Vulnerability index

Browse CVEs

15 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Traffic Steering Xapplication HIGH 7.5
CVE-2024-34049

Open Networking Foundation SD-RAN Rimedo rimedo-ts 0.1.1 has a slice bounds out-of-range panic in "return plmnIdString[0:3], plmnIdString[3:]" in rea…

No fix yet
Fix from $1,950 2024-04-30
Traffic Steering Xapplication HIGH 7.5
CVE-2024-34050

Open Networking Foundation SD-RAN Rimedo rimedo-ts 0.1.1 has a slice bounds out-of-range panic in "return uint64(b[2])<<16 | uint64(b[1])<<8 | uint64…

No fix yet
Fix from $1,950 2024-04-30
Onos MEDIUM 6.1
CVE-2023-30093

A cross-site scripting (XSS) vulnerability in Open Networking Foundation ONOS from version v1.9.0 to v2.7.0 allows attackers to execute arbitrary web…

Fix: after 2.7.0
Fix from $1,600 2023-05-04
Onos CRITICAL 9.8
CVE-2019-13624

In ONOS 1.15.0, apps/yang/web/src/main/java/org/onosproject/yang/web/YangWebResource.java mishandles backquote characters within strings that can be …

Patch available
Fix from $2,300 2019-07-17
Onos CRITICAL 9.8
CVE-2018-1000614

ONOS ONOS Controller version 1.13.1 and earlier contains a XML External Entity (XXE) vulnerability in providers/netconf/alarm/src/main/java/org/onosp…

Fix: after 1.13.1
Fix from $2,300 2018-07-09
Onos CRITICAL 9.8
CVE-2018-1000616

ONOS ONOS controller version 1.13.1 and earlier contains a XML External Entity (XXE) vulnerability in onos\drivers\utilities\src\main\java\org\onospr…

Fix: after 1.13.1
Fix from $2,300 2018-07-09
Onos HIGH 7.5
CVE-2018-1000615

ONOS ONOS Controller version 1.13.1 and earlier contains a Denial of Service (Service crash) vulnerability in OVSDB component in ONOS that can result…

Fix: after 1.13.1
Fix from $1,950 2018-07-09
Onos MEDIUM 6.8
CVE-2018-12691

Time-of-check to time-of-use (TOCTOU) race condition in org.onosproject.acl (aka the access control application) in ONOS v1.13 and earlier allows att…

Fix: after 1.13.0
Fix from $1,600 2018-07-05
Onos HIGH 7.5
CVE-2017-13763

ONOS versions 1.8.0, 1.9.0, and 1.10.0 do not restrict the amount of memory allocated. The Netty payload size is not limited.

Mitigation only
Fix from $1,950 2017-08-30
Onos MEDIUM 6.1
CVE-2017-13762

ONOS versions 1.8.0, 1.9.0, and 1.10.0 are vulnerable to XSS.

No fix yet
Fix from $1,600 2017-08-30
Onos HIGH 7.5
CVE-2015-7516

ONOS before 1.5.0 when using the ifwd app allows remote attackers to cause a denial of service (NULL pointer dereference and switch disconnect) by se…

Fix: after 1.4.0
Fix from $1,950 2017-08-24
Onos CRITICAL 9.8
CVE-2017-1000081

Linux foundation ONOS 1.9.0 is vulnerable to unauthenticated upload of applications (.oar) resulting in remote code execution.

Mitigation only
Fix from $2,300 2017-07-17
Onos HIGH 7.5
CVE-2017-1000079

Linux foundation ONOS 1.9.0 is vulnerable to a DoS.

No fix yet
Fix from $1,950 2017-07-17
Onos HIGH 7.5
CVE-2017-1000080

Linux foundation ONOS 1.9.0 allows unauthenticated use of websockets.

Mitigation only
Fix from $1,950 2017-07-17
Onos MEDIUM 6.1
CVE-2017-1000078

Linux foundation ONOS 1.9 is vulnerable to XSS in the device. registration

Mitigation only
Fix from $1,600 2017-07-17