Show filters
161 Total Results
Displaying 51-60 of 161
Sort by:
Attacker Value
Unknown
CVE-2017-14970
Disclosure Date: October 02, 2017 (last updated November 26, 2024)
In lib/ofp-util.c in Open vSwitch (OvS) before 2.8.1, there are multiple memory leaks while parsing malformed OpenFlow group mod messages. NOTE: the vendor disputes the relevance of this report, stating "it can only be triggered by an OpenFlow controller, but OpenFlow controllers have much more direct and powerful ways to force Open vSwitch to allocate memory, such as by inserting flows into the flow table."
0
Attacker Value
Unknown
CVE-2017-9264
Disclosure Date: May 29, 2017 (last updated November 26, 2024)
In lib/conntrack.c in the firewall implementation in Open vSwitch (OvS) 2.6.1, there is a buffer over-read while parsing malformed TCP, UDP, and IPv6 packets in the functions `extract_l3_ipv6`, `extract_l4_tcp`, and `extract_l4_udp` that can be triggered remotely.
0
Attacker Value
Unknown
CVE-2016-10377
Disclosure Date: May 29, 2017 (last updated November 26, 2024)
In Open vSwitch (OvS) 2.5.0, a malformed IP packet can cause the switch to read past the end of the packet buffer due to an unsigned integer underflow in `lib/flow.c` in the function `miniflow_extract`, permitting remote bypass of the access control list enforced by the switch.
0
Attacker Value
Unknown
CVE-2017-9263
Disclosure Date: May 29, 2017 (last updated November 26, 2024)
In Open vSwitch (OvS) 2.7.0, while parsing an OpenFlow role status message, there is a call to the abort() function for undefined role status reasons in the function `ofp_print_role_status_message` in `lib/ofp-print.c` that may be leveraged toward a remote DoS attack by a malicious switch.
0
Attacker Value
Unknown
CVE-2017-9265
Disclosure Date: May 29, 2017 (last updated November 26, 2024)
In Open vSwitch (OvS) v2.7.0, there is a buffer over-read while parsing the group mod OpenFlow message sent from the controller in `lib/ofp-util.c` in the function `ofputil_pull_ofp15_group_mod`.
0
Attacker Value
Unknown
CVE-2017-9214
Disclosure Date: May 23, 2017 (last updated November 26, 2024)
In Open vSwitch (OvS) 2.7.0, while parsing an OFPT_QUEUE_GET_CONFIG_REPLY type OFP 1.0 message, there is a buffer over-read that is caused by an unsigned integer underflow in the function `ofputil_pull_queue_get_config_reply10` in `lib/ofp-util.c`.
0
Attacker Value
Unknown
CVE-2017-6195
Disclosure Date: May 18, 2017 (last updated November 26, 2024)
Ipswitch MOVEit Transfer (formerly DMZ) allows pre-authentication blind SQL injection. The fixed versions are MOVEit Transfer 2017 9.0.0.201, MOVEit DMZ 8.3.0.30, and MOVEit DMZ 8.2.0.20.
0
Attacker Value
Unknown
CVE-2016-2074
Disclosure Date: July 03, 2016 (last updated November 25, 2024)
Buffer overflow in lib/flow.c in ovs-vswitchd in Open vSwitch 2.2.x and 2.3.x before 2.3.3 and 2.4.x before 2.4.1 allows remote attackers to execute arbitrary code via crafted MPLS packets, as demonstrated by a long string in an ovs-appctl command.
0
Attacker Value
Unknown
CVE-2015-7676
Disclosure Date: April 15, 2016 (last updated November 25, 2024)
Ipswitch MOVEit File Transfer (formerly DMZ) 8.1 and earlier, when configured to support file view on download, allows remote authenticated users to conduct cross-site scripting (XSS) attacks by uploading HTML files.
0
Attacker Value
Unknown
CVE-2015-7678
Disclosure Date: February 10, 2016 (last updated November 25, 2024)
Multiple cross-site request forgery (CSRF) vulnerabilities in Ipswitch MOVEit Mobile 1.2.0.962 and earlier allow remote attackers to hijack the authentication of unspecified victims via unknown vectors.
0