CVE Tools

Onosproject

11 CVEs tracked since 2017. Since Jul 2017, none of them reached CISA KEV.

Onosproject CVEs per month

Jul 2017 to Jul 2018. Point at a month, or focus the strip and use the arrow keys.
Onosproject CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2017-0740
2017-0830
2017-09null or fewer
2017-10null or fewer
2017-11null or fewer
2017-12null or fewer
2018-01null or fewer
2018-02null or fewer
2018-03null or fewer
2018-04null or fewer
2018-05null or fewer
2018-06null or fewer
2018-0740

Products

The products that kept showing up in Onosproject's monthly top three, with their CVEs summed over those months.

  1. Onos113 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Onosproject.

  1. CVE-2025-30077Open Networking Foundation SD-RAN ONOS onos-lib-go 0.10.28 allows an index out-of-range panic in asn1/aper GetBitString via a zero value of numBits.6.2
  2. CVE-2024-34050Open Networking Foundation SD-RAN Rimedo rimedo-ts 0.1.1 has a slice bounds out-of-range panic in "return uint64(b[2])<<16 | uint64(b[1])<<8 | uint64(b[0])" in reader.go.7.5
  3. CVE-2024-34049Open Networking Foundation SD-RAN Rimedo rimedo-ts 0.1.1 has a slice bounds out-of-range panic in "return plmnIdString[0:3], plmnIdString[3:]" in reader.go.7.5
  4. CVE-2023-30093A cross-site scripting (XSS) vulnerability in Open Networking Foundation ONOS from version v1.9.0 to v2.7.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected ...6.1
  5. CVE-2019-13624In ONOS 1.15.0, apps/yang/web/src/main/java/org/onosproject/yang/web/YangWebResource.java mishandles backquote characters within strings that can be used in a shell command.9.8
  6. CVE-2018-1000615ONOS ONOS Controller version 1.13.1 and earlier contains a Denial of Service (Service crash) vulnerability in OVSDB component in ONOS that can result in An adversary can remotely crash OVSDB servic...7.5
  7. CVE-2018-1000616ONOS ONOS controller version 1.13.1 and earlier contains a XML External Entity (XXE) vulnerability in onos\drivers\utilities\src\main\java\org\onosproject\drivers\utilities\XmlConfigParser.java loa...9.8
  8. CVE-2018-1000614ONOS ONOS Controller version 1.13.1 and earlier contains a XML External Entity (XXE) vulnerability in providers/netconf/alarm/src/main/java/org/onosproject/provider/netconf/alarm/NetconfAlarmTransl...9.8
  9. CVE-2018-12691Time-of-check to time-of-use (TOCTOU) race condition in org.onosproject.acl (aka the access control application) in ONOS v1.13 and earlier allows attackers to bypass network access control via data...6.8
  10. CVE-2017-13763ONOS versions 1.8.0, 1.9.0, and 1.10.0 do not restrict the amount of memory allocated. The Netty payload size is not limited.7.5
  11. CVE-2017-13762ONOS versions 1.8.0, 1.9.0, and 1.10.0 are vulnerable to XSS.6.1
  12. CVE-2015-7516ONOS before 1.5.0 when using the ifwd app allows remote attackers to cause a denial of service (NULL pointer dereference and switch disconnect) by sending two Ethernet frames with ether_type Jumbo ...7.5
  13. CVE-2017-1000079Linux foundation ONOS 1.9.0 is vulnerable to a DoS.7.5
  14. CVE-2017-1000081Linux foundation ONOS 1.9.0 is vulnerable to unauthenticated upload of applications (.oar) resulting in remote code execution.9.8
  15. CVE-2017-1000078Linux foundation ONOS 1.9 is vulnerable to XSS in the device. registration6.1

The record

Peak rank
#87 in Jul 2017
Busiest month shown
Jul 2017, 4 CVEs
Months with a KEV entry
0 since Jul 2017
Monthly snapshots
3 since 2017
Onosproject's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store