openvswitch kayıtları
openvswitch üreticisine ait 22 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %95,5
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-125 Out-of-bounds Read5
- CWE-400 Uncontrolled Resource Consumption3
- CWE-401 Missing Release of Memory after Effective Lifetime2
- CWE-617 Reachable Assertion2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-345 Insufficient Verification of Data Authenticity1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
22 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2016-2074İstismar yok | Buffer overflow in lib/flow.c in ovs-vswitchd in Open vSwitch 2.2.x and 2.3.x before 2.3.3 and 2.4.x before 2.4.1 allows remote attackers toopenvswitch · openvswitch · CWE-119 | Kritik9,8 | — | %6,4 | 3 Tem 2016 |
40Planlayın | CVE-2017-9214İstismar yok | In Open vSwitch (OvS) 2.7.0, while parsing an OFPT_QUEUE_GET_CONFIG_REPLY type OFP 1.0 message, there is a buffer over-read that is caused bopenvswitch · openvswitch · CWE-191 | Kritik9,8 | — | %2,9 | 23 May 2017 |
40Planlayın | CVE-2017-9265İstismar yok | In Open vSwitch (OvS) v2.7.0, there is a buffer over-read while parsing the group mod OpenFlow message sent from the controller in `lib/ofp-openvswitch · openvswitch · CWE-125 | Kritik9,8 | — | %2,8 | 29 May 2017 |
40Planlayın | CVE-2017-9264İstismar yok | In lib/conntrack.c in the firewall implementation in Open vSwitch (OvS) 2.6.1, there is a buffer over-read while parsing malformed TCP, UDP,openvswitch · openvswitch · CWE-125 | Kritik9,8 | — | %2,4 | 29 May 2017 |
39İzleyin | CVE-2022-4338İstismar yok | An integer underflow in Organization Specific TLV was found in various versions of OpenvSwitch.openvswitch · openvswitch · CWE-125 | Kritik9,8 | — | %1,3 | 10 Oca 2023 |
39İzleyin | CVE-2022-4337İstismar yok | An out-of-bounds read in Organization Specific TLV was found in various versions of OpenvSwitch.openvswitch · openvswitch · CWE-125 | Kritik9,8 | — | %1,3 | 10 Oca 2023 |
35İzleyin | CVE-2016-10377İstismar yok | In Open vSwitch (OvS) 2.5.0, a malformed IP packet can cause the switch to read past the end of the packet buffer due to an unsigned integeropenvswitch · openvswitch · CWE-119 | Yüksek8,8 | — | %0,9 | 29 May 2017 |
32İzleyin | CVE-2020-35498Kavram kanıtı | A vulnerability was found in openvswitch.openvswitch · openvswitch · CWE-400 | Yüksek7,5 | — | %8,0 | 11 Şub 2021 |
31İzleyin | CVE-2020-27827İstismar yok | A flaw was found in multiple versions of OpenvSwitch.openvswitch · openvswitch · CWE-400 | Yüksek7,5 | — | %3,2 | 18 Mar 2021 |
31İzleyin | CVE-2018-17205İstismar yok | An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6, affecting ofproto_rule_insert__ in ofproto/ofproto.c.openvswitch · openvswitch · CWE-617 | Yüksek7,5 | — | %2,5 | 19 Eyl 2018 |
31İzleyin | CVE-2021-3905İstismar yok | A memory leak was found in Open vSwitch (OVS) during userspace IP fragmentation processing.openvswitch · openvswitch · CWE-401 | Yüksek7,5 | — | %2,0 | 23 Ağu 2022 |
30İzleyin | CVE-2023-3966İstismar yok | Openvswsitch: ovs-vswitch fails to recover after malformed geneve metadata packetopenvswitch · openvswitch · CWE-248 | Yüksek7,5 | — | %1,0 | 22 Şub 2024 |
30İzleyin | CVE-2024-22563İstismar yok | openvswitch 2.17.8 was discovered to contain a memory leak via the function xmalloc__ in openvswitch-2.17.8/lib/util.c.openvswitch · openvswitch · CWE-401 | Yüksek7,5 | — | %0,6 | 19 Oca 2024 |
26İzleyin | CVE-2017-9263İstismar yok | In Open vSwitch (OvS) 2.7.0, while parsing an OpenFlow role status message, there is a call to the abort() function for undefined role statuopenvswitch · openvswitch · CWE-20 | Orta6,5 | — | %1,0 | 29 May 2017 |
26İzleyin | CVE-2022-0669İstismar yok | A flaw was found in dpdk.dpdk · data plane development kit · CWE-400 | Orta6,5 | — | %0,3 | 29 Ağu 2022 |
24İzleyin | CVE-2019-25076İstismar yok | The TSS (Tuple Space Search) algorithm in Open vSwitch 2.x through 2.17.2 and 3.0.0 allows remote attackers to cause a denial of service (deopenvswitch · openvswitch | Orta5,8 | — | %2,3 | 8 Eyl 2022 |
23İzleyin | CVE-2017-14970İstismar yok | In lib/ofp-util.c in Open vSwitch (OvS) before 2.8.1, there are multiple memory leaks while parsing malformed OpenFlow group mod messages.openvswitch · openvswitch · CWE-772 | Orta5,9 | — | %1,2 | 1 Eki 2017 |
22İzleyin | CVE-2021-36980İstismar yok | Open vSwitch (aka openvswitch) 2.11.0 through 2.15.0 has a use-after-free in decode_NXAST_RAW_ENCAP (called from ofpact_decode and ofpacts_dopenvswitch · openvswitch · CWE-416 | Orta5,5 | — | %1,2 | 20 Tem 2021 |
22İzleyin | CVE-2023-5366İstismar yok | Openvswitch don't match packets on nd_target fieldopenvswitch · openvswitch · CWE-345 | Orta5,5 | — | %0,4 | 6 Eki 2023 |
20İzleyin | CVE-2018-17206İstismar yok | An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6.openvswitch · openvswitch · CWE-125 | Orta4,9 | — | %2,0 | 19 Eyl 2018 |
18İzleyin | CVE-2018-17204İstismar yok | An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6, affecting parse_group_prop_ntr_selection_method in lib/ofp-util.c.openvswitch · openvswitch · CWE-617 | Orta4,3 | — | %1,9 | 19 Eyl 2018 |
14İzleyin | CVE-2012-3449İstismar yok | Open vSwitch 1.4.2 uses world writable permissions for (1) /var/lib/openvswitch/pki/controllerca/incoming/ and (2) /var/lib/openvswitch/pki/openvswitch · openvswitch · CWE-264 | Düşük3,6 | — | %0,3 | 7 Ağu 2012 |
- CVE-2016-207441Planlayın
Buffer overflow in lib/flow.c in ovs-vswitchd in Open vSwitch 2.2.x and 2.3.x before 2.3.3 and 2.4.x before 2.4.1 allows remote attackers to
KritikCVSS 9,8İstismar yokEPSS %6openvswitch · openvswitch3 Tem 2016
- CVE-2017-921440Planlayın
In Open vSwitch (OvS) 2.7.0, while parsing an OFPT_QUEUE_GET_CONFIG_REPLY type OFP 1.0 message, there is a buffer over-read that is caused b
KritikCVSS 9,8İstismar yokEPSS %3openvswitch · openvswitch23 May 2017
- CVE-2017-926540Planlayın
In Open vSwitch (OvS) v2.7.0, there is a buffer over-read while parsing the group mod OpenFlow message sent from the controller in `lib/ofp-
KritikCVSS 9,8İstismar yokEPSS %3openvswitch · openvswitch29 May 2017
- CVE-2017-926440Planlayın
In lib/conntrack.c in the firewall implementation in Open vSwitch (OvS) 2.6.1, there is a buffer over-read while parsing malformed TCP, UDP,
KritikCVSS 9,8İstismar yokEPSS %2openvswitch · openvswitch29 May 2017
- CVE-2022-433839İzleyin
An integer underflow in Organization Specific TLV was found in various versions of OpenvSwitch.
KritikCVSS 9,8İstismar yokEPSS %1openvswitch · openvswitch10 Oca 2023
- CVE-2022-433739İzleyin
An out-of-bounds read in Organization Specific TLV was found in various versions of OpenvSwitch.
KritikCVSS 9,8İstismar yokEPSS %1openvswitch · openvswitch10 Oca 2023
- CVE-2016-1037735İzleyin
In Open vSwitch (OvS) 2.5.0, a malformed IP packet can cause the switch to read past the end of the packet buffer due to an unsigned integer
YüksekCVSS 8,8İstismar yokEPSS %1openvswitch · openvswitch29 May 2017
- CVE-2020-3549832İzleyin
A vulnerability was found in openvswitch.
YüksekCVSS 7,5Kavram kanıtıEPSS %8openvswitch · openvswitch11 Şub 2021
- CVE-2020-2782731İzleyin
A flaw was found in multiple versions of OpenvSwitch.
YüksekCVSS 7,5İstismar yokEPSS %3openvswitch · openvswitch18 Mar 2021
- CVE-2018-1720531İzleyin
An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6, affecting ofproto_rule_insert__ in ofproto/ofproto.c.
YüksekCVSS 7,5İstismar yokEPSS %3openvswitch · openvswitch19 Eyl 2018
- CVE-2021-390531İzleyin
A memory leak was found in Open vSwitch (OVS) during userspace IP fragmentation processing.
YüksekCVSS 7,5İstismar yokEPSS %2openvswitch · openvswitch23 Ağu 2022
- CVE-2023-396630İzleyin
Openvswsitch: ovs-vswitch fails to recover after malformed geneve metadata packet
YüksekCVSS 7,5İstismar yokEPSS %1openvswitch · openvswitch22 Şub 2024
- CVE-2024-2256330İzleyin
openvswitch 2.17.8 was discovered to contain a memory leak via the function xmalloc__ in openvswitch-2.17.8/lib/util.c.
YüksekCVSS 7,5İstismar yokEPSS %1openvswitch · openvswitch19 Oca 2024
- CVE-2017-926326İzleyin
In Open vSwitch (OvS) 2.7.0, while parsing an OpenFlow role status message, there is a call to the abort() function for undefined role statu
OrtaCVSS 6,5İstismar yokEPSS %1openvswitch · openvswitch29 May 2017
- CVE-2022-066926İzleyin
A flaw was found in dpdk.
OrtaCVSS 6,5İstismar yokEPSS %0dpdk · data plane development kit29 Ağu 2022
- CVE-2019-2507624İzleyin
The TSS (Tuple Space Search) algorithm in Open vSwitch 2.x through 2.17.2 and 3.0.0 allows remote attackers to cause a denial of service (de
OrtaCVSS 5,8İstismar yokEPSS %2openvswitch · openvswitch8 Eyl 2022
- CVE-2017-1497023İzleyin
In lib/ofp-util.c in Open vSwitch (OvS) before 2.8.1, there are multiple memory leaks while parsing malformed OpenFlow group mod messages.
OrtaCVSS 5,9İstismar yokEPSS %1openvswitch · openvswitch1 Eki 2017
- CVE-2021-3698022İzleyin
Open vSwitch (aka openvswitch) 2.11.0 through 2.15.0 has a use-after-free in decode_NXAST_RAW_ENCAP (called from ofpact_decode and ofpacts_d
OrtaCVSS 5,5İstismar yokEPSS %1openvswitch · openvswitch20 Tem 2021
- CVE-2023-536622İzleyin
Openvswitch don't match packets on nd_target field
OrtaCVSS 5,5İstismar yokEPSS %0openvswitch · openvswitch6 Eki 2023
- CVE-2018-1720620İzleyin
An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6.
OrtaCVSS 4,9İstismar yokEPSS %2openvswitch · openvswitch19 Eyl 2018
- CVE-2018-1720418İzleyin
An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6, affecting parse_group_prop_ntr_selection_method in lib/ofp-util.c.
OrtaCVSS 4,3İstismar yokEPSS %2openvswitch · openvswitch19 Eyl 2018
- CVE-2012-344914İzleyin
Open vSwitch 1.4.2 uses world writable permissions for (1) /var/lib/openvswitch/pki/controllerca/incoming/ and (2) /var/lib/openvswitch/pki/
DüşükCVSS 3,6İstismar yokEPSS %0openvswitch · openvswitch7 Ağu 2012