Записи openvswitch
22 опубликованных записей вендора openvswitch.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 95,5 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-125 Out-of-bounds Read5
- CWE-400 Uncontrolled Resource Consumption3
- CWE-401 Missing Release of Memory after Effective Lifetime2
- CWE-617 Reachable Assertion2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-345 Insufficient Verification of Data Authenticity1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
22 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2016-2074Эксплойта нет | Buffer overflow in lib/flow.c in ovs-vswitchd in Open vSwitch 2.2.x and 2.3.x before 2.3.3 and 2.4.x before 2.4.1 allows remote attackers toopenvswitch · openvswitch · CWE-119 | Критическая9,8 | — | 6,3 % | 3 июл. 2016 г. |
40В плане | CVE-2017-9214Эксплойта нет | In Open vSwitch (OvS) 2.7.0, while parsing an OFPT_QUEUE_GET_CONFIG_REPLY type OFP 1.0 message, there is a buffer over-read that is caused bopenvswitch · openvswitch · CWE-191 | Критическая9,8 | — | 2,9 % | 23 мая 2017 г. |
40В плане | CVE-2017-9265Эксплойта нет | In Open vSwitch (OvS) v2.7.0, there is a buffer over-read while parsing the group mod OpenFlow message sent from the controller in `lib/ofp-openvswitch · openvswitch · CWE-125 | Критическая9,8 | — | 2,8 % | 29 мая 2017 г. |
40В плане | CVE-2017-9264Эксплойта нет | In lib/conntrack.c in the firewall implementation in Open vSwitch (OvS) 2.6.1, there is a buffer over-read while parsing malformed TCP, UDP,openvswitch · openvswitch · CWE-125 | Критическая9,8 | — | 2,4 % | 29 мая 2017 г. |
39Наблюдать | CVE-2022-4338Эксплойта нет | An integer underflow in Organization Specific TLV was found in various versions of OpenvSwitch.openvswitch · openvswitch · CWE-125 | Критическая9,8 | — | 1,3 % | 10 янв. 2023 г. |
39Наблюдать | CVE-2022-4337Эксплойта нет | An out-of-bounds read in Organization Specific TLV was found in various versions of OpenvSwitch.openvswitch · openvswitch · CWE-125 | Критическая9,8 | — | 1,3 % | 10 янв. 2023 г. |
35Наблюдать | CVE-2016-10377Эксплойта нет | In Open vSwitch (OvS) 2.5.0, a malformed IP packet can cause the switch to read past the end of the packet buffer due to an unsigned integeropenvswitch · openvswitch · CWE-119 | Высокая8,8 | — | 0,9 % | 29 мая 2017 г. |
32Наблюдать | CVE-2020-35498Proof of concept | A vulnerability was found in openvswitch.openvswitch · openvswitch · CWE-400 | Высокая7,5 | — | 8,0 % | 11 февр. 2021 г. |
31Наблюдать | CVE-2020-27827Эксплойта нет | A flaw was found in multiple versions of OpenvSwitch.openvswitch · openvswitch · CWE-400 | Высокая7,5 | — | 3,2 % | 18 мар. 2021 г. |
31Наблюдать | CVE-2018-17205Эксплойта нет | An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6, affecting ofproto_rule_insert__ in ofproto/ofproto.c.openvswitch · openvswitch · CWE-617 | Высокая7,5 | — | 2,5 % | 19 сент. 2018 г. |
31Наблюдать | CVE-2021-3905Эксплойта нет | A memory leak was found in Open vSwitch (OVS) during userspace IP fragmentation processing.openvswitch · openvswitch · CWE-401 | Высокая7,5 | — | 2,0 % | 23 авг. 2022 г. |
30Наблюдать | CVE-2023-3966Эксплойта нет | Openvswsitch: ovs-vswitch fails to recover after malformed geneve metadata packetopenvswitch · openvswitch · CWE-248 | Высокая7,5 | — | 1,0 % | 22 февр. 2024 г. |
30Наблюдать | CVE-2024-22563Эксплойта нет | openvswitch 2.17.8 was discovered to contain a memory leak via the function xmalloc__ in openvswitch-2.17.8/lib/util.c.openvswitch · openvswitch · CWE-401 | Высокая7,5 | — | 0,6 % | 19 янв. 2024 г. |
26Наблюдать | CVE-2017-9263Эксплойта нет | In Open vSwitch (OvS) 2.7.0, while parsing an OpenFlow role status message, there is a call to the abort() function for undefined role statuopenvswitch · openvswitch · CWE-20 | Средняя6,5 | — | 1,0 % | 29 мая 2017 г. |
26Наблюдать | CVE-2022-0669Эксплойта нет | A flaw was found in dpdk.dpdk · data plane development kit · CWE-400 | Средняя6,5 | — | 0,3 % | 29 авг. 2022 г. |
24Наблюдать | CVE-2019-25076Эксплойта нет | The TSS (Tuple Space Search) algorithm in Open vSwitch 2.x through 2.17.2 and 3.0.0 allows remote attackers to cause a denial of service (deopenvswitch · openvswitch | Средняя5,8 | — | 2,3 % | 8 сент. 2022 г. |
23Наблюдать | CVE-2017-14970Эксплойта нет | In lib/ofp-util.c in Open vSwitch (OvS) before 2.8.1, there are multiple memory leaks while parsing malformed OpenFlow group mod messages.openvswitch · openvswitch · CWE-772 | Средняя5,9 | — | 1,2 % | 1 окт. 2017 г. |
22Наблюдать | CVE-2021-36980Эксплойта нет | Open vSwitch (aka openvswitch) 2.11.0 through 2.15.0 has a use-after-free in decode_NXAST_RAW_ENCAP (called from ofpact_decode and ofpacts_dopenvswitch · openvswitch · CWE-416 | Средняя5,5 | — | 1,2 % | 20 июл. 2021 г. |
22Наблюдать | CVE-2023-5366Эксплойта нет | Openvswitch don't match packets on nd_target fieldopenvswitch · openvswitch · CWE-345 | Средняя5,5 | — | 0,4 % | 6 окт. 2023 г. |
20Наблюдать | CVE-2018-17206Эксплойта нет | An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6.openvswitch · openvswitch · CWE-125 | Средняя4,9 | — | 2,0 % | 19 сент. 2018 г. |
18Наблюдать | CVE-2018-17204Эксплойта нет | An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6, affecting parse_group_prop_ntr_selection_method in lib/ofp-util.c.openvswitch · openvswitch · CWE-617 | Средняя4,3 | — | 1,9 % | 19 сент. 2018 г. |
14Наблюдать | CVE-2012-3449Эксплойта нет | Open vSwitch 1.4.2 uses world writable permissions for (1) /var/lib/openvswitch/pki/controllerca/incoming/ and (2) /var/lib/openvswitch/pki/openvswitch · openvswitch · CWE-264 | Низкая3,6 | — | 0,3 % | 7 авг. 2012 г. |
- CVE-2016-207441В плане
Buffer overflow in lib/flow.c in ovs-vswitchd in Open vSwitch 2.2.x and 2.3.x before 2.3.3 and 2.4.x before 2.4.1 allows remote attackers to
КритическаяCVSS 9,8Эксплойта нетEPSS 6 %openvswitch · openvswitch3 июл. 2016 г.
- CVE-2017-921440В плане
In Open vSwitch (OvS) 2.7.0, while parsing an OFPT_QUEUE_GET_CONFIG_REPLY type OFP 1.0 message, there is a buffer over-read that is caused b
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %openvswitch · openvswitch23 мая 2017 г.
- CVE-2017-926540В плане
In Open vSwitch (OvS) v2.7.0, there is a buffer over-read while parsing the group mod OpenFlow message sent from the controller in `lib/ofp-
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %openvswitch · openvswitch29 мая 2017 г.
- CVE-2017-926440В плане
In lib/conntrack.c in the firewall implementation in Open vSwitch (OvS) 2.6.1, there is a buffer over-read while parsing malformed TCP, UDP,
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %openvswitch · openvswitch29 мая 2017 г.
- CVE-2022-433839Наблюдать
An integer underflow in Organization Specific TLV was found in various versions of OpenvSwitch.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %openvswitch · openvswitch10 янв. 2023 г.
- CVE-2022-433739Наблюдать
An out-of-bounds read in Organization Specific TLV was found in various versions of OpenvSwitch.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %openvswitch · openvswitch10 янв. 2023 г.
- CVE-2016-1037735Наблюдать
In Open vSwitch (OvS) 2.5.0, a malformed IP packet can cause the switch to read past the end of the packet buffer due to an unsigned integer
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %openvswitch · openvswitch29 мая 2017 г.
- CVE-2020-3549832Наблюдать
A vulnerability was found in openvswitch.
ВысокаяCVSS 7,5Proof of conceptEPSS 8 %openvswitch · openvswitch11 февр. 2021 г.
- CVE-2020-2782731Наблюдать
A flaw was found in multiple versions of OpenvSwitch.
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %openvswitch · openvswitch18 мар. 2021 г.
- CVE-2018-1720531Наблюдать
An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6, affecting ofproto_rule_insert__ in ofproto/ofproto.c.
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %openvswitch · openvswitch19 сент. 2018 г.
- CVE-2021-390531Наблюдать
A memory leak was found in Open vSwitch (OVS) during userspace IP fragmentation processing.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %openvswitch · openvswitch23 авг. 2022 г.
- CVE-2023-396630Наблюдать
Openvswsitch: ovs-vswitch fails to recover after malformed geneve metadata packet
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %openvswitch · openvswitch22 февр. 2024 г.
- CVE-2024-2256330Наблюдать
openvswitch 2.17.8 was discovered to contain a memory leak via the function xmalloc__ in openvswitch-2.17.8/lib/util.c.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %openvswitch · openvswitch19 янв. 2024 г.
- CVE-2017-926326Наблюдать
In Open vSwitch (OvS) 2.7.0, while parsing an OpenFlow role status message, there is a call to the abort() function for undefined role statu
СредняяCVSS 6,5Эксплойта нетEPSS 1 %openvswitch · openvswitch29 мая 2017 г.
- CVE-2022-066926Наблюдать
A flaw was found in dpdk.
СредняяCVSS 6,5Эксплойта нетEPSS 0 %dpdk · data plane development kit29 авг. 2022 г.
- CVE-2019-2507624Наблюдать
The TSS (Tuple Space Search) algorithm in Open vSwitch 2.x through 2.17.2 and 3.0.0 allows remote attackers to cause a denial of service (de
СредняяCVSS 5,8Эксплойта нетEPSS 2 %openvswitch · openvswitch8 сент. 2022 г.
- CVE-2017-1497023Наблюдать
In lib/ofp-util.c in Open vSwitch (OvS) before 2.8.1, there are multiple memory leaks while parsing malformed OpenFlow group mod messages.
СредняяCVSS 5,9Эксплойта нетEPSS 1 %openvswitch · openvswitch1 окт. 2017 г.
- CVE-2021-3698022Наблюдать
Open vSwitch (aka openvswitch) 2.11.0 through 2.15.0 has a use-after-free in decode_NXAST_RAW_ENCAP (called from ofpact_decode and ofpacts_d
СредняяCVSS 5,5Эксплойта нетEPSS 1 %openvswitch · openvswitch20 июл. 2021 г.
- CVE-2023-536622Наблюдать
Openvswitch don't match packets on nd_target field
СредняяCVSS 5,5Эксплойта нетEPSS 0 %openvswitch · openvswitch6 окт. 2023 г.
- CVE-2018-1720620Наблюдать
An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6.
СредняяCVSS 4,9Эксплойта нетEPSS 2 %openvswitch · openvswitch19 сент. 2018 г.
- CVE-2018-1720418Наблюдать
An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6, affecting parse_group_prop_ntr_selection_method in lib/ofp-util.c.
СредняяCVSS 4,3Эксплойта нетEPSS 2 %openvswitch · openvswitch19 сент. 2018 г.
- CVE-2012-344914Наблюдать
Open vSwitch 1.4.2 uses world writable permissions for (1) /var/lib/openvswitch/pki/controllerca/incoming/ and (2) /var/lib/openvswitch/pki/
НизкаяCVSS 3,6Эксплойта нетEPSS 0 %openvswitch · openvswitch7 авг. 2012 г.