Записи libreswan
24 опубликованных записей вендора libreswan.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 5
- С записью об исправлении
- 70,8 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-476 NULL Pointer Dereference5
- CWE-20 Improper Input Validation4
- CWE-400 Uncontrolled Resource Consumption3
- CWE-347 Improper Verification of Cryptographic Signature2
- CWE-189 Numeric Errors2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
24 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
37Наблюдать | CVE-2013-7283Эксплойта нет | Race condition in the libreswan.spec files for Red Hat Enterprise Linux (RHEL) and Fedora packages in libreswan 3.6 has unspecified impact alibreswan · libreswan · CWE-362 | Критическая9,3 | — | 1,6 % | 9 янв. 2014 г. |
31Наблюдать | CVE-2020-1763Эксплойта нет | An out-of-bounds buffer read flaw was found in the pluto daemon of libreswan from versions 3.27 till 3.31 where, an unauthenticated attackerlibreswan · libreswan · CWE-125 | Высокая7,5 | — | 3,6 % | 12 мая 2020 г. |
31Наблюдать | CVE-2016-5391Эксплойта нет | libreswan before 3.18 allows remote attackers to cause a denial of service (NULL pointer dereference and pluto daemon restart).libreswan · libreswan · CWE-476 | Высокая7,5 | — | 3,0 % | 13 июн. 2017 г. |
31Наблюдать | CVE-2019-12312Эксплойта нет | In Libreswan 3.27 an assertion failure can lead to a pluto IKE daemon restart.libreswan · libreswan · CWE-476 | Высокая7,5 | — | 2,7 % | 24 мая 2019 г. |
31Наблюдать | CVE-2016-5361Эксплойта нет | programs/pluto/ikev1.c in libreswan before 3.17 retransmits in initial-responder states, which allows remote attackers to cause a denial of libreswan · libreswan · CWE-20 | Высокая7,5 | — | 2,7 % | 16 июн. 2016 г. |
31Наблюдать | CVE-2016-3071Эксплойта нет | Libreswan 3.16 might allow remote attackers to cause a denial of service (daemon restart) via an IKEv2 aes_xcbc transform.libreswan · libreswan · CWE-20 | Высокая7,5 | — | 2,6 % | 18 апр. 2016 г. |
31Наблюдать | CVE-2022-23094Эксплойта нет | Libreswan 4.2 through 4.5 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted IKElibreswan · libreswan · CWE-476 | Высокая7,5 | — | 2,5 % | 14 янв. 2022 г. |
30Наблюдать | CVE-2023-2295Эксплойта нет | A vulnerability was found in the libreswan library.libreswan · libreswan · CWE-400 | Высокая7,5 | — | 1,6 % | 17 мая 2023 г. |
30Наблюдать | CVE-2023-30570Эксплойта нет | pluto in Libreswan before 4.11 allows a denial of service (responder SPI mishandling and daemon crash) via unauthenticated IKEv1 Aggressive libreswan · libreswan · CWE-400 | Высокая7,5 | — | 1,2 % | 28 мая 2023 г. |
30Наблюдать | CVE-2026-12413Эксплойта нет | IKEv2 Denial of Service via malformed fragmentationlibreswan · libreswan · CWE-193 | Высокая7,5 | — | 0,6 % | 2 июл. 2026 г. |
26Наблюдать | CVE-2023-23009Эксплойта нет | Libreswan 4.9 allows remote attackers to cause a denial of service (assert failure and daemon restart) via crafted TS payload with an incorrlibreswan · libreswan · CWE-400 | Средняя6,5 | — | 1,6 % | 21 февр. 2023 г. |
26Наблюдать | CVE-2023-38710Эксплойта нет | An issue was discovered in Libreswan before 4.12.libreswan · libreswan | Средняя6,5 | — | 0,8 % | 25 авг. 2023 г. |
26Наблюдать | CVE-2023-38712Эксплойта нет | An issue was discovered in Libreswan 3.x and 4.x before 4.12.libreswan · libreswan · CWE-476 | Средняя6,5 | — | 0,8 % | 25 авг. 2023 г. |
26Наблюдать | CVE-2023-38711Эксплойта нет | An issue was discovered in Libreswan before 4.12.libreswan · libreswan · CWE-476 | Средняя6,5 | — | 0,8 % | 25 авг. 2023 г. |
26Наблюдать | CVE-2024-3652Эксплойта нет | IKEv1 default AH/ESP responder can cause libreswan to abort and restartlibreswan · libreswan · CWE-404 | Средняя6,5 | — | 0,8 % | 10 апр. 2024 г. |
23Наблюдать | CVE-2026-50721Эксплойта нет | IKEv1 Denial of Service via RSA-SHA1 (PKCS#1 Version 1.5 Encrypted) authentication payloadlibreswan · libreswan · CWE-347 | Средняя5,9 | — | 0,4 % | 2 июл. 2026 г. |
23Наблюдать | CVE-2026-50722Эксплойта нет | IKEv2 Denial of Service via RSA-SHA1 (PKCS#1 RSASSA-PKCS1-v1_5) authentication payloadlibreswan · libreswan · CWE-347 | Средняя5,9 | — | 0,3 % | 2 июл. 2026 г. |
21Наблюдать | CVE-2013-4564Эксплойта нет | Libreswan 3.6 allows remote attackers to cause a denial of service (crash) via a small length value and (1) no version or (2) an invalid majlibreswan · libreswan · CWE-189 | Средняя5,0 | — | 2,7 % | 7 янв. 2014 г. |
21Наблюдать | CVE-2015-3204Эксплойта нет | libreswan 3.9 through 3.12 allows remote attackers to cause a denial of service (daemon restart) via an IKEv1 packet with (1) unassigned bitlibreswan · libreswan · CWE-20 | Средняя5,0 | — | 2,6 % | 1 июл. 2015 г. |
21Наблюдать | CVE-2013-7294Эксплойта нет | The ikev2parent_inI1outR1 function in pluto/ikev2_parent.c in libreswan before 3.7 allows remote attackers to cause a denial of service (reslibreswan · libreswan · CWE-20 | Средняя5,0 | — | 2,5 % | 16 янв. 2014 г. |
21Наблюдать | CVE-2013-6467Эксплойта нет | Libreswan 3.7 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon restart) via IKEv2 plibreswan · libreswan | Средняя5,0 | — | 2,5 % | 26 янв. 2014 г. |
21Наблюдать | CVE-2013-2052Эксплойта нет | Buffer overflow in the atodn function in libreswan 3.0 and 3.1, when Opportunistic Encryption is enabled and an RSA key is being used, allowlibreswan · libreswan · CWE-119 | Средняя5,1 | — | 1,8 % | 9 июл. 2013 г. |
18Наблюдать | CVE-2015-3240Эксплойта нет | The pluto IKE daemon in libreswan before 3.15 and Openswan before 2.6.45, when built with NSS, allows remote attackers to cause a denial of libreswan · libreswan · CWE-189 | Средняя4,3 | — | 2,8 % | 9 нояб. 2015 г. |
12Наблюдать | CVE-2019-10155Эксплойта нет | The Libreswan Project has found a vulnerability in the processing of IKEv1 informational exchange packets which are encrypted and integrity libreswan · libreswan · CWE-354 | Низкая3,1 | — | 0,5 % | 12 июн. 2019 г. |
- CVE-2013-728337Наблюдать
Race condition in the libreswan.spec files for Red Hat Enterprise Linux (RHEL) and Fedora packages in libreswan 3.6 has unspecified impact a
КритическаяCVSS 9,3Эксплойта нетEPSS 2 %libreswan · libreswan9 янв. 2014 г.
- CVE-2020-176331Наблюдать
An out-of-bounds buffer read flaw was found in the pluto daemon of libreswan from versions 3.27 till 3.31 where, an unauthenticated attacker
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %libreswan · libreswan12 мая 2020 г.
- CVE-2016-539131Наблюдать
libreswan before 3.18 allows remote attackers to cause a denial of service (NULL pointer dereference and pluto daemon restart).
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %libreswan · libreswan13 июн. 2017 г.
- CVE-2019-1231231Наблюдать
In Libreswan 3.27 an assertion failure can lead to a pluto IKE daemon restart.
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %libreswan · libreswan24 мая 2019 г.
- CVE-2016-536131Наблюдать
programs/pluto/ikev1.c in libreswan before 3.17 retransmits in initial-responder states, which allows remote attackers to cause a denial of
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %libreswan · libreswan16 июн. 2016 г.
- CVE-2016-307131Наблюдать
Libreswan 3.16 might allow remote attackers to cause a denial of service (daemon restart) via an IKEv2 aes_xcbc transform.
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %libreswan · libreswan18 апр. 2016 г.
- CVE-2022-2309431Наблюдать
Libreswan 4.2 through 4.5 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted IKE
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %libreswan · libreswan14 янв. 2022 г.
- CVE-2023-229530Наблюдать
A vulnerability was found in the libreswan library.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %libreswan · libreswan17 мая 2023 г.
- CVE-2023-3057030Наблюдать
pluto in Libreswan before 4.11 allows a denial of service (responder SPI mishandling and daemon crash) via unauthenticated IKEv1 Aggressive
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %libreswan · libreswan28 мая 2023 г.
- CVE-2026-1241330Наблюдать
IKEv2 Denial of Service via malformed fragmentation
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %libreswan · libreswan2 июл. 2026 г.
- CVE-2023-2300926Наблюдать
Libreswan 4.9 allows remote attackers to cause a denial of service (assert failure and daemon restart) via crafted TS payload with an incorr
СредняяCVSS 6,5Эксплойта нетEPSS 2 %libreswan · libreswan21 февр. 2023 г.
- CVE-2023-3871026Наблюдать
An issue was discovered in Libreswan before 4.12.
СредняяCVSS 6,5Эксплойта нетEPSS 1 %libreswan · libreswan25 авг. 2023 г.
- CVE-2023-3871226Наблюдать
An issue was discovered in Libreswan 3.x and 4.x before 4.12.
СредняяCVSS 6,5Эксплойта нетEPSS 1 %libreswan · libreswan25 авг. 2023 г.
- CVE-2023-3871126Наблюдать
An issue was discovered in Libreswan before 4.12.
СредняяCVSS 6,5Эксплойта нетEPSS 1 %libreswan · libreswan25 авг. 2023 г.
- CVE-2024-365226Наблюдать
IKEv1 default AH/ESP responder can cause libreswan to abort and restart
СредняяCVSS 6,5Эксплойта нетEPSS 1 %libreswan · libreswan10 апр. 2024 г.
- CVE-2026-5072123Наблюдать
IKEv1 Denial of Service via RSA-SHA1 (PKCS#1 Version 1.5 Encrypted) authentication payload
СредняяCVSS 5,9Эксплойта нетEPSS 0 %libreswan · libreswan2 июл. 2026 г.
- CVE-2026-5072223Наблюдать
IKEv2 Denial of Service via RSA-SHA1 (PKCS#1 RSASSA-PKCS1-v1_5) authentication payload
СредняяCVSS 5,9Эксплойта нетEPSS 0 %libreswan · libreswan2 июл. 2026 г.
- CVE-2013-456421Наблюдать
Libreswan 3.6 allows remote attackers to cause a denial of service (crash) via a small length value and (1) no version or (2) an invalid maj
СредняяCVSS 5,0Эксплойта нетEPSS 3 %libreswan · libreswan7 янв. 2014 г.
- CVE-2015-320421Наблюдать
libreswan 3.9 through 3.12 allows remote attackers to cause a denial of service (daemon restart) via an IKEv1 packet with (1) unassigned bit
СредняяCVSS 5,0Эксплойта нетEPSS 3 %libreswan · libreswan1 июл. 2015 г.
- CVE-2013-729421Наблюдать
The ikev2parent_inI1outR1 function in pluto/ikev2_parent.c in libreswan before 3.7 allows remote attackers to cause a denial of service (res
СредняяCVSS 5,0Эксплойта нетEPSS 3 %libreswan · libreswan16 янв. 2014 г.
- CVE-2013-646721Наблюдать
Libreswan 3.7 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon restart) via IKEv2 p
СредняяCVSS 5,0Эксплойта нетEPSS 2 %libreswan · libreswan26 янв. 2014 г.
- CVE-2013-205221Наблюдать
Buffer overflow in the atodn function in libreswan 3.0 and 3.1, when Opportunistic Encryption is enabled and an RSA key is being used, allow
СредняяCVSS 5,1Эксплойта нетEPSS 2 %libreswan · libreswan9 июл. 2013 г.
- CVE-2015-324018Наблюдать
The pluto IKE daemon in libreswan before 3.15 and Openswan before 2.6.45, when built with NSS, allows remote attackers to cause a denial of
СредняяCVSS 4,3Эксплойта нетEPSS 3 %libreswan · libreswan9 нояб. 2015 г.
- CVE-2019-1015512Наблюдать
The Libreswan Project has found a vulnerability in the processing of IKEv1 informational exchange packets which are encrypted and integrity
НизкаяCVSS 3,1Эксплойта нетEPSS 1 %libreswan · libreswan12 июн. 2019 г.