Security Finder

You can use the Security Finder to search for security issues and their impact on Riverbed products. This page is continuously updated, displaying the most current public security issues first. The search box can be used to look up records by specific CVE numbers or relevant search word, e.g. Apache, 8.5.0, Workaround. For additional search tips, refer to article S16165. Security issues listed here are categorized into three groups: fixed, workaround recommended and not applicable.

For general security topics, security best practices and other security related topics, try performing a general search.

BETA FEATURE: This feature is currently under development and is considered Beta Software. We are still enhancing the features and results so please exercise caution when interpreting and implementing the results. If you have any questions, please open a case with Riverbed Support. If you have feedback for this tool, please send it to supportfeedback@riverbed.com.

Riverbed Technology is committed to protecting customers against vulnerabilities in our supported products. Vulnerabilities are addressed in accordance to the software support policy. https://support.riverbed.com/content/support/about_support/end_of_life_policy.html

For search tips, read article S16165.

PreviousNext
TitleLast Modified
OpenSSL cumulative security update for advisory - secadv_20150709 2016-05-05
CVE-2015-4620 - ISC BIND 9.7.x through 9.9.x before 9.9.7-P1 and 9.10.x before 9.10.2-P2, when configured as a recursive resolver with DNSSEC validation, allows remote attackers to cause a denial of service. 2016-05-05
CVE-2015-1819 - The xmlreader in libxml allows remote attackers to cause a denial of service 2016-05-05
CVE-2015-5986 - openpgpkey_61.c in named in ISC BIND 9.9.7 before 9.9.7-P3 allows remote attackers to cause a denial of service CVE-2015-5722 - buffer.c in named in ISC BIND 9.x before 9.9.7-P3 allows remote attackers to cause a denial of service 2016-05-05
CVE-2015-8000: bind denial of service by remote attacker via a malformed class attribute. 2016-05-05
CVE-2015-8704 bind: specific APL data could trigger an INSIST in apl_42.c. 2016-05-05
CVE-2015-8138, CVE-2015-7973, and CVE-2015-7979: NTP security update. 2016-05-05
CVE-2016-0701: OpenSSL 1.0.2 through 1.0.2e is vulnerable to DH small subgroups 2016-05-05
Multiple DoS vulnerabilities in various tcpdump packet printers. 2016-01-25
Enhanced security for telemetry connections 2015-10-02
CVE-2015-5477: BIND TKEY query handling flaw leading to denial of service 2015-09-21
NTP: DoS and authentication bypass in symmetric key crypto 2015-09-04
CVE-2015-1782: libssh2 remote DoS via crafted SSH_MSG_KEXINIT packet 2015-09-03
SQLite: Multiple overflow and memory corruption errors 2015-09-01
CVE-2014-6272 libevent: Multiple integer overflow flaws were found in the evbuffer API of Libevent. 2015-08-28
CVE-2014-8500 BIND library: Delegation handling denial of service attack. 2015-08-28
CVE-2015-1349: BIND trust anchor management remote DoS. 2015-08-28
Security update for the glibc functions getaddrinfo() and gethostbyname_r(). 2015-08-27
CVE-2014-8150 Libcurl: HTTP response splitting attacks via a CRLF injection vulnerability. 2015-08-27
Unzip utility: Multiple buffer overflows and out-of-bounds vulnerabilities. 2015-08-27
CVE-2014-9293, CVE-2014-9294, CVE-2014-9295, CVE-2014-9296: NTP: Network Time Protocol cumulative security update RHSA-2014:2024-1 2015-08-27
CVE-2014-8767, CVE-2014-8769, CVE-2014-9140. Tcpdump: Multiple denial of service attacks caused by malformed PPP, AODV & OLSR packets. 2015-08-27
CVE-2014-0591: BIND DoS with Crafted Query against an NSEC3-signed Zone 2015-08-27
CVE-2014-4877: Wget FTP symbolic link, arbitrary file system access. 2015-08-27
CVE-2013-0169 - OpenSSL: SSL, TLS and DTLS Plaintext Recovery Attack ("Lucky 13") 2015-08-14
CVE-2012-4929 and CVE-2012-4930 - general HTTPS: enabling compression may result in information disclosure ("CRIME attack") 2015-08-13
Improved Cross-Site Request Forgery (CSRF) prevention using CSRF tokens 2015-08-10
CVE-2013-4496: Samba insufficient password-guessing protection allows brute-force ChangePasswordUser2 2015-08-07
CVE-2015-0240: Samba remote code execution due to uninitialized stack pointer. 2015-08-07
CVE-2014-0160: The TLS implementations in OpenSSL do not properly handle Heartbeat packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, aka the Heartbleed bug. 2015-08-06
CVE-2014-3616 nginx: Virtual host confusion attacks 2015-07-30
CVE-2014-7145 Linux Kernel: CIFS NULL pointer dereference in SMB2_tcon 2015-07-29
AutoComplete attribute not disabled for password in Form based authentication 2015-07-29
Vulnerabilities in Linux kernel SCTP module 2015-07-29
CVE-2006-0300: Tar Invalid Headers Buffer Overflow Vulnerability 2015-07-29
CVE-2013-0166: OpenSSL DoS due to improper handling of OCSP response verification 2015-07-29
CVE-2012-2686 OpenSSL DoS due to improper handling of CBC ciphersuites in TLS 1.1/1.2 on AES-NI supported platforms 2015-07-29
CVE-2015-5352: OpenSSH: XSECURITY restrictions bypass under certain conditions in ssh(1) 2015-07-29
CVE-2014-6271, CVE-2014-7169: "ShellShock" - Bash Code Injection Vulnerability via Specially Crafted Environment Variables 2015-07-09
CVE-2014-3660: libxml2 denial of service via recursive entity expansion 2015-07-08
PreviousNext