Arista
arista
103 CVEs • 324 products
Products (324)
Click to collapseToggle
Products (324)
Click to collapse
CVEs (103)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
7Arista CanonicalFedoraproject+4 more11Enterprise Linux EosFedora+8 moreNov 21, 2024 Jan 31, 2020 N/A· v4 3.5 LOW· v3 2.7 LOW· v2 The process_tx_desc function in hw/net/e1000.c in QEMU before 2.4.0.1 does not properly process transmit descriptor data when sending a network packet, which allows attackers to cause a denial of service (infinite loop a...Show more |
3Arista FedoraprojectQemu3Eos FedoraQemuNov 21, 2024 Jan 23, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Buffer overflow in the send_control_msg function in hw/char/virtio-serial-bus.c in QEMU before 2.4.0 allows guest users to cause a denial of service (QEMU process crash) via a crafted virtio control message. |
4Arista CanonicalFedoraproject+1 more4Eos FedoraQemu+1 moreNov 21, 2024 Jan 23, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 The ne2000_receive function in hw/net/ne2000.c in QEMU before 2.4.0.1 allows attackers to cause a denial of service (infinite loop and instance crash) or possibly execute arbitrary code via vectors related to receiving p...Show more |
5Arista CanonicalFedoraproject+2 more8Eos FedoraLinux Enterprise Debuginfo+5 moreNov 21, 2024 Jan 23, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Integer overflow in the VNC display driver in QEMU before 2.1.0 allows attachers to cause a denial of service (process crash) via a CLIENT_CUT_TEXT message, which triggers an infinite loop. |
In CloudVision Portal all releases in the 2018.1 and 2018.2 Code train allows users with read-only permissions to bypass permissions for restricted functionality via CVP API calls through the Configlet Builder modules. T...Show more |
In CloudVision Portal (CVP) for all releases in the 2018.2 Train, under certain conditions, the application logs user passwords in plain text for certain API calls, potentially leading to user password exposure. This onl...Show more |
6Arista DebianFedoraproject+3 more11Cloudvision Portal Debian LinuxDeveloper Tools+8 moreJun 17, 2026 Oct 24, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public key. There are several attack scenarios, such as traffic from a client to a server that veri...Show more |
1Arista 1Extensible Operating System Jun 17, 2026 Oct 10, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability has been found in the implementation of the Label Distribution Protocol (LDP) protocol in EOS. Under race conditions, the LDP agent can establish an LDP session with a malicious peer potentially allowing...Show more |
Arista EOS through 4.21.0F allows a crash because 802.1x authentication is mishandled. |
Arista CloudVision Portal through 2018.1.1 has Incorrect Permissions. |
Arista EOS before 4.20.2F allows remote BGP peers to cause a denial of service (Rib agent restart) via a malformed path attribute in an UPDATE message. |
The Mlag agent in Arista EOS 4.19 before 4.19.4M and 4.20 before 4.20.2F allows remote attackers to cause a denial of service (agent restart) via crafted UDP packets. |
9Arista CanonicalDebian+6 more29Arx Caas PlatformCloud Magnum Orchestration+26 moreJan 3, 2025 Jan 3, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11, and 4.9.x before 4.9.36, allows remote attackers to cause a denial of service (use-after-free and memory corruption) or poss...Show more |
12Arista ArubanetworksCanonical+9 more21Arubaos Debian LinuxDiskstation Manager+18 moreMay 13, 2026 Oct 4, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response. |
CloudVision Portal (CVP) before 2016.1.2.1 allows remote authenticated users to gain access to the internal configuration mechanisms via the management plane, related to a request to /web/system/console/bundle. |
1Arista 3Dcs 7050q Eos Software Dcs 7050s Eos SoftwareDcs 7050t Eos SoftwareMay 6, 2026 Jan 4, 2017 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Arista EOS 4.15 before 4.15.8M, 4.16 before 4.16.7M, and 4.17 before 4.17.0F on DCS-7050 series devices allow remote attackers to cause a denial of service (device reboot) by sending crafted packets to the control plane. |
Arista EOS before 4.11.12, 4.12 before 4.12.11, 4.13 before 4.13.14M, 4.14 before 4.14.5FX.5, and 4.15 before 4.15.0FX1.1 allows remote attackers to execute arbitrary code as root by leveraging management-plane access, a...Show more |
6Arista CanonicalDebian+3 more7Debian Linux EosFedora+4 moreMay 6, 2026 Nov 6, 2015 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 hw/ide/core.c in QEMU does not properly restrict the commands accepted by an ATAPI device, which allows guest users to cause a denial of service or possibly have unspecified other impact via certain IDE commands, as demo...Show more |
6Arista DebianLenovo+3 more19Debian Linux Emc Px12 400r IvxEmc Px12 450r Ivx+16 moreMay 6, 2026 Aug 31, 2015 N/A· v4 N/A· v3 6.9 MEDIUM· v2 The pit_ioport_read in i8254.c in the Linux kernel before 2.6.33 and QEMU before 2.3.1 does not distinguish between read lengths and write lengths, which might allow guest OS users to execute arbitrary code on the host O...Show more |
7Arista DebianFedoraproject+4 more24Debian Linux Enterprise Linux Compute Node EusEnterprise Linux Desktop+21 moreMay 6, 2026 Aug 12, 2015 N/A· v4 N/A· v3 9.3 HIGH· v2 The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4.5.x and earlier, allows remote attackers to read process heap memory via unspecified vectors. |