Vulnerability index

Browse CVEs

11 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2018-1132 A flaw was found in Opendaylight's SDNInterfaceapp (SDNI). Attackers can SQL inject the component's database (SQLite) without authenticating to the c… Sdninterfaceapp No fix yet Fix from $2,3002018-06-20 CRITICAL 9.8 CVE-2018-1078 OpenDayLight version Carbon SR3 and earlier contain a vulnerability during node reconciliation that can result in traffic flows that should be expire… Openflow Mitigation only Fix from $2,3002018-03-16 HIGH 7.5 CVE-2017-1000411 OpenFlow Plugin and OpenDayLight Controller versions Nitrogen, Carbon, Boron, Robert Varga, Anil Vishnoi contain a flaw when multiple 'expired' flows… Opendaylight Mitigation only Fix from $1,9502018-01-31 HIGH 7.5 CVE-2017-1000406 OpenDaylight Karaf 0.6.1-Carbon fails to clear the cache after a password change, allowing the old password to be used until the Karaf cache is manua… Karaf Mitigation only Fix from $1,9502017-11-30 HIGH 7.5 CVE-2017-1000357 Denial of Service attack when the switch rejects to receive packets from the controller. Component: This vulnerability affects OpenDaylight odl-l2swi… Opendaylight No fix yet Fix from $1,9502017-04-24 HIGH 7.5 CVE-2017-1000361 DOMRpcImplementationNotAvailableException when sending Port-Status packets to OpenDaylight. Controller launches exceptions and consumes more CPU reso… Opendaylight No fix yet Fix from $1,9502017-04-24 MEDIUM 6.5 CVE-2017-1000358 Controller throws an exception and does not allow user to add subsequent flow for a particular switch. Component: OpenDaylight odl-restconf feature c… Opendaylight No fix yet Fix from $1,6002017-04-24 MEDIUM 5.3 CVE-2017-1000359 Java out of memory error and significant increase in resource consumption. Component: OpenDaylight odl-mdsal-xsql is vulnerable to this flaw. Version… Opendaylight No fix yet Fix from $1,6002017-04-24 MEDIUM 5.3 CVE-2017-1000360 StreamCorruptedException and NullPointerException in OpenDaylight odl-mdsal-xsql. Controller launches exceptions in the console. Component: OpenDayli… Opendaylight No fix yet Fix from $1,6002017-04-24 MEDIUM 5.3 CVE-2015-1610 hosttracker in OpenDaylight l2switch allows remote attackers to change the host location information by spoofing the MAC address, aka "topology spoof… L2switch Mitigation only Fix from $1,6002017-03-20 MEDIUM 6.8 CVE-2014-5035 The Netconf (TCP) service in OpenDaylight 1.0 allows remote attackers to read arbitrary files via an XML external entity declaration in conjunction w… Opendaylight No fix yet Fix from $1,6002014-08-26