Security Finder

You can use the Security Finder to search for security issues and their impact on Riverbed products. This page is continuously updated, displaying the most current public security issues first. The search box can be used to look up records by specific CVE numbers or relevant search word, e.g. Apache, 8.5.0, Workaround. For additional search tips, refer to article S16165. Security issues listed here are categorized into three groups: fixed, workaround recommended and not applicable.

For general security topics, security best practices and other security related topics, try performing a general search.

BETA FEATURE: This feature is currently under development and is considered Beta Software. We are still enhancing the features and results so please exercise caution when interpreting and implementing the results. If you have any questions, please open a case with Riverbed Support. If you have feedback for this tool, please send it to supportfeedback@riverbed.com.

Riverbed Technology is committed to protecting customers against vulnerabilities in our supported products. Vulnerabilities are addressed in accordance to the software support policy. https://support.riverbed.com/content/support/about_support/end_of_life_policy.html

For search tips, read article S16165.

PreviousNext
TitleLast Modified
Limiting ciphers for the ssh server. 2014-03-12
Changed some kernel parameters to more secure states. 2014-03-12
Malformed packets on port 7850 can cause optimization process to crash when connection forwarding is enabled 2014-03-12
CVE-2010-1321: krb5 invalid GSS-API Denial of Service 2014-03-12
Cumulative Python 2.4 CVE patch 2014-03-12
CVE-2010-1205: libpng pngread buffer overflow. 2014-03-12
CVE-2010-2252: wget crafted filename 3xx redirect 2014-03-12
CVE-2010-0211: OpenLDAP Denial of service using invalid UTF-8 in RDN string 2014-03-12
CVE-2010-0740, CVE-2010-0742: OpenSSL malformed TLS record DoS and CMS OriginatorInfo mishandling 2014-03-12
CVE-2010-0740, CVE-2010-0742: OpenSSL malformed TLS record DoS and CMS OriginatorInfo mishandling 2014-03-12
CVE-2010-0740, CVE-2010-0742: OpenSSL malformed TLS record DoS and CMS OriginatorInfo mishandling 2014-03-12
CVE-2010-3069: Samba crafted SID Denial of Service 2014-03-12
CVE-2010-0405: Bzip2 Denial of service via crafted compressed file. 2014-03-12
CVE-2010-0405: Bzip2 Denial of service via crafted compressed file. 2014-03-12
CVE-2010-4022, CVE-2011-0281, CVE-2011-0282, CVE-2011-0283: Krb5 KDC Denial of Service. 2014-03-12
CVE-2011-0014: OpenSSL OCSP stapling vulnerability 2014-03-12
CVE-2011-0284: krb5 KDC PKINIT Denial of Service using e_data field 2014-03-12
CVE-2011-1024: OpenLDAP external-program authentication bypass 2014-03-12
Remotely-authenticated users mapped onto local RBM accounts have incorrect privileges in the CLI 2014-03-12
Cumulative Apache CVE update 2014-03-12
Cumulative krb5 1.7 CVE update 2014-03-12
CVE-2011-0997: DHCP remote arbitrary command execution via shell metacharacters 2014-03-12
CVE-2010-3081: Linux kernel stack pointer underflow 2014-03-12
CVE-2011-0014: OpenSSL OCSP stapling Vulnerability 2014-03-12
CVE-2011-0014: OpenSSL OCSP stapling vulnerability 2014-03-12
Cumulative kernel CVE update. 2014-03-12
Unauthenticated, stored XSS issues in system logs 2014-03-12
Unauthenticated cross-site scripting (XSS) issue in login page 2014-03-12
Authenticated, stored Cross-site scripting (XSS)issues in web front-end 2014-03-12
Authenticated cross-site scripting (XSS) issues in web front-end 2014-03-12
Decreased SSH login timeout 2014-03-12
Added delay between failed login attempts 2014-03-12
CVE-2011-3192: Apache byterange filter DoS 2014-03-12
CVE-2011-3192: Apache byterange filter Denial of Service 2014-03-12
CVE-2012-2110: OpenSSL asnl buffer overflow remote DoS attack via crafted DER data 2014-03-12
CVE-2012-2333: OpenSSL CBC Integer underflow Denial of Service 2014-03-12
CVE-2012-5166: DNS named daemon could be susceptible to denial of service attack 2014-03-12
CVE-2012-2807: Integer overflows in libxml2 allow remote attackers to cause a denial of service 2014-03-12
CVE-2012-2687, CVE-2012-0883, CVE-2012-3502: Vulnerabilities in Apache modules mod_negotiation, mod_proxy_http and envars 2014-03-12
CVE-2013-0169: SSL, TLS, and DTLS Plaintext Recovery Attack (aka "Lucky 13"). 2014-03-12
PreviousNext