onosproject kayıtları
onosproject üreticisine ait 15 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %6,7
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-611 Improper Restriction of XML External Entity Reference2
- CWE-19 Data Processing Errors1
- CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')1
- CWE-125 Out-of-bounds Read1
- CWE-476 NULL Pointer Dereference1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
15 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2017-1000081İstismar yok | Linux foundation ONOS 1.9.0 is vulnerable to unauthenticated upload of applications (.oar) resulting in remote code execution.onosproject · onos · CWE-434 | Kritik9,8 | — | %3,0 | 17 Tem 2017 |
40Planlayın | CVE-2019-13624İstismar yok | In ONOS 1.15.0, apps/yang/web/src/main/java/org/onosproject/yang/web/YangWebResource.java mishandles backquote characters within strings thaonosproject · onos · CWE-19 | Kritik9,8 | — | %1,9 | 16 Tem 2019 |
39İzleyin | CVE-2018-1000614İstismar yok | ONOS ONOS Controller version 1.13.1 and earlier contains a XML External Entity (XXE) vulnerability in providers/netconf/alarm/src/main/java/onosproject · onos · CWE-611 | Kritik9,8 | — | %1,6 | 9 Tem 2018 |
39İzleyin | CVE-2018-1000616İstismar yok | ONOS ONOS controller version 1.13.1 and earlier contains a XML External Entity (XXE) vulnerability in onos\drivers\utilities\src\main\java\oonosproject · onos · CWE-611 | Kritik9,8 | — | %1,4 | 9 Tem 2018 |
31İzleyin | CVE-2015-7516İstismar yok | ONOS before 1.5.0 when using the ifwd app allows remote attackers to cause a denial of service (NULL pointer dereference and switch disconneonosproject · onos · CWE-476 | Yüksek7,5 | — | %3,7 | 24 Ağu 2017 |
30İzleyin | CVE-2017-1000079İstismar yok | Linux foundation ONOS 1.9.0 is vulnerable to a DoS.onosproject · onos | Yüksek7,5 | — | %1,3 | 17 Tem 2017 |
30İzleyin | CVE-2018-1000615İstismar yok | ONOS ONOS Controller version 1.13.1 and earlier contains a Denial of Service (Service crash) vulnerability in OVSDB component in ONOS that conosproject · onos | Yüksek7,5 | — | %1,2 | 9 Tem 2018 |
30İzleyin | CVE-2017-13763İstismar yok | ONOS versions 1.8.0, 1.9.0, and 1.10.0 do not restrict the amount of memory allocated.onosproject · onos · CWE-770 | Yüksek7,5 | — | %1,1 | 29 Ağu 2017 |
30İzleyin | CVE-2017-1000080İstismar yok | Linux foundation ONOS 1.9.0 allows unauthenticated use of websockets.onosproject · onos | Yüksek7,5 | — | %1,0 | 17 Tem 2017 |
30İzleyin | CVE-2024-34049İstismar yok | Open Networking Foundation SD-RAN Rimedo rimedo-ts 0.1.1 has a slice bounds out-of-range panic in "return plmnIdString[0:3], plmnIdString[3:onosproject · traffic steering xapplication · CWE-125 | Yüksek7,5 | — | %0,5 | 29 Nis 2024 |
30İzleyin | CVE-2024-34050İstismar yok | Open Networking Foundation SD-RAN Rimedo rimedo-ts 0.1.1 has a slice bounds out-of-range panic in "return uint64(b[2])<<16 | uint64(b[1])<<8onosproject · traffic steering xapplication · CWE-129 | Yüksek7,5 | — | %0,5 | 29 Nis 2024 |
27İzleyin | CVE-2018-12691İstismar yok | Time-of-check to time-of-use (TOCTOU) race condition in org.onosproject.acl (aka the access control application) in ONOS v1.13 and earlier aonosproject · onos · CWE-362 | Orta6,8 | — | %0,7 | 5 Tem 2018 |
24İzleyin | CVE-2017-13762İstismar yok | ONOS versions 1.8.0, 1.9.0, and 1.10.0 are vulnerable to XSS.onosproject · onos · CWE-79 | Orta6,1 | — | %1,2 | 29 Ağu 2017 |
24İzleyin | CVE-2017-1000078İstismar yok | Linux foundation ONOS 1.9 is vulnerable to XSS in the device.onosproject · onos · CWE-79 | Orta6,1 | — | %0,7 | 17 Tem 2017 |
24İzleyin | CVE-2023-30093İstismar yok | A cross-site scripting (XSS) vulnerability in Open Networking Foundation ONOS from version v1.9.0 to v2.7.0 allows attackers to execute arbionosproject · onos · CWE-79 | Orta6,1 | — | %0,5 | 4 May 2023 |
- CVE-2017-100008140Planlayın
Linux foundation ONOS 1.9.0 is vulnerable to unauthenticated upload of applications (.oar) resulting in remote code execution.
KritikCVSS 9,8İstismar yokEPSS %3onosproject · onos17 Tem 2017
- CVE-2019-1362440Planlayın
In ONOS 1.15.0, apps/yang/web/src/main/java/org/onosproject/yang/web/YangWebResource.java mishandles backquote characters within strings tha
KritikCVSS 9,8İstismar yokEPSS %2onosproject · onos16 Tem 2019
- CVE-2018-100061439İzleyin
ONOS ONOS Controller version 1.13.1 and earlier contains a XML External Entity (XXE) vulnerability in providers/netconf/alarm/src/main/java/
KritikCVSS 9,8İstismar yokEPSS %2onosproject · onos9 Tem 2018
- CVE-2018-100061639İzleyin
ONOS ONOS controller version 1.13.1 and earlier contains a XML External Entity (XXE) vulnerability in onos\drivers\utilities\src\main\java\o
KritikCVSS 9,8İstismar yokEPSS %1onosproject · onos9 Tem 2018
- CVE-2015-751631İzleyin
ONOS before 1.5.0 when using the ifwd app allows remote attackers to cause a denial of service (NULL pointer dereference and switch disconne
YüksekCVSS 7,5İstismar yokEPSS %4onosproject · onos24 Ağu 2017
- CVE-2017-100007930İzleyin
Linux foundation ONOS 1.9.0 is vulnerable to a DoS.
YüksekCVSS 7,5İstismar yokEPSS %1onosproject · onos17 Tem 2017
- CVE-2018-100061530İzleyin
ONOS ONOS Controller version 1.13.1 and earlier contains a Denial of Service (Service crash) vulnerability in OVSDB component in ONOS that c
YüksekCVSS 7,5İstismar yokEPSS %1onosproject · onos9 Tem 2018
- CVE-2017-1376330İzleyin
ONOS versions 1.8.0, 1.9.0, and 1.10.0 do not restrict the amount of memory allocated.
YüksekCVSS 7,5İstismar yokEPSS %1onosproject · onos29 Ağu 2017
- CVE-2017-100008030İzleyin
Linux foundation ONOS 1.9.0 allows unauthenticated use of websockets.
YüksekCVSS 7,5İstismar yokEPSS %1onosproject · onos17 Tem 2017
- CVE-2024-3404930İzleyin
Open Networking Foundation SD-RAN Rimedo rimedo-ts 0.1.1 has a slice bounds out-of-range panic in "return plmnIdString[0:3], plmnIdString[3:
YüksekCVSS 7,5İstismar yokEPSS %1onosproject · traffic steering xapplication29 Nis 2024
- CVE-2024-3405030İzleyin
Open Networking Foundation SD-RAN Rimedo rimedo-ts 0.1.1 has a slice bounds out-of-range panic in "return uint64(b[2])<<16 | uint64(b[1])<<8
YüksekCVSS 7,5İstismar yokEPSS %1onosproject · traffic steering xapplication29 Nis 2024
- CVE-2018-1269127İzleyin
Time-of-check to time-of-use (TOCTOU) race condition in org.onosproject.acl (aka the access control application) in ONOS v1.13 and earlier a
OrtaCVSS 6,8İstismar yokEPSS %1onosproject · onos5 Tem 2018
- CVE-2017-1376224İzleyin
ONOS versions 1.8.0, 1.9.0, and 1.10.0 are vulnerable to XSS.
OrtaCVSS 6,1İstismar yokEPSS %1onosproject · onos29 Ağu 2017
- CVE-2017-100007824İzleyin
Linux foundation ONOS 1.9 is vulnerable to XSS in the device.
OrtaCVSS 6,1İstismar yokEPSS %1onosproject · onos17 Tem 2017
- CVE-2023-3009324İzleyin
A cross-site scripting (XSS) vulnerability in Open Networking Foundation ONOS from version v1.9.0 to v2.7.0 allows attackers to execute arbi
OrtaCVSS 6,1İstismar yokEPSS %0onosproject · onos4 May 2023