Security Finder

You can use the Security Finder to search for security issues and their impact on Riverbed products. This page is continuously updated, displaying the most current public security issues first. The search box can be used to look up records by specific CVE numbers or relevant search word, e.g. Apache, 8.5.0, Workaround. For additional search tips, refer to article S16165. Security issues listed here are categorized into three groups: fixed, workaround recommended and not applicable.

For general security topics, security best practices and other security related topics, try performing a general search.

BETA FEATURE: This feature is currently under development and is considered Beta Software. We are still enhancing the features and results so please exercise caution when interpreting and implementing the results. If you have any questions, please open a case with Riverbed Support. If you have feedback for this tool, please send it to supportfeedback@riverbed.com.

Riverbed Technology is committed to protecting customers against vulnerabilities in our supported products. Vulnerabilities are addressed in accordance to the software support policy. https://support.riverbed.com/content/support/about_support/end_of_life_policy.html

For search tips, read article S16165.

PreviousNext
TitleLast Modified
CVE-2012-4929: SSL/TLS CRIME attack against HTTPS 2015-02-25
CVE-2011-1071: glibc: Stack extension attack 2015-02-25
CVE-2011-0997: Insufficient sanitization of certain DHCP response values 2015-02-25
CVE-2008-1372 bzip2: crash on malformed archive file 2015-02-25
CVE-2006-4980: Python repr unicode buffer overflow 2015-02-25
CVE-2013-5211: NTPd monlist Denial of Service 2015-02-25
OpenSSL CRL validation bypass and ECDH Denial of Service 2015-02-25
CVE-2013-2566: SSL/TLS use of weak RC4 cipher 2015-02-11
CVE-2014-2532: OpenSSH AcceptEnv Security Bypass 2015-02-06
NTP multiple security vulnerabilities (CVE-2014-9293, CVE-2014-9294, CVE-2014-9295, CVE-2014-9296) 2015-02-06
File: Multiple denial of service (DoS) vulnerabilities (CVE-2014-8116, CVE-2014-8117) 2015-02-06
CVE-2014-8109 Apache httpd: LuaAuthzProvider argument handling issue 2015-02-06
CVE-2014-8151 libcurl: Certificate check bypass when built with DarwinSSL as TLS backend 2015-02-06
krb5: Vulnerabilities in the MIT Kerberos 5 (aka krb5) kadmind component 2015-02-06
CVE-2014-8730 TLS: Incorrect check of padding bytes when using CBC cipher suites (Poodle variant) 2015-02-06
CVE-2014-9112 GNU Cpio: heap-based buffer overflow flaw in list_file() 2015-02-06
CVE-2014-7817 glibc: command execution in wordexp() with WRDE_NOCMD specified 2015-02-06
CVE-2014-3707 Libcurl: Sensitive information disclosure due to incorrect handle duplication 2015-02-06
CVE-2014-3581 Apache httpd: NULL pointer dereference in mod_cache if Content-Type has empty value 2015-02-06
CVE-2014-8132 libssh: Remote DoS with crafted kexinit packet 2015-02-06
CVE-2013-2099 Python: ssl.match_hostname() DoS via certificates with specially crafted hostname wildcard patterns 2015-02-06
CVE-2014-3565 net-snmp: snmptrapd Denial of Service via crafted SNMP trap message 2015-02-06
Cumulative update for OpenSSL security advisory - secadv_20141015 (includes "Poodle" attack) 2015-02-04
CVE-2014-1692: OpenSSH J-PAKE error condition denial of service 2014-12-31
CVE-2009-4537: Linux Kernel RTL8169 frame size DoS 2014-12-31
CVE-2013-4353, CVE-2013-6449, CVE-2013-6450: Openssl cumulative security update 2014-08-12
CVE-2009-1633: kernel CIFS denial of service using malformed unicode characters 2014-08-11
CVE-2012-6638: Linux Kernel tcp_rcv_state_process SYN+FIN remote DoS 2014-08-01
CVE-2010-5107: OpenSSHv6.1 fixed time limit connection slot exhaustion DoS 2014-07-15
CVE-2013-1775: sudo authentication bypass via system clock and user timestamp reset 2014-07-15
CVE-2013-2249: Apache HTTP mod_session_dbd module unsafe save operations 2014-07-15
CVE-2013-4545: cURL man in the middle certificate spoofing 2014-05-29
CVE-2013-6449: OpenSSL ssl_get_algorithm2 version number remote DoS using TLS 1.2 client 2014-05-29
CVE-2013-4353, CVE-2013-6449, CVE-2013-6450: Openssl cumulative security update 2014-05-29
Image fetch log message displays account information in the syslog entry. 2014-05-29
CVE-2013-1944: cURL cookie stealing vulnerability in tailmatch 2014-04-29
"web ssl cert generate key-size" does not prevent specifying unusable key sizes that cause the web server to fail. 2014-04-29
Riverbed customer support diagnostic access improvements 2014-04-17
CVE-2013-1950: libtirpc rpcbind remote denial of service 2014-04-17
CVE-2013-4238: Python ssl.match_hostname man in the middle arbitrary server certificate spoof attack 2014-04-17
PreviousNext