Записи freeradius
49 опубликованных записей вендора freeradius.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 10
- С записью об исправлении
- 87,8 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer6
- CWE-787 Out-of-bounds Write3
- CWE-125 Out-of-bounds Read3
- CWE-287 Improper Authentication3
- CWE-476 NULL Pointer Dereference2
- CWE-399 Resource Management Errors2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
49 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2019-11234Эксплойта нет | FreeRADIUS before 3.0.19 does not prevent use of reflection for authentication spoofing, aka a "Dragonblood" issue, a similar issue to CVE-2freeradius · freeradius · CWE-287 | Критическая9,8 | — | 7,6 % | 22 апр. 2019 г. |
41В плане | CVE-2017-10979Эксплойта нет | An FR-GV-202 issue in FreeRADIUS 2.x before 2.2.10 allows "Write overflow in rad_coalesce()" - this allows remote attackers to cause a deniafreeradius · freeradius · CWE-787 | Критическая9,8 | — | 7,0 % | 17 июл. 2017 г. |
41В плане | CVE-2017-10984Эксплойта нет | An FR-GV-301 issue in FreeRADIUS 3.x before 3.0.15 allows "Write overflow in data2vp_wimax()" - this allows remote attackers to cause a denifreeradius · freeradius · CWE-787 | Критическая9,8 | — | 6,4 % | 17 июл. 2017 г. |
41В плане | CVE-2003-0968Эксплойта нет | Stack-based buffer overflow in SMB_Logon_Server of the rlm_smb experimental module for FreeRADIUS 0.9.3 and earlier allows remote attackers freeradius · freeradius | Критическая10,0 | — | 3,7 % | 15 дек. 2003 г. |
40В плане | CVE-2024-3596Proof of concept | RADIUS Protocol under RFC2865 is vulnerable to forgery attacks.freeradius · freeradius · CWE-354 | Критическая9,0 | — | 14,9 % | 9 июл. 2024 г. |
40В плане | CVE-2017-9148Эксплойта нет | The TLS session cache in FreeRADIUS 2.1.1 through 2.1.7, 3.0.x before 3.0.14, 3.1.x before 2017-02-04, and 4.0.x before 2017-02-04 fails to freeradius · freeradius · CWE-287 | Критическая9,8 | — | 3,9 % | 29 мая 2017 г. |
40В плане | CVE-2019-11235Эксплойта нет | FreeRADIUS before 3.0.19 mishandles the "each participant verifies that the received scalar is within a range, and that the received group efreeradius · freeradius · CWE-345 | Критическая9,8 | — | 3,6 % | 22 апр. 2019 г. |
33Наблюдать | CVE-2001-1376Эксплойта нет | Buffer overflow in digest calculation function of multiple RADIUS implementations allows remote attackers to cause a denial of service and pascend · radius | Высокая7,5 | — | 8,5 % | 4 мар. 2002 г. |
32Наблюдать | CVE-2005-4746Эксплойта нет | Multiple buffer overflows in FreeRADIUS 1.0.3 and 1.0.4 allow remote attackers to cause denial of service (crash) via (1) the rlm_sqlcounterfreeradius · freeradius | Высокая7,8 | — | 2,4 % | 31 дек. 2005 г. |
32Наблюдать | CVE-2015-8763Эксплойта нет | The EAP-PWD module in FreeRADIUS 3.0 through 3.0.8 allows remote attackers to have unspecified impact via a crafted (1) commit or (2) confirfreeradius · freeradius · CWE-125 | Высокая8,1 | — | 1,2 % | 27 мар. 2017 г. |
32Наблюдать | CVE-2015-8764Эксплойта нет | Off-by-one error in the EAP-PWD module in FreeRADIUS 3.0 through 3.0.8, which triggers a buffer overflow.freeradius · freeradius · CWE-119 | Высокая8,1 | — | 1,1 % | 27 мар. 2017 г. |
31Наблюдать | CVE-2014-2015Эксплойта нет | Stack-based buffer overflow in the normify function in the rlm_pap module (modules/rlm_pap/rlm_pap.c) in FreeRADIUS 2.x, possibly 2.2.3 and freeradius · freeradius · CWE-119 | Высокая7,5 | — | 3,9 % | 1 нояб. 2014 г. |
31Наблюдать | CVE-2017-10982Эксплойта нет | An FR-GV-205 issue in FreeRADIUS 2.x before 2.2.10 allows "DHCP - Buffer over-read in fr_dhcp_decode_options()" and a denial of service.freeradius · freeradius · CWE-125 | Высокая7,5 | — | 3,8 % | 17 июл. 2017 г. |
31Наблюдать | CVE-2017-10978Эксплойта нет | An FR-GV-201 issue in FreeRADIUS 2.x before 2.2.10 and 3.x before 3.0.15 allows "Read / write overflow in make_secret()" and a denial of serfreeradius · freeradius · CWE-119 | Высокая7,5 | — | 3,8 % | 17 июл. 2017 г. |
31Наблюдать | CVE-2015-9542Эксплойта нет | add_password in pam_radius_auth.c in pam_radius 1.4.0 does not correctly check the length of the input password, and is vulnerable to a stacfreeradius · pam radius · CWE-787 | Высокая7,5 | — | 3,5 % | 24 февр. 2020 г. |
31Наблюдать | CVE-2017-10983Эксплойта нет | An FR-GV-206 issue in FreeRADIUS 2.x before 2.2.10 and 3.x before 3.0.15 allows "DHCP - Read overflow when decoding option 63" and a denial freeradius · freeradius · CWE-119 | Высокая7,5 | — | 3,4 % | 17 июл. 2017 г. |
31Наблюдать | CVE-2017-10981Эксплойта нет | An FR-GV-204 issue in FreeRADIUS 2.x before 2.2.10 allows "DHCP - Memory leak in fr_dhcp_decode()" and a denial of service.freeradius · freeradius · CWE-772 | Высокая7,5 | — | 3,4 % | 17 июл. 2017 г. |
31Наблюдать | CVE-2017-10980Эксплойта нет | An FR-GV-203 issue in FreeRADIUS 2.x before 2.2.10 allows "DHCP - Memory leak in decode_tlv()" and a denial of service.freeradius · freeradius · CWE-772 | Высокая7,5 | — | 3,4 % | 17 июл. 2017 г. |
31Наблюдать | CVE-2017-10985Эксплойта нет | An FR-GV-302 issue in FreeRADIUS 3.x before 3.0.15 allows "Infinite loop and memory exhaustion with 'concat' attributes" and a denial of serfreeradius · freeradius · CWE-835 | Высокая7,5 | — | 3,3 % | 17 июл. 2017 г. |
31Наблюдать | CVE-2017-10986Эксплойта нет | An FR-GV-303 issue in FreeRADIUS 3.x before 3.0.15 allows "DHCP - Infinite read in dhcp_attr2vp()" and a denial of service.freeradius · freeradius · CWE-835 | Высокая7,5 | — | 3,0 % | 17 июл. 2017 г. |
31Наблюдать | CVE-2017-10987Эксплойта нет | An FR-GV-304 issue in FreeRADIUS 3.x before 3.0.15 allows "DHCP - Buffer over-read in fr_dhcp_decode_suboptions()" and a denial of service.freeradius · freeradius · CWE-125 | Высокая7,5 | — | 3,0 % | 17 июл. 2017 г. |
31Наблюдать | CVE-2006-1354Эксплойта нет | Unspecified vulnerability in FreeRADIUS 1.0.0 up to 1.1.0 allows remote attackers to bypass authentication or cause a denial of service (serfreeradius · freeradius | Высокая7,5 | — | 2,8 % | 21 мар. 2006 г. |
31Наблюдать | CVE-2005-1455Эксплойта нет | Buffer overflow in the sql_escape_func function in the SQL module for FreeRADIUS 1.0.2 and earlier allows remote attackers to cause a denialfreeradius · freeradius | Высокая7,5 | — | 2,5 % | 19 мая 2005 г. |
31Наблюдать | CVE-2019-17185Эксплойта нет | In FreeRADIUS 3.0.x before 3.0.20, the EAP-pwd module used a global OpenSSL BN_CTX instance to handle all handshakes.freeradius · freeradius · CWE-662 | Высокая7,5 | — | 2,2 % | 20 мар. 2020 г. |
31Наблюдать | CVE-2005-1454Эксплойта нет | SQL injection vulnerability in the radius_xlat function in the SQL module for FreeRADIUS 1.0.2 and earlier allows remote authenticated usersfreeradius · freeradius | Высокая7,5 | — | 1,8 % | 19 мая 2005 г. |
- CVE-2019-1123441В плане
FreeRADIUS before 3.0.19 does not prevent use of reflection for authentication spoofing, aka a "Dragonblood" issue, a similar issue to CVE-2
КритическаяCVSS 9,8Эксплойта нетEPSS 8 %freeradius · freeradius22 апр. 2019 г.
- CVE-2017-1097941В плане
An FR-GV-202 issue in FreeRADIUS 2.x before 2.2.10 allows "Write overflow in rad_coalesce()" - this allows remote attackers to cause a denia
КритическаяCVSS 9,8Эксплойта нетEPSS 7 %freeradius · freeradius17 июл. 2017 г.
- CVE-2017-1098441В плане
An FR-GV-301 issue in FreeRADIUS 3.x before 3.0.15 allows "Write overflow in data2vp_wimax()" - this allows remote attackers to cause a deni
КритическаяCVSS 9,8Эксплойта нетEPSS 6 %freeradius · freeradius17 июл. 2017 г.
- CVE-2003-096841В плане
Stack-based buffer overflow in SMB_Logon_Server of the rlm_smb experimental module for FreeRADIUS 0.9.3 and earlier allows remote attackers
КритическаяCVSS 10,0Эксплойта нетEPSS 4 %freeradius · freeradius15 дек. 2003 г.
- CVE-2024-359640В плане
RADIUS Protocol under RFC2865 is vulnerable to forgery attacks.
КритическаяCVSS 9,0Proof of conceptEPSS 15 %freeradius · freeradius9 июл. 2024 г.
- CVE-2017-914840В плане
The TLS session cache in FreeRADIUS 2.1.1 through 2.1.7, 3.0.x before 3.0.14, 3.1.x before 2017-02-04, and 4.0.x before 2017-02-04 fails to
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %freeradius · freeradius29 мая 2017 г.
- CVE-2019-1123540В плане
FreeRADIUS before 3.0.19 mishandles the "each participant verifies that the received scalar is within a range, and that the received group e
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %freeradius · freeradius22 апр. 2019 г.
- CVE-2001-137633Наблюдать
Buffer overflow in digest calculation function of multiple RADIUS implementations allows remote attackers to cause a denial of service and p
ВысокаяCVSS 7,5Эксплойта нетEPSS 9 %ascend · radius4 мар. 2002 г.
- CVE-2005-474632Наблюдать
Multiple buffer overflows in FreeRADIUS 1.0.3 and 1.0.4 allow remote attackers to cause denial of service (crash) via (1) the rlm_sqlcounter
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %freeradius · freeradius31 дек. 2005 г.
- CVE-2015-876332Наблюдать
The EAP-PWD module in FreeRADIUS 3.0 through 3.0.8 allows remote attackers to have unspecified impact via a crafted (1) commit or (2) confir
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %freeradius · freeradius27 мар. 2017 г.
- CVE-2015-876432Наблюдать
Off-by-one error in the EAP-PWD module in FreeRADIUS 3.0 through 3.0.8, which triggers a buffer overflow.
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %freeradius · freeradius27 мар. 2017 г.
- CVE-2014-201531Наблюдать
Stack-based buffer overflow in the normify function in the rlm_pap module (modules/rlm_pap/rlm_pap.c) in FreeRADIUS 2.x, possibly 2.2.3 and
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %freeradius · freeradius1 нояб. 2014 г.
- CVE-2017-1098231Наблюдать
An FR-GV-205 issue in FreeRADIUS 2.x before 2.2.10 allows "DHCP - Buffer over-read in fr_dhcp_decode_options()" and a denial of service.
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %freeradius · freeradius17 июл. 2017 г.
- CVE-2017-1097831Наблюдать
An FR-GV-201 issue in FreeRADIUS 2.x before 2.2.10 and 3.x before 3.0.15 allows "Read / write overflow in make_secret()" and a denial of ser
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %freeradius · freeradius17 июл. 2017 г.
- CVE-2015-954231Наблюдать
add_password in pam_radius_auth.c in pam_radius 1.4.0 does not correctly check the length of the input password, and is vulnerable to a stac
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %freeradius · pam radius24 февр. 2020 г.
- CVE-2017-1098331Наблюдать
An FR-GV-206 issue in FreeRADIUS 2.x before 2.2.10 and 3.x before 3.0.15 allows "DHCP - Read overflow when decoding option 63" and a denial
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %freeradius · freeradius17 июл. 2017 г.
- CVE-2017-1098131Наблюдать
An FR-GV-204 issue in FreeRADIUS 2.x before 2.2.10 allows "DHCP - Memory leak in fr_dhcp_decode()" and a denial of service.
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %freeradius · freeradius17 июл. 2017 г.
- CVE-2017-1098031Наблюдать
An FR-GV-203 issue in FreeRADIUS 2.x before 2.2.10 allows "DHCP - Memory leak in decode_tlv()" and a denial of service.
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %freeradius · freeradius17 июл. 2017 г.
- CVE-2017-1098531Наблюдать
An FR-GV-302 issue in FreeRADIUS 3.x before 3.0.15 allows "Infinite loop and memory exhaustion with 'concat' attributes" and a denial of ser
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %freeradius · freeradius17 июл. 2017 г.
- CVE-2017-1098631Наблюдать
An FR-GV-303 issue in FreeRADIUS 3.x before 3.0.15 allows "DHCP - Infinite read in dhcp_attr2vp()" and a denial of service.
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %freeradius · freeradius17 июл. 2017 г.
- CVE-2017-1098731Наблюдать
An FR-GV-304 issue in FreeRADIUS 3.x before 3.0.15 allows "DHCP - Buffer over-read in fr_dhcp_decode_suboptions()" and a denial of service.
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %freeradius · freeradius17 июл. 2017 г.
- CVE-2006-135431Наблюдать
Unspecified vulnerability in FreeRADIUS 1.0.0 up to 1.1.0 allows remote attackers to bypass authentication or cause a denial of service (ser
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %freeradius · freeradius21 мар. 2006 г.
- CVE-2005-145531Наблюдать
Buffer overflow in the sql_escape_func function in the SQL module for FreeRADIUS 1.0.2 and earlier allows remote attackers to cause a denial
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %freeradius · freeradius19 мая 2005 г.
- CVE-2019-1718531Наблюдать
In FreeRADIUS 3.0.x before 3.0.20, the EAP-pwd module used a global OpenSSL BN_CTX instance to handle all handshakes.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %freeradius · freeradius20 мар. 2020 г.
- CVE-2005-145431Наблюдать
SQL injection vulnerability in the radius_xlat function in the SQL module for FreeRADIUS 1.0.2 and earlier allows remote authenticated users
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %freeradius · freeradius19 мая 2005 г.