netfilter records
5 published records for vendor netfilter.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 40%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-17 DEPRECATED: Code1
- CWE-203 Observable Discrepancy1
- CWE-770 Allocation of Resources Without Limits or Throttling1
- CWE-787 Out-of-bounds Write1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
5 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
31Monitor | CVE-2012-2663No exploit | extensions/libxt_tcp.c in iptables through 1.4.21 does not match TCP SYN+FIN packets in --syn rules, which might allow remote attackers to bnetfilter · iptables | High7.5 | — | 2.7% | Feb 15, 2014 |
21Monitor | CVE-2015-6496No exploit | conntrackd in conntrack-tools 1.4.2 and earlier does not ensure that the optional kernel modules are loaded before using them, which allows netfilter · conntrack-tools · CWE-17 | Medium5.0 | — | 3.2% | Aug 24, 2015 |
20Monitor | CVE-2001-1388No exploit | iptables before 1.2.4 does not accurately convert rate limits that are specified on the command line, which could allow attackers or users tnetfilter · iptables · CWE-770 | Medium5.0 | — | 1.1% | Nov 5, 2001 |
17Monitor | CVE-2019-11360No exploit | A buffer overflow in iptables-restore in netfilter iptables 1.8.2 allows an attacker to (at least) crash the program or potentially gain codnetfilter · iptables · CWE-787 | Medium4.2 | — | 1.8% | Jul 12, 2019 |
8Monitor | CVE-2001-1387No exploit | iptables-save in iptables before 1.2.4 records the "--reject-with icmp-host-prohibited" rule as "--reject-with tcp-reset," which causes iptanetfilter · iptables · CWE-203 | Low2.1 | — | 0.4% | Nov 5, 2001 |
- CVE-2012-266331Monitor
extensions/libxt_tcp.c in iptables through 1.4.21 does not match TCP SYN+FIN packets in --syn rules, which might allow remote attackers to b
HighCVSS 7.5No exploitEPSS 3%netfilter · iptablesFeb 15, 2014
- CVE-2015-649621Monitor
conntrackd in conntrack-tools 1.4.2 and earlier does not ensure that the optional kernel modules are loaded before using them, which allows
MediumCVSS 5.0No exploitEPSS 3%netfilter · conntrack-toolsAug 24, 2015
- CVE-2001-138820Monitor
iptables before 1.2.4 does not accurately convert rate limits that are specified on the command line, which could allow attackers or users t
MediumCVSS 5.0No exploitEPSS 1%netfilter · iptablesNov 5, 2001
- CVE-2019-1136017Monitor
A buffer overflow in iptables-restore in netfilter iptables 1.8.2 allows an attacker to (at least) crash the program or potentially gain cod
MediumCVSS 4.2No exploitEPSS 2%netfilter · iptablesJul 12, 2019
- CVE-2001-13878Monitor
iptables-save in iptables before 1.2.4 records the "--reject-with icmp-host-prohibited" rule as "--reject-with tcp-reset," which causes ipta
LowCVSS 2.1No exploitEPSS 0%netfilter · iptablesNov 5, 2001