İçeriğe atla
Noroxi

freeradius kayıtları

freeradius üreticisine ait 49 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
10
Düzeltme kaydı olan
%87,8
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

49 kayıt
  • CVE-2019-11234
    41Planlayın

    FreeRADIUS before 3.0.19 does not prevent use of reflection for authentication spoofing, aka a "Dragonblood" issue, a similar issue to CVE-2

    KritikCVSS 9,8İstismar yokEPSS %8

    freeradius · freeradius22 Nis 2019

  • CVE-2017-10979
    41Planlayın

    An FR-GV-202 issue in FreeRADIUS 2.x before 2.2.10 allows "Write overflow in rad_coalesce()" - this allows remote attackers to cause a denia

    KritikCVSS 9,8İstismar yokEPSS %7

    freeradius · freeradius17 Tem 2017

  • CVE-2017-10984
    41Planlayın

    An FR-GV-301 issue in FreeRADIUS 3.x before 3.0.15 allows "Write overflow in data2vp_wimax()" - this allows remote attackers to cause a deni

    KritikCVSS 9,8İstismar yokEPSS %6

    freeradius · freeradius17 Tem 2017

  • CVE-2003-0968
    41Planlayın

    Stack-based buffer overflow in SMB_Logon_Server of the rlm_smb experimental module for FreeRADIUS 0.9.3 and earlier allows remote attackers

    KritikCVSS 10,0İstismar yokEPSS %4

    freeradius · freeradius15 Ara 2003

  • CVE-2024-3596
    40Planlayın

    RADIUS Protocol under RFC2865 is vulnerable to forgery attacks.

    KritikCVSS 9,0Kavram kanıtıEPSS %15

    freeradius · freeradius9 Tem 2024

  • CVE-2017-9148
    40Planlayın

    The TLS session cache in FreeRADIUS 2.1.1 through 2.1.7, 3.0.x before 3.0.14, 3.1.x before 2017-02-04, and 4.0.x before 2017-02-04 fails to

    KritikCVSS 9,8İstismar yokEPSS %4

    freeradius · freeradius29 May 2017

  • CVE-2019-11235
    40Planlayın

    FreeRADIUS before 3.0.19 mishandles the "each participant verifies that the received scalar is within a range, and that the received group e

    KritikCVSS 9,8İstismar yokEPSS %4

    freeradius · freeradius22 Nis 2019

  • CVE-2001-1376
    33İzleyin

    Buffer overflow in digest calculation function of multiple RADIUS implementations allows remote attackers to cause a denial of service and p

    YüksekCVSS 7,5İstismar yokEPSS %9

    ascend · radius4 Mar 2002

  • CVE-2005-4746
    32İzleyin

    Multiple buffer overflows in FreeRADIUS 1.0.3 and 1.0.4 allow remote attackers to cause denial of service (crash) via (1) the rlm_sqlcounter

    YüksekCVSS 7,8İstismar yokEPSS %2

    freeradius · freeradius31 Ara 2005

  • CVE-2015-8763
    32İzleyin

    The EAP-PWD module in FreeRADIUS 3.0 through 3.0.8 allows remote attackers to have unspecified impact via a crafted (1) commit or (2) confir

    YüksekCVSS 8,1İstismar yokEPSS %1

    freeradius · freeradius27 Mar 2017

  • CVE-2015-8764
    32İzleyin

    Off-by-one error in the EAP-PWD module in FreeRADIUS 3.0 through 3.0.8, which triggers a buffer overflow.

    YüksekCVSS 8,1İstismar yokEPSS %1

    freeradius · freeradius27 Mar 2017

  • CVE-2014-2015
    31İzleyin

    Stack-based buffer overflow in the normify function in the rlm_pap module (modules/rlm_pap/rlm_pap.c) in FreeRADIUS 2.x, possibly 2.2.3 and

    YüksekCVSS 7,5İstismar yokEPSS %4

    freeradius · freeradius1 Kas 2014

  • CVE-2017-10982
    31İzleyin

    An FR-GV-205 issue in FreeRADIUS 2.x before 2.2.10 allows "DHCP - Buffer over-read in fr_dhcp_decode_options()" and a denial of service.

    YüksekCVSS 7,5İstismar yokEPSS %4

    freeradius · freeradius17 Tem 2017

  • CVE-2017-10978
    31İzleyin

    An FR-GV-201 issue in FreeRADIUS 2.x before 2.2.10 and 3.x before 3.0.15 allows "Read / write overflow in make_secret()" and a denial of ser

    YüksekCVSS 7,5İstismar yokEPSS %4

    freeradius · freeradius17 Tem 2017

  • CVE-2015-9542
    31İzleyin

    add_password in pam_radius_auth.c in pam_radius 1.4.0 does not correctly check the length of the input password, and is vulnerable to a stac

    YüksekCVSS 7,5İstismar yokEPSS %4

    freeradius · pam radius24 Şub 2020

  • CVE-2017-10983
    31İzleyin

    An FR-GV-206 issue in FreeRADIUS 2.x before 2.2.10 and 3.x before 3.0.15 allows "DHCP - Read overflow when decoding option 63" and a denial

    YüksekCVSS 7,5İstismar yokEPSS %3

    freeradius · freeradius17 Tem 2017

  • CVE-2017-10981
    31İzleyin

    An FR-GV-204 issue in FreeRADIUS 2.x before 2.2.10 allows "DHCP - Memory leak in fr_dhcp_decode()" and a denial of service.

    YüksekCVSS 7,5İstismar yokEPSS %3

    freeradius · freeradius17 Tem 2017

  • CVE-2017-10980
    31İzleyin

    An FR-GV-203 issue in FreeRADIUS 2.x before 2.2.10 allows "DHCP - Memory leak in decode_tlv()" and a denial of service.

    YüksekCVSS 7,5İstismar yokEPSS %3

    freeradius · freeradius17 Tem 2017

  • CVE-2017-10985
    31İzleyin

    An FR-GV-302 issue in FreeRADIUS 3.x before 3.0.15 allows "Infinite loop and memory exhaustion with 'concat' attributes" and a denial of ser

    YüksekCVSS 7,5İstismar yokEPSS %3

    freeradius · freeradius17 Tem 2017

  • CVE-2017-10986
    31İzleyin

    An FR-GV-303 issue in FreeRADIUS 3.x before 3.0.15 allows "DHCP - Infinite read in dhcp_attr2vp()" and a denial of service.

    YüksekCVSS 7,5İstismar yokEPSS %3

    freeradius · freeradius17 Tem 2017

  • CVE-2017-10987
    31İzleyin

    An FR-GV-304 issue in FreeRADIUS 3.x before 3.0.15 allows "DHCP - Buffer over-read in fr_dhcp_decode_suboptions()" and a denial of service.

    YüksekCVSS 7,5İstismar yokEPSS %3

    freeradius · freeradius17 Tem 2017

  • CVE-2006-1354
    31İzleyin

    Unspecified vulnerability in FreeRADIUS 1.0.0 up to 1.1.0 allows remote attackers to bypass authentication or cause a denial of service (ser

    YüksekCVSS 7,5İstismar yokEPSS %3

    freeradius · freeradius21 Mar 2006

  • CVE-2005-1455
    31İzleyin

    Buffer overflow in the sql_escape_func function in the SQL module for FreeRADIUS 1.0.2 and earlier allows remote attackers to cause a denial

    YüksekCVSS 7,5İstismar yokEPSS %3

    freeradius · freeradius19 May 2005

  • CVE-2019-17185
    31İzleyin

    In FreeRADIUS 3.0.x before 3.0.20, the EAP-pwd module used a global OpenSSL BN_CTX instance to handle all handshakes.

    YüksekCVSS 7,5İstismar yokEPSS %2

    freeradius · freeradius20 Mar 2020

  • CVE-2005-1454
    31İzleyin

    SQL injection vulnerability in the radius_xlat function in the SQL module for FreeRADIUS 1.0.2 and earlier allows remote authenticated users

    YüksekCVSS 7,5İstismar yokEPSS %2

    freeradius · freeradius19 May 2005