Vulnerability index

Browse CVEs

37 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Freeradius MEDIUM 6.4
CVE-2005-4744

Off-by-one error in the sql_error function in sql_unixodbc.c in FreeRADIUS 1.0.2.5-5, and possibly other versions including 1.0.4, might allow remote…

Patch available
Fix from $1,600 2005-12-31
Freeradius HIGH 7.5
CVE-2005-1454

SQL injection vulnerability in the radius_xlat function in the SQL module for FreeRADIUS 1.0.2 and earlier allows remote authenticated users to execu…

Patch available
Fix from $1,950 2005-05-19
Freeradius HIGH 7.5
CVE-2005-1455

Buffer overflow in the sql_escape_func function in the SQL module for FreeRADIUS 1.0.2 and earlier allows remote attackers to cause a denial of servi…

Patch available
Fix from $1,950 2005-05-19
Freeradius MEDIUM 5.0
CVE-2004-0938

FreeRADIUS before 1.0.1 allows remote attackers to cause a denial of service (server crash) by sending an Ascend-Send-Secret attribute without the re…

Fix: after 1.0.1
Fix from $1,600 2004-11-03
Freeradius MEDIUM 5.0
CVE-2003-0967

rad_decode in FreeRADIUS 0.9.2 and earlier allows remote attackers to cause a denial of service (crash) via a short RADIUS string attribute with a ta…

Fix: after 0.9.2
Fix from $1,600 2003-12-15
Freeradius MEDIUM 5.0
CVE-2002-0318

FreeRADIUS RADIUS server allows remote attackers to cause a denial of service (CPU consumption) via a flood of Access-Request packets.

Mitigation only
Fix from $1,600 2002-06-25
Freeradius MEDIUM 5.0
CVE-2001-1377EPSS 5%

Multiple RADIUS implementations do not properly validate the Vendor-Length of the Vendor-Specific attribute, which allows remote attackers to cause a…

Patch available
Fix from $1,600 2002-03-04