VYPR
Vendor

Onosproject

Products
1
CVEs
6
Across products
6
Status
Private

Products

1

Recent CVEs

6
CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2017-1000081Cri0.649.80.08Jul 17, 2017Linux foundation ONOS 1.9.0 is vulnerable to unauthenticated upload of applications (.oar) resulting in remote code execution.
CVE-2017-1000080Hig0.497.50.00Jul 17, 2017Linux foundation ONOS 1.9.0 allows unauthenticated use of websockets.
CVE-2017-1000079Hig0.497.50.00Jul 17, 2017Linux foundation ONOS 1.9.0 is vulnerable to a DoS.
CVE-2017-13763Hig0.427.50.00Aug 30, 2017ONOS versions 1.8.0, 1.9.0, and 1.10.0 do not restrict the amount of memory allocated. The Netty payload size is not limited.
CVE-2017-13762Med0.406.10.01Aug 30, 2017ONOS versions 1.8.0, 1.9.0, and 1.10.0 are vulnerable to XSS.
CVE-2017-1000078Med0.406.10.00Jul 17, 2017Linux foundation ONOS 1.9 is vulnerable to XSS in the device. registration