Security Finder

You can use the Security Finder to search for security issues and their impact on Riverbed products. This page is continuously updated, displaying the most current public security issues first. The search box can be used to look up records by specific CVE numbers or relevant search word, e.g. Apache, 8.5.0, Workaround. For additional search tips, refer to article S16165. Security issues listed here are categorized into three groups: fixed, workaround recommended and not applicable.

For general security topics, security best practices and other security related topics, try performing a general search.

BETA FEATURE: This feature is currently under development and is considered Beta Software. We are still enhancing the features and results so please exercise caution when interpreting and implementing the results. If you have any questions, please open a case with Riverbed Support. If you have feedback for this tool, please send it to supportfeedback@riverbed.com.

Riverbed Technology is committed to protecting customers against vulnerabilities in our supported products. Vulnerabilities are addressed in accordance to the software support policy. https://support.riverbed.com/content/support/about_support/end_of_life_policy.html

For search tips, read article S16165.

PreviousNext
TitleLast Modified
OpenSSL cumulative update for security advisory secadv_20140806 2015-06-04
Removed DigiNotar CA from our default CA list. 2015-05-21
glibc cumulative security update 2015-05-14
CVE-2011-3048: Libpng heap buffer overflow remote DoS 2015-05-14
CVE-2013-1944: tailMatch function in cURL and libcurl allows remote attackers to steal cookies 2015-05-14
CVE-2011-3188: IPv4/IPv6 in Linux kernel use MD4 sequence numbers and Fragment Identification values that assists remote DoS 2015-05-14
CVE-2012-0053 - Apache: error responses can expose cookies 2015-05-14
CVE-2013-0166 - OpenSSL: OCSP invalid key DoS issueCVE-2013-0169 - OpenSSL: SSL, TLS and DTLS Plaintext Recovery Attack ("Lucky 13") 2015-05-14
CVE-2011-3389: HTTPS block-wise chosen-plaintext attack against SSL/TLS ("BEAST" attack) 2015-05-13
CVE-2011-3389 - general HTTPS: block-wise chosen-plaintext attack against SSL/TLS ("BEAST" attack) 2015-05-13
CVE-2011-3192: Apache HTTP server Byterange filter Denial of Service 2015-05-13
CVE-2010-4478 - OpenSSH: J-PAKE authentication bypass. CVE-2012-0814 - OpenSSH: Forced command handling leaks private information to clients 2015-05-13
CVE-2009-1265: Linux Kernel sendmsg Integer overflow 2015-05-12
CVE-2009-068: Cyrus-sasl sasl_encode64() does not reliably null-terminate its output 2015-05-12
CVE-2008-1673: Linux kernel Possible buffer overflow in ASN.1 parsing routines 2015-05-12
CVE-2009-1888: Samba improper file access 2015-05-12
CVE-2007-6199: Rsync remote access to restricted files via out of module symlinks 2015-05-12
OpenSSH v1 vulnerabilities detected reported by security scanners 2015-05-12
CVE-2014-9278 OpenSSH: .k5users unexpectedly grants remote login 2015-05-12
Vulnerabilities in Apache ActiveMQ 2015-05-12
CVE-2014-9402 Glibc: Denial of service in getnetbyname function 2015-05-12
CVE-2015-1465 Linux kernel: DoS due to routing packets to too many different destinations too fast 2015-05-12
CVE-2014-0160: OpenSSL heartbeat extension sensitive information disclosure. (a.k.a. "Heartbleed" bug) 2015-05-12
Uploads of large files to HTTPS server hangs. 2015-05-12
CVE-2014-5119, CVE-2014-0475: Context-dependent vulnerabilities in GLibc Locale components 2015-04-28
CVE-2002-0510: UDP Constant IP Identification Field Fingerprinting Vulnerability 2015-04-20
The continuous logging page could cause the Web UI to hang. 2015-03-24
Postgresql: Multiple buffer overflows and information disclosure 2015-03-11
CVE-1999-0502: Default or blank password for user account 2015-03-04
Web Server Uses Plain-Text Form Based Authentication 2015-03-04
Bad or weak SSL/TLS certificate configurations 2015-03-04
SSH CBC Mode Plaintext Recovery - Remote 2015-03-04
SSL/TLS weak cipher strength supported 2015-03-04
CVE-2007-6750: Apache httpd Slowloris denial of service 2015-03-04
SNMP default or guessable community name 2015-03-04
CVE-2011-0719: Samba remote DoS using unsafe fd_set 2015-03-04
False web application XSS vulnerabilities 2015-03-04
CVE-2010-0309: Linux kvm /dev/port read denial of service 2015-03-04
CVE-2010-1633: OpenSSL information leak due to invalid Return value check 2015-02-25
CVE-2009-3555: TLS MITM attacks via session renegotiation 2015-02-25
PreviousNext