Security Finder

You can use the Security Finder to search for security issues and their impact on Riverbed products. This page is continuously updated, displaying the most current public security issues first. The search box can be used to look up records by specific CVE numbers or relevant search word, e.g. Apache, 8.5.0, Workaround. For additional search tips, refer to article S16165. Security issues listed here are categorized into three groups: fixed, workaround recommended and not applicable.

For general security topics, security best practices and other security related topics, try performing a general search.

BETA FEATURE: This feature is currently under development and is considered Beta Software. We are still enhancing the features and results so please exercise caution when interpreting and implementing the results. If you have any questions, please open a case with Riverbed Support. If you have feedback for this tool, please send it to supportfeedback@riverbed.com.

Riverbed Technology is committed to protecting customers against vulnerabilities in our supported products. Vulnerabilities are addressed in accordance to the software support policy. https://support.riverbed.com/content/support/about_support/end_of_life_policy.html

For search tips, read article S16165.

PreviousNext
TitleLast Modified
Cumulative update for OpenSSL security advisory - secadv_20141015 (includes "Poodle" attack) 2015-07-08
CVE-2014-0224: OpenSSL weak keying MITM vulnerability 2015-06-29
CVE-2014-3535: Linux kernel VxLAN NULL pointer dereference flaw. 2015-06-29
CVE-2015-0235 - The glibc gethostbyname buffer overflow (GHOST vulnerability). A heap-based buffer overflow was found in the glibc __nss_hostname_digits_dots() function that is used by the gethostbyname() and gethostbyname2() glibc function calls. 2015-06-29
CVE-2014-5119, CVE-2014-0475: Context-dependent vulnerabilities in GLibc Locale components 2015-06-12
Kerberos(Krb5) cumulative security update 2015-06-12
CVE-2009-0590, CVE-2009-0591, CVE-2009-0789: OpenSSL: Signature repudiation and ASN.1 denial of service vulnerabilies 2015-06-12
CVE-2013-4387: IPv6 small packet UDP Fragmentation Offload (UFO) processing Denial of Service (DoS) vulnerability 2015-06-12
CVE-2013-6438: Apache Httpd mod_dav denial of service via crafted DAV WRITE request 2015-06-12
CVE-2014-3634, CVE-2014-3683: Remote syslog PRI vulnerability 2015-06-12
CVE-2014-7187: Bash off-by-one error arbitrary code execution 2015-06-12
CVE-2014-3613: cURL remote arbitrary cookie due to incorrect handling of cookie domain IP addresses 2015-06-12
CVE-2014-3620: Libcurl cookie leak for TLDs 2015-06-12
Cookie Does Not Contain The "secure" Attribute for user session management when using HTTP 2015-06-12
CVE-2014-3560: Samba NetBIOS message block daemon (nmbd) heap-based buffer overflow flaw 2015-06-12
CVE-2013-5704: Apache Httpd bypass of mod_headers rules via chunked requests 2015-06-12
CVE-2014-2532: OpenSSH AcceptEnv environment restriction bypass flaw 2015-06-12
CVE-2014-2523: Linux kernel: DCCP remote denial of service 2015-06-12
CVE-2014-0100: Linux kernel ICMP echo remote Denial of Service 2015-06-12
CVE-2014-2039 Linux Kernel: Crash (DoS) due to improper linkage stack instructions 2015-06-12
CVE-2014-1690: Linux Kernel netfilter information leak using remote IRC DCC session 2015-06-12
CVE-2012-6151: NET-SNMP snmpd AgentX subagent time-out Denial of service 2015-06-12
CVE-2013-4365 mod_fcgid: heap overflow 2015-06-12
CVE-2007-2768: OpenSSH OPIE remote account enumeration 2015-06-12
CVE-2004-1653: OpenSSH AllowTcpForwarding Port Bouncing 2015-06-12
CVE-2007-2243: OpenSSH S/KEY Authentication Account Enumeration 2015-06-12
SSL Certificate Domain Name Mismatch with scanner 2015-06-12
CVE-2009-2813, CVE-2009-2906, CVE-2009-2948: Samba Credentialed Vulnerabilities 2015-06-12
CVE-2008-3496: Linux kernel uvcvideo buffer overflow in format descriptor parsing 2015-06-12
CVE-2005-3623: Linux Kernel NFS ACL Access Control Bypass Vulnerability 2015-06-12
CVE-2008-3526, CVE-2008-3276: Linux Kernel Integer Overflow in setsockopt of SCTP and DCCP protocols 2015-06-12
CVE-2008-5134: Linux kernel libertas invalid beacon/probe response buffer overrun 2015-06-12
CVE-2014-2653: OpenSSH remote servers skipping SSHFP DNS RR checking 2015-06-08
CVE-2014-1912: Denial of Serivce vulnerability in Python sockets due to boundary check errors in sock_recvfrom_into 2015-06-08
CVE-2014-0092: GnuTLS Certificate Validation Security Bypass Vulnerability 2015-06-08
CVE-2014-0098: Apache httpd mod_log_config crafted log cookie denial of service 2015-06-08
Apache 2.2 and 2.4 Denial of Service Security updates 2015-06-08
CVE-2014-0198: OpenSSL do_ssl3_write with SSL_MODE_RELEASE_BUFFERS denial of service via alerts 2015-06-04
CVE-2014-0191, CVE-2013-2877: Libxml2 security update RHSA-2014:0513-1 2015-06-04
CVE-2014-0224: OpenSSL weak keying MITM vulnerability 2015-06-04
PreviousNext