openswan records
6 published records for vendor openswan.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 16.7%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-59 Improper Link Resolution Before File Access ('Link Following')2
- CWE-264 Permissions, Privileges, and Access Controls1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2004-0590No exploit | FreeS/WAN 1.x and 2.x, and other related products including superfreeswan 1.x, openswan 1.x before 1.0.6, openswan 2.x before 2.1.4, and stropenswan · openswan | Critical10.0 | — | 2.8% | Dec 6, 2004 |
33Monitor | CVE-2005-3671No exploit | The Internet Key Exchange version 1 (IKEv1) implementation in Openswan 2 (openswan-2) before 2.4.4, and freeswan in SUSE LINUX 9.1 before 2.openswan · openswan | High7.8 | — | 7.5% | Nov 18, 2005 |
29Monitor | CVE-2005-0162No exploit | Stack-based buffer overflow in the get_internal_addresses function in the pluto application for Openswan 1.x before 1.0.9, and Openswan 2.x openswan · openswan | High7.2 | — | 1.7% | Jan 26, 2005 |
27Monitor | CVE-2008-4966No exploit | linux-patch-openswan 2.4.12 allows local users to overwrite arbitrary files via a symlink attack on (a) /tmp/snap##### and (b) /tmp/nightly#openswan · linux-patch-openswan · CWE-59 | Medium6.9 | — | 0.4% | Nov 6, 2008 |
17Monitor | CVE-2008-4190Proof of concept | The IPSEC livetest tool in Openswan 2.4.12 and earlier, and 2.6.x through 2.6.16, allows local users to overwrite arbitrary files and executopenswan · openswan · CWE-59 | Medium4.4 | — | 1.1% | Sep 24, 2008 |
14Monitor | CVE-2011-2147No exploit | Openswan 2.2.x does not properly restrict permissions for (1) /var/run/starter.pid, related to starter.c in the IPsec starter, and (2) /var/openswan · openswan · CWE-264 | Low3.6 | — | 0.3% | May 20, 2011 |
- CVE-2004-059041Plan
FreeS/WAN 1.x and 2.x, and other related products including superfreeswan 1.x, openswan 1.x before 1.0.6, openswan 2.x before 2.1.4, and str
CriticalCVSS 10.0No exploitEPSS 3%openswan · openswanDec 6, 2004
- CVE-2005-367133Monitor
The Internet Key Exchange version 1 (IKEv1) implementation in Openswan 2 (openswan-2) before 2.4.4, and freeswan in SUSE LINUX 9.1 before 2.
HighCVSS 7.8No exploitEPSS 7%openswan · openswanNov 18, 2005
- CVE-2005-016229Monitor
Stack-based buffer overflow in the get_internal_addresses function in the pluto application for Openswan 1.x before 1.0.9, and Openswan 2.x
HighCVSS 7.2No exploitEPSS 2%openswan · openswanJan 26, 2005
- CVE-2008-496627Monitor
linux-patch-openswan 2.4.12 allows local users to overwrite arbitrary files via a symlink attack on (a) /tmp/snap##### and (b) /tmp/nightly#
MediumCVSS 6.9No exploitEPSS 0%openswan · linux-patch-openswanNov 6, 2008
- CVE-2008-419017Monitor
The IPSEC livetest tool in Openswan 2.4.12 and earlier, and 2.6.x through 2.6.16, allows local users to overwrite arbitrary files and execut
MediumCVSS 4.4Proof of conceptEPSS 1%openswan · openswanSep 24, 2008
- CVE-2011-214714Monitor
Openswan 2.2.x does not properly restrict permissions for (1) /var/run/starter.pid, related to starter.c in the IPsec starter, and (2) /var/
LowCVSS 3.6No exploitEPSS 0%openswan · openswanMay 20, 2011