista · ng firewallJan 10, 2025

  • CVE-2015-3209
    33Monitor

    Heap-based buffer overflow in the PCNET controller in QEMU allows remote attackers to execute arbitrary code by sending a packet with TXSTAT

    HighCVSS 7.5No exploitEPSS 10%

    qemu · qemuJun 15, 2015