libreswan kayıtları
libreswan üreticisine ait 24 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 5
- Düzeltme kaydı olan
- %70,8
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-476 NULL Pointer Dereference5
- CWE-20 Improper Input Validation4
- CWE-400 Uncontrolled Resource Consumption3
- CWE-347 Improper Verification of Cryptographic Signature2
- CWE-189 Numeric Errors2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
24 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
37İzleyin | CVE-2013-7283İstismar yok | Race condition in the libreswan.spec files for Red Hat Enterprise Linux (RHEL) and Fedora packages in libreswan 3.6 has unspecified impact alibreswan · libreswan · CWE-362 | Kritik9,3 | — | %1,6 | 9 Oca 2014 |
31İzleyin | CVE-2020-1763İstismar yok | An out-of-bounds buffer read flaw was found in the pluto daemon of libreswan from versions 3.27 till 3.31 where, an unauthenticated attackerlibreswan · libreswan · CWE-125 | Yüksek7,5 | — | %3,6 | 12 May 2020 |
31İzleyin | CVE-2016-5391İstismar yok | libreswan before 3.18 allows remote attackers to cause a denial of service (NULL pointer dereference and pluto daemon restart).libreswan · libreswan · CWE-476 | Yüksek7,5 | — | %3,0 | 13 Haz 2017 |
31İzleyin | CVE-2019-12312İstismar yok | In Libreswan 3.27 an assertion failure can lead to a pluto IKE daemon restart.libreswan · libreswan · CWE-476 | Yüksek7,5 | — | %2,7 | 24 May 2019 |
31İzleyin | CVE-2016-5361İstismar yok | programs/pluto/ikev1.c in libreswan before 3.17 retransmits in initial-responder states, which allows remote attackers to cause a denial of libreswan · libreswan · CWE-20 | Yüksek7,5 | — | %2,7 | 16 Haz 2016 |
31İzleyin | CVE-2016-3071İstismar yok | Libreswan 3.16 might allow remote attackers to cause a denial of service (daemon restart) via an IKEv2 aes_xcbc transform.libreswan · libreswan · CWE-20 | Yüksek7,5 | — | %2,6 | 18 Nis 2016 |
31İzleyin | CVE-2022-23094İstismar yok | Libreswan 4.2 through 4.5 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted IKElibreswan · libreswan · CWE-476 | Yüksek7,5 | — | %2,5 | 14 Oca 2022 |
30İzleyin | CVE-2023-2295İstismar yok | A vulnerability was found in the libreswan library.libreswan · libreswan · CWE-400 | Yüksek7,5 | — | %1,6 | 17 May 2023 |
30İzleyin | CVE-2023-30570İstismar yok | pluto in Libreswan before 4.11 allows a denial of service (responder SPI mishandling and daemon crash) via unauthenticated IKEv1 Aggressive libreswan · libreswan · CWE-400 | Yüksek7,5 | — | %1,2 | 28 May 2023 |
30İzleyin | CVE-2026-12413İstismar yok | IKEv2 Denial of Service via malformed fragmentationlibreswan · libreswan · CWE-193 | Yüksek7,5 | — | %0,6 | 2 Tem 2026 |
26İzleyin | CVE-2023-23009İstismar yok | Libreswan 4.9 allows remote attackers to cause a denial of service (assert failure and daemon restart) via crafted TS payload with an incorrlibreswan · libreswan · CWE-400 | Orta6,5 | — | %1,6 | 21 Şub 2023 |
26İzleyin | CVE-2023-38710İstismar yok | An issue was discovered in Libreswan before 4.12.libreswan · libreswan | Orta6,5 | — | %0,8 | 25 Ağu 2023 |
26İzleyin | CVE-2023-38712İstismar yok | An issue was discovered in Libreswan 3.x and 4.x before 4.12.libreswan · libreswan · CWE-476 | Orta6,5 | — | %0,8 | 25 Ağu 2023 |
26İzleyin | CVE-2023-38711İstismar yok | An issue was discovered in Libreswan before 4.12.libreswan · libreswan · CWE-476 | Orta6,5 | — | %0,8 | 25 Ağu 2023 |
26İzleyin | CVE-2024-3652İstismar yok | IKEv1 default AH/ESP responder can cause libreswan to abort and restartlibreswan · libreswan · CWE-404 | Orta6,5 | — | %0,8 | 10 Nis 2024 |
23İzleyin | CVE-2026-50721İstismar yok | IKEv1 Denial of Service via RSA-SHA1 (PKCS#1 Version 1.5 Encrypted) authentication payloadlibreswan · libreswan · CWE-347 | Orta5,9 | — | %0,4 | 2 Tem 2026 |
23İzleyin | CVE-2026-50722İstismar yok | IKEv2 Denial of Service via RSA-SHA1 (PKCS#1 RSASSA-PKCS1-v1_5) authentication payloadlibreswan · libreswan · CWE-347 | Orta5,9 | — | %0,3 | 2 Tem 2026 |
21İzleyin | CVE-2013-4564İstismar yok | Libreswan 3.6 allows remote attackers to cause a denial of service (crash) via a small length value and (1) no version or (2) an invalid majlibreswan · libreswan · CWE-189 | Orta5,0 | — | %2,7 | 7 Oca 2014 |
21İzleyin | CVE-2015-3204İstismar yok | libreswan 3.9 through 3.12 allows remote attackers to cause a denial of service (daemon restart) via an IKEv1 packet with (1) unassigned bitlibreswan · libreswan · CWE-20 | Orta5,0 | — | %2,6 | 1 Tem 2015 |
21İzleyin | CVE-2013-7294İstismar yok | The ikev2parent_inI1outR1 function in pluto/ikev2_parent.c in libreswan before 3.7 allows remote attackers to cause a denial of service (reslibreswan · libreswan · CWE-20 | Orta5,0 | — | %2,5 | 16 Oca 2014 |
21İzleyin | CVE-2013-6467İstismar yok | Libreswan 3.7 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon restart) via IKEv2 plibreswan · libreswan | Orta5,0 | — | %2,5 | 26 Oca 2014 |
21İzleyin | CVE-2013-2052İstismar yok | Buffer overflow in the atodn function in libreswan 3.0 and 3.1, when Opportunistic Encryption is enabled and an RSA key is being used, allowlibreswan · libreswan · CWE-119 | Orta5,1 | — | %1,8 | 9 Tem 2013 |
18İzleyin | CVE-2015-3240İstismar yok | The pluto IKE daemon in libreswan before 3.15 and Openswan before 2.6.45, when built with NSS, allows remote attackers to cause a denial of libreswan · libreswan · CWE-189 | Orta4,3 | — | %2,8 | 9 Kas 2015 |
12İzleyin | CVE-2019-10155İstismar yok | The Libreswan Project has found a vulnerability in the processing of IKEv1 informational exchange packets which are encrypted and integrity libreswan · libreswan · CWE-354 | Düşük3,1 | — | %0,5 | 12 Haz 2019 |
- CVE-2013-728337İzleyin
Race condition in the libreswan.spec files for Red Hat Enterprise Linux (RHEL) and Fedora packages in libreswan 3.6 has unspecified impact a
KritikCVSS 9,3İstismar yokEPSS %2libreswan · libreswan9 Oca 2014
- CVE-2020-176331İzleyin
An out-of-bounds buffer read flaw was found in the pluto daemon of libreswan from versions 3.27 till 3.31 where, an unauthenticated attacker
YüksekCVSS 7,5İstismar yokEPSS %4libreswan · libreswan12 May 2020
- CVE-2016-539131İzleyin
libreswan before 3.18 allows remote attackers to cause a denial of service (NULL pointer dereference and pluto daemon restart).
YüksekCVSS 7,5İstismar yokEPSS %3libreswan · libreswan13 Haz 2017
- CVE-2019-1231231İzleyin
In Libreswan 3.27 an assertion failure can lead to a pluto IKE daemon restart.
YüksekCVSS 7,5İstismar yokEPSS %3libreswan · libreswan24 May 2019
- CVE-2016-536131İzleyin
programs/pluto/ikev1.c in libreswan before 3.17 retransmits in initial-responder states, which allows remote attackers to cause a denial of
YüksekCVSS 7,5İstismar yokEPSS %3libreswan · libreswan16 Haz 2016
- CVE-2016-307131İzleyin
Libreswan 3.16 might allow remote attackers to cause a denial of service (daemon restart) via an IKEv2 aes_xcbc transform.
YüksekCVSS 7,5İstismar yokEPSS %3libreswan · libreswan18 Nis 2016
- CVE-2022-2309431İzleyin
Libreswan 4.2 through 4.5 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted IKE
YüksekCVSS 7,5İstismar yokEPSS %3libreswan · libreswan14 Oca 2022
- CVE-2023-229530İzleyin
A vulnerability was found in the libreswan library.
YüksekCVSS 7,5İstismar yokEPSS %2libreswan · libreswan17 May 2023
- CVE-2023-3057030İzleyin
pluto in Libreswan before 4.11 allows a denial of service (responder SPI mishandling and daemon crash) via unauthenticated IKEv1 Aggressive
YüksekCVSS 7,5İstismar yokEPSS %1libreswan · libreswan28 May 2023
- CVE-2026-1241330İzleyin
IKEv2 Denial of Service via malformed fragmentation
YüksekCVSS 7,5İstismar yokEPSS %1libreswan · libreswan2 Tem 2026
- CVE-2023-2300926İzleyin
Libreswan 4.9 allows remote attackers to cause a denial of service (assert failure and daemon restart) via crafted TS payload with an incorr
OrtaCVSS 6,5İstismar yokEPSS %2libreswan · libreswan21 Şub 2023
- CVE-2023-3871026İzleyin
An issue was discovered in Libreswan before 4.12.
OrtaCVSS 6,5İstismar yokEPSS %1libreswan · libreswan25 Ağu 2023
- CVE-2023-3871226İzleyin
An issue was discovered in Libreswan 3.x and 4.x before 4.12.
OrtaCVSS 6,5İstismar yokEPSS %1libreswan · libreswan25 Ağu 2023
- CVE-2023-3871126İzleyin
An issue was discovered in Libreswan before 4.12.
OrtaCVSS 6,5İstismar yokEPSS %1libreswan · libreswan25 Ağu 2023
- CVE-2024-365226İzleyin
IKEv1 default AH/ESP responder can cause libreswan to abort and restart
OrtaCVSS 6,5İstismar yokEPSS %1libreswan · libreswan10 Nis 2024
- CVE-2026-5072123İzleyin
IKEv1 Denial of Service via RSA-SHA1 (PKCS#1 Version 1.5 Encrypted) authentication payload
OrtaCVSS 5,9İstismar yokEPSS %0libreswan · libreswan2 Tem 2026
- CVE-2026-5072223İzleyin
IKEv2 Denial of Service via RSA-SHA1 (PKCS#1 RSASSA-PKCS1-v1_5) authentication payload
OrtaCVSS 5,9İstismar yokEPSS %0libreswan · libreswan2 Tem 2026
- CVE-2013-456421İzleyin
Libreswan 3.6 allows remote attackers to cause a denial of service (crash) via a small length value and (1) no version or (2) an invalid maj
OrtaCVSS 5,0İstismar yokEPSS %3libreswan · libreswan7 Oca 2014
- CVE-2015-320421İzleyin
libreswan 3.9 through 3.12 allows remote attackers to cause a denial of service (daemon restart) via an IKEv1 packet with (1) unassigned bit
OrtaCVSS 5,0İstismar yokEPSS %3libreswan · libreswan1 Tem 2015
- CVE-2013-729421İzleyin
The ikev2parent_inI1outR1 function in pluto/ikev2_parent.c in libreswan before 3.7 allows remote attackers to cause a denial of service (res
OrtaCVSS 5,0İstismar yokEPSS %3libreswan · libreswan16 Oca 2014
- CVE-2013-646721İzleyin
Libreswan 3.7 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon restart) via IKEv2 p
OrtaCVSS 5,0İstismar yokEPSS %2libreswan · libreswan26 Oca 2014
- CVE-2013-205221İzleyin
Buffer overflow in the atodn function in libreswan 3.0 and 3.1, when Opportunistic Encryption is enabled and an RSA key is being used, allow
OrtaCVSS 5,1İstismar yokEPSS %2libreswan · libreswan9 Tem 2013
- CVE-2015-324018İzleyin
The pluto IKE daemon in libreswan before 3.15 and Openswan before 2.6.45, when built with NSS, allows remote attackers to cause a denial of
OrtaCVSS 4,3İstismar yokEPSS %3libreswan · libreswan9 Kas 2015
- CVE-2019-1015512İzleyin
The Libreswan Project has found a vulnerability in the processing of IKEv1 informational exchange packets which are encrypted and integrity
DüşükCVSS 3,1İstismar yokEPSS %1libreswan · libreswan12 Haz 2019