freeradius kayıtları
freeradius üreticisine ait 49 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 10
- Düzeltme kaydı olan
- %87,8
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer6
- CWE-787 Out-of-bounds Write3
- CWE-125 Out-of-bounds Read3
- CWE-287 Improper Authentication3
- CWE-476 NULL Pointer Dereference2
- CWE-399 Resource Management Errors2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
49 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2019-11234İstismar yok | FreeRADIUS before 3.0.19 does not prevent use of reflection for authentication spoofing, aka a "Dragonblood" issue, a similar issue to CVE-2freeradius · freeradius · CWE-287 | Kritik9,8 | — | %7,6 | 22 Nis 2019 |
41Planlayın | CVE-2017-10979İstismar yok | An FR-GV-202 issue in FreeRADIUS 2.x before 2.2.10 allows "Write overflow in rad_coalesce()" - this allows remote attackers to cause a deniafreeradius · freeradius · CWE-787 | Kritik9,8 | — | %7,0 | 17 Tem 2017 |
41Planlayın | CVE-2017-10984İstismar yok | An FR-GV-301 issue in FreeRADIUS 3.x before 3.0.15 allows "Write overflow in data2vp_wimax()" - this allows remote attackers to cause a denifreeradius · freeradius · CWE-787 | Kritik9,8 | — | %6,4 | 17 Tem 2017 |
41Planlayın | CVE-2003-0968İstismar yok | Stack-based buffer overflow in SMB_Logon_Server of the rlm_smb experimental module for FreeRADIUS 0.9.3 and earlier allows remote attackers freeradius · freeradius | Kritik10,0 | — | %3,7 | 15 Ara 2003 |
40Planlayın | CVE-2024-3596Kavram kanıtı | RADIUS Protocol under RFC2865 is vulnerable to forgery attacks.freeradius · freeradius · CWE-354 | Kritik9,0 | — | %14,9 | 9 Tem 2024 |
40Planlayın | CVE-2017-9148İstismar yok | The TLS session cache in FreeRADIUS 2.1.1 through 2.1.7, 3.0.x before 3.0.14, 3.1.x before 2017-02-04, and 4.0.x before 2017-02-04 fails to freeradius · freeradius · CWE-287 | Kritik9,8 | — | %3,9 | 29 May 2017 |
40Planlayın | CVE-2019-11235İstismar yok | FreeRADIUS before 3.0.19 mishandles the "each participant verifies that the received scalar is within a range, and that the received group efreeradius · freeradius · CWE-345 | Kritik9,8 | — | %3,6 | 22 Nis 2019 |
33İzleyin | CVE-2001-1376İstismar yok | Buffer overflow in digest calculation function of multiple RADIUS implementations allows remote attackers to cause a denial of service and pascend · radius | Yüksek7,5 | — | %8,5 | 4 Mar 2002 |
32İzleyin | CVE-2005-4746İstismar yok | Multiple buffer overflows in FreeRADIUS 1.0.3 and 1.0.4 allow remote attackers to cause denial of service (crash) via (1) the rlm_sqlcounterfreeradius · freeradius | Yüksek7,8 | — | %2,4 | 31 Ara 2005 |
32İzleyin | CVE-2015-8763İstismar yok | The EAP-PWD module in FreeRADIUS 3.0 through 3.0.8 allows remote attackers to have unspecified impact via a crafted (1) commit or (2) confirfreeradius · freeradius · CWE-125 | Yüksek8,1 | — | %1,2 | 27 Mar 2017 |
32İzleyin | CVE-2015-8764İstismar yok | Off-by-one error in the EAP-PWD module in FreeRADIUS 3.0 through 3.0.8, which triggers a buffer overflow.freeradius · freeradius · CWE-119 | Yüksek8,1 | — | %1,1 | 27 Mar 2017 |
31İzleyin | CVE-2014-2015İstismar yok | Stack-based buffer overflow in the normify function in the rlm_pap module (modules/rlm_pap/rlm_pap.c) in FreeRADIUS 2.x, possibly 2.2.3 and freeradius · freeradius · CWE-119 | Yüksek7,5 | — | %3,9 | 1 Kas 2014 |
31İzleyin | CVE-2017-10982İstismar yok | An FR-GV-205 issue in FreeRADIUS 2.x before 2.2.10 allows "DHCP - Buffer over-read in fr_dhcp_decode_options()" and a denial of service.freeradius · freeradius · CWE-125 | Yüksek7,5 | — | %3,8 | 17 Tem 2017 |
31İzleyin | CVE-2017-10978İstismar yok | An FR-GV-201 issue in FreeRADIUS 2.x before 2.2.10 and 3.x before 3.0.15 allows "Read / write overflow in make_secret()" and a denial of serfreeradius · freeradius · CWE-119 | Yüksek7,5 | — | %3,8 | 17 Tem 2017 |
31İzleyin | CVE-2015-9542İstismar yok | add_password in pam_radius_auth.c in pam_radius 1.4.0 does not correctly check the length of the input password, and is vulnerable to a stacfreeradius · pam radius · CWE-787 | Yüksek7,5 | — | %3,5 | 24 Şub 2020 |
31İzleyin | CVE-2017-10983İstismar yok | An FR-GV-206 issue in FreeRADIUS 2.x before 2.2.10 and 3.x before 3.0.15 allows "DHCP - Read overflow when decoding option 63" and a denial freeradius · freeradius · CWE-119 | Yüksek7,5 | — | %3,4 | 17 Tem 2017 |
31İzleyin | CVE-2017-10981İstismar yok | An FR-GV-204 issue in FreeRADIUS 2.x before 2.2.10 allows "DHCP - Memory leak in fr_dhcp_decode()" and a denial of service.freeradius · freeradius · CWE-772 | Yüksek7,5 | — | %3,4 | 17 Tem 2017 |
31İzleyin | CVE-2017-10980İstismar yok | An FR-GV-203 issue in FreeRADIUS 2.x before 2.2.10 allows "DHCP - Memory leak in decode_tlv()" and a denial of service.freeradius · freeradius · CWE-772 | Yüksek7,5 | — | %3,4 | 17 Tem 2017 |
31İzleyin | CVE-2017-10985İstismar yok | An FR-GV-302 issue in FreeRADIUS 3.x before 3.0.15 allows "Infinite loop and memory exhaustion with 'concat' attributes" and a denial of serfreeradius · freeradius · CWE-835 | Yüksek7,5 | — | %3,3 | 17 Tem 2017 |
31İzleyin | CVE-2017-10986İstismar yok | An FR-GV-303 issue in FreeRADIUS 3.x before 3.0.15 allows "DHCP - Infinite read in dhcp_attr2vp()" and a denial of service.freeradius · freeradius · CWE-835 | Yüksek7,5 | — | %3,0 | 17 Tem 2017 |
31İzleyin | CVE-2017-10987İstismar yok | An FR-GV-304 issue in FreeRADIUS 3.x before 3.0.15 allows "DHCP - Buffer over-read in fr_dhcp_decode_suboptions()" and a denial of service.freeradius · freeradius · CWE-125 | Yüksek7,5 | — | %3,0 | 17 Tem 2017 |
31İzleyin | CVE-2006-1354İstismar yok | Unspecified vulnerability in FreeRADIUS 1.0.0 up to 1.1.0 allows remote attackers to bypass authentication or cause a denial of service (serfreeradius · freeradius | Yüksek7,5 | — | %2,8 | 21 Mar 2006 |
31İzleyin | CVE-2005-1455İstismar yok | Buffer overflow in the sql_escape_func function in the SQL module for FreeRADIUS 1.0.2 and earlier allows remote attackers to cause a denialfreeradius · freeradius | Yüksek7,5 | — | %2,5 | 19 May 2005 |
31İzleyin | CVE-2019-17185İstismar yok | In FreeRADIUS 3.0.x before 3.0.20, the EAP-pwd module used a global OpenSSL BN_CTX instance to handle all handshakes.freeradius · freeradius · CWE-662 | Yüksek7,5 | — | %2,2 | 20 Mar 2020 |
31İzleyin | CVE-2005-1454İstismar yok | SQL injection vulnerability in the radius_xlat function in the SQL module for FreeRADIUS 1.0.2 and earlier allows remote authenticated usersfreeradius · freeradius | Yüksek7,5 | — | %1,8 | 19 May 2005 |
- CVE-2019-1123441Planlayın
FreeRADIUS before 3.0.19 does not prevent use of reflection for authentication spoofing, aka a "Dragonblood" issue, a similar issue to CVE-2
KritikCVSS 9,8İstismar yokEPSS %8freeradius · freeradius22 Nis 2019
- CVE-2017-1097941Planlayın
An FR-GV-202 issue in FreeRADIUS 2.x before 2.2.10 allows "Write overflow in rad_coalesce()" - this allows remote attackers to cause a denia
KritikCVSS 9,8İstismar yokEPSS %7freeradius · freeradius17 Tem 2017
- CVE-2017-1098441Planlayın
An FR-GV-301 issue in FreeRADIUS 3.x before 3.0.15 allows "Write overflow in data2vp_wimax()" - this allows remote attackers to cause a deni
KritikCVSS 9,8İstismar yokEPSS %6freeradius · freeradius17 Tem 2017
- CVE-2003-096841Planlayın
Stack-based buffer overflow in SMB_Logon_Server of the rlm_smb experimental module for FreeRADIUS 0.9.3 and earlier allows remote attackers
KritikCVSS 10,0İstismar yokEPSS %4freeradius · freeradius15 Ara 2003
- CVE-2024-359640Planlayın
RADIUS Protocol under RFC2865 is vulnerable to forgery attacks.
KritikCVSS 9,0Kavram kanıtıEPSS %15freeradius · freeradius9 Tem 2024
- CVE-2017-914840Planlayın
The TLS session cache in FreeRADIUS 2.1.1 through 2.1.7, 3.0.x before 3.0.14, 3.1.x before 2017-02-04, and 4.0.x before 2017-02-04 fails to
KritikCVSS 9,8İstismar yokEPSS %4freeradius · freeradius29 May 2017
- CVE-2019-1123540Planlayın
FreeRADIUS before 3.0.19 mishandles the "each participant verifies that the received scalar is within a range, and that the received group e
KritikCVSS 9,8İstismar yokEPSS %4freeradius · freeradius22 Nis 2019
- CVE-2001-137633İzleyin
Buffer overflow in digest calculation function of multiple RADIUS implementations allows remote attackers to cause a denial of service and p
YüksekCVSS 7,5İstismar yokEPSS %9ascend · radius4 Mar 2002
- CVE-2005-474632İzleyin
Multiple buffer overflows in FreeRADIUS 1.0.3 and 1.0.4 allow remote attackers to cause denial of service (crash) via (1) the rlm_sqlcounter
YüksekCVSS 7,8İstismar yokEPSS %2freeradius · freeradius31 Ara 2005
- CVE-2015-876332İzleyin
The EAP-PWD module in FreeRADIUS 3.0 through 3.0.8 allows remote attackers to have unspecified impact via a crafted (1) commit or (2) confir
YüksekCVSS 8,1İstismar yokEPSS %1freeradius · freeradius27 Mar 2017
- CVE-2015-876432İzleyin
Off-by-one error in the EAP-PWD module in FreeRADIUS 3.0 through 3.0.8, which triggers a buffer overflow.
YüksekCVSS 8,1İstismar yokEPSS %1freeradius · freeradius27 Mar 2017
- CVE-2014-201531İzleyin
Stack-based buffer overflow in the normify function in the rlm_pap module (modules/rlm_pap/rlm_pap.c) in FreeRADIUS 2.x, possibly 2.2.3 and
YüksekCVSS 7,5İstismar yokEPSS %4freeradius · freeradius1 Kas 2014
- CVE-2017-1098231İzleyin
An FR-GV-205 issue in FreeRADIUS 2.x before 2.2.10 allows "DHCP - Buffer over-read in fr_dhcp_decode_options()" and a denial of service.
YüksekCVSS 7,5İstismar yokEPSS %4freeradius · freeradius17 Tem 2017
- CVE-2017-1097831İzleyin
An FR-GV-201 issue in FreeRADIUS 2.x before 2.2.10 and 3.x before 3.0.15 allows "Read / write overflow in make_secret()" and a denial of ser
YüksekCVSS 7,5İstismar yokEPSS %4freeradius · freeradius17 Tem 2017
- CVE-2015-954231İzleyin
add_password in pam_radius_auth.c in pam_radius 1.4.0 does not correctly check the length of the input password, and is vulnerable to a stac
YüksekCVSS 7,5İstismar yokEPSS %4freeradius · pam radius24 Şub 2020
- CVE-2017-1098331İzleyin
An FR-GV-206 issue in FreeRADIUS 2.x before 2.2.10 and 3.x before 3.0.15 allows "DHCP - Read overflow when decoding option 63" and a denial
YüksekCVSS 7,5İstismar yokEPSS %3freeradius · freeradius17 Tem 2017
- CVE-2017-1098131İzleyin
An FR-GV-204 issue in FreeRADIUS 2.x before 2.2.10 allows "DHCP - Memory leak in fr_dhcp_decode()" and a denial of service.
YüksekCVSS 7,5İstismar yokEPSS %3freeradius · freeradius17 Tem 2017
- CVE-2017-1098031İzleyin
An FR-GV-203 issue in FreeRADIUS 2.x before 2.2.10 allows "DHCP - Memory leak in decode_tlv()" and a denial of service.
YüksekCVSS 7,5İstismar yokEPSS %3freeradius · freeradius17 Tem 2017
- CVE-2017-1098531İzleyin
An FR-GV-302 issue in FreeRADIUS 3.x before 3.0.15 allows "Infinite loop and memory exhaustion with 'concat' attributes" and a denial of ser
YüksekCVSS 7,5İstismar yokEPSS %3freeradius · freeradius17 Tem 2017
- CVE-2017-1098631İzleyin
An FR-GV-303 issue in FreeRADIUS 3.x before 3.0.15 allows "DHCP - Infinite read in dhcp_attr2vp()" and a denial of service.
YüksekCVSS 7,5İstismar yokEPSS %3freeradius · freeradius17 Tem 2017
- CVE-2017-1098731İzleyin
An FR-GV-304 issue in FreeRADIUS 3.x before 3.0.15 allows "DHCP - Buffer over-read in fr_dhcp_decode_suboptions()" and a denial of service.
YüksekCVSS 7,5İstismar yokEPSS %3freeradius · freeradius17 Tem 2017
- CVE-2006-135431İzleyin
Unspecified vulnerability in FreeRADIUS 1.0.0 up to 1.1.0 allows remote attackers to bypass authentication or cause a denial of service (ser
YüksekCVSS 7,5İstismar yokEPSS %3freeradius · freeradius21 Mar 2006
- CVE-2005-145531İzleyin
Buffer overflow in the sql_escape_func function in the SQL module for FreeRADIUS 1.0.2 and earlier allows remote attackers to cause a denial
YüksekCVSS 7,5İstismar yokEPSS %3freeradius · freeradius19 May 2005
- CVE-2019-1718531İzleyin
In FreeRADIUS 3.0.x before 3.0.20, the EAP-pwd module used a global OpenSSL BN_CTX instance to handle all handshakes.
YüksekCVSS 7,5İstismar yokEPSS %2freeradius · freeradius20 Mar 2020
- CVE-2005-145431İzleyin
SQL injection vulnerability in the radius_xlat function in the SQL module for FreeRADIUS 1.0.2 and earlier allows remote authenticated users
YüksekCVSS 7,5İstismar yokEPSS %2freeradius · freeradius19 May 2005