Vulnerability index

Browse CVEs

37 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.0 CVE-2024-3596EPSS 15% RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject,… Freeradius 3.0.27+ Fix from $2,3002024-07-09 HIGH 7.5 CVE-2022-41859 In freeradius, the EAP-PWD function compute_password_element() leaks information about the password which allows an attacker to substantially reduce … Freeradius 3.0.0+ Fix from $1,9502023-01-17 HIGH 7.5 CVE-2022-41860 In freeradius, when an EAP-SIM supplicant sends an unknown SIM option, the server will try to look that option up in the internal dictionaries. This … Freeradius after 3.0.25 Fix from $1,9502023-01-17 MEDIUM 6.5 CVE-2022-41861 A flaw was found in freeradius. A malicious RADIUS client or home server can send a malformed abinary attribute which can cause the server to crash. Freeradius after 3.0.25 Fix from $1,6002023-01-17 HIGH 7.5 CVE-2019-17185 In FreeRADIUS 3.0.x before 3.0.20, the EAP-pwd module used a global OpenSSL BN_CTX instance to handle all handshakes. This mean multiple threads use … Freeradius 3.0.20+ Fix from $1,9502020-03-21 CRITICAL 9.8 CVE-2017-10979EPSS 7% An FR-GV-202 issue in FreeRADIUS 2.x before 2.2.10 allows "Write overflow in rad_coalesce()" - this allows remote attackers to cause a denial of serv… Freeradius Patch available Fix from $2,3002017-07-17 CRITICAL 9.8 CVE-2017-10984EPSS 6% An FR-GV-301 issue in FreeRADIUS 3.x before 3.0.15 allows "Write overflow in data2vp_wimax()" - this allows remote attackers to cause a denial of ser… Freeradius Patch available Fix from $2,3002017-07-17 HIGH 7.5 CVE-2017-10980 An FR-GV-203 issue in FreeRADIUS 2.x before 2.2.10 allows "DHCP - Memory leak in decode_tlv()" and a denial of service. Freeradius Patch available Fix from $1,9502017-07-17 HIGH 7.5 CVE-2017-10981 An FR-GV-204 issue in FreeRADIUS 2.x before 2.2.10 allows "DHCP - Memory leak in fr_dhcp_decode()" and a denial of service. Freeradius Patch available Fix from $1,9502017-07-17 HIGH 7.5 CVE-2017-10982 An FR-GV-205 issue in FreeRADIUS 2.x before 2.2.10 allows "DHCP - Buffer over-read in fr_dhcp_decode_options()" and a denial of service. Freeradius Patch available Fix from $1,9502017-07-17 HIGH 7.5 CVE-2017-10983 An FR-GV-206 issue in FreeRADIUS 2.x before 2.2.10 and 3.x before 3.0.15 allows "DHCP - Read overflow when decoding option 63" and a denial of servic… Freeradius Patch available Fix from $1,9502017-07-17 HIGH 7.5 CVE-2017-10985 An FR-GV-302 issue in FreeRADIUS 3.x before 3.0.15 allows "Infinite loop and memory exhaustion with 'concat' attributes" and a denial of service. Freeradius Patch available Fix from $1,9502017-07-17 HIGH 7.5 CVE-2017-10986 An FR-GV-303 issue in FreeRADIUS 3.x before 3.0.15 allows "DHCP - Infinite read in dhcp_attr2vp()" and a denial of service. Freeradius Patch available Fix from $1,9502017-07-17 HIGH 7.5 CVE-2017-10987 An FR-GV-304 issue in FreeRADIUS 3.x before 3.0.15 allows "DHCP - Buffer over-read in fr_dhcp_decode_suboptions()" and a denial of service. Freeradius Mitigation only Fix from $1,9502017-07-17 CRITICAL 9.8 CVE-2017-9148 The TLS session cache in FreeRADIUS 2.1.1 through 2.1.7, 3.0.x before 3.0.14, 3.1.x before 2017-02-04, and 4.0.x before 2017-02-04 fails to reliably … Freeradius Mitigation only Fix from $2,3002017-05-29 HIGH 7.5 CVE-2015-4680 FreeRADIUS 2.2.x before 2.2.8 and 3.0.x before 3.0.9 does not properly check revocation of intermediate CA certificates. Freeradius Patch available Fix from $1,9502017-04-05 HIGH 8.1 CVE-2015-8763 The EAP-PWD module in FreeRADIUS 3.0 through 3.0.8 allows remote attackers to have unspecified impact via a crafted (1) commit or (2) confirm message… Freeradius Patch available Fix from $1,9502017-03-27 HIGH 8.1 CVE-2015-8764 Off-by-one error in the EAP-PWD module in FreeRADIUS 3.0 through 3.0.8, which triggers a buffer overflow. Freeradius Patch available Fix from $1,9502017-03-27 MEDIUM 5.9 CVE-2015-8762 The EAP-PWD module in FreeRADIUS 3.0 through 3.0.8 allows remote attackers to cause a denial of service (NULL pointer dereference and server crash) v… Freeradius Patch available Fix from $1,6002017-03-27 HIGH 7.5 CVE-2014-2015 Stack-based buffer overflow in the normify function in the rlm_pap module (modules/rlm_pap/rlm_pap.c) in FreeRADIUS 2.x, possibly 2.2.3 and earlier, … Freeradius Patch available Fix from $1,9502014-11-02 MEDIUM 6.0 CVE-2011-4966 modules/rlm_unix/rlm_unix.c in FreeRADIUS before 2.2.0, when unix mode is enabled for user authentication, does not properly check the password expir… Freeradius after 2.2.0 Fix from $1,6002013-03-12 MEDIUM 6.8 CVE-2012-3547EPSS 6% Stack-based buffer overflow in the cbtls_verify function in FreeRADIUS 2.1.10 through 2.1.12, when using TLS-based EAP methods, allows remote attacke… Freeradius Mitigation only Fix from $1,6002012-09-18 MEDIUM 5.8 CVE-2011-2701 The ocsp_check function in rlm_eap_tls.c in FreeRADIUS 2.1.11, when OCSP is enabled, does not properly parse replies from OCSP responders, which allo… Freeradius Patch available Fix from $1,6002011-08-04 MEDIUM 5.0 CVE-2009-3111EPSS 11% The rad_decode function in FreeRADIUS before 1.1.8 allows remote attackers to cause a denial of service (radiusd crash) via zero-length Tunnel-Passwo… Freeradius after 1.1.7 Fix from $1,6002009-09-09 HIGH 7.2 CVE-2008-4474 freeradius-dialupadmin in freeradius 2.0.4 allows local users to overwrite arbitrary files via a symlink attack on temporary files in (1) backup_rada… Freeradius Mitigation only Fix from $1,9502008-10-07 MEDIUM 5.0 CVE-2007-2028 Memory leak in freeRADIUS 1.1.5 and earlier allows remote attackers to cause a denial of service (memory consumption) via a large number of EAP-TTLS … Freeradius after 1.1.5 Fix from $1,6002007-04-13 MEDIUM 6.6 CVE-2007-0080 Buffer overflow in the SMB_Connect_Server function in FreeRadius 1.1.3 and earlier allows attackers to execute arbitrary code related to the server d… Freeradius after 1.1.3 Fix from $1,6002007-01-05 HIGH 7.5 CVE-2006-1354 Unspecified vulnerability in FreeRADIUS 1.0.0 up to 1.1.0 allows remote attackers to bypass authentication or cause a denial of service (server crash… Freeradius Patch available Fix from $1,9502006-03-22 HIGH 7.8 CVE-2005-4746 Multiple buffer overflows in FreeRADIUS 1.0.3 and 1.0.4 allow remote attackers to cause denial of service (crash) via (1) the rlm_sqlcounter module o… Freeradius Patch available Fix from $1,9502005-12-31 HIGH 7.5 CVE-2005-4745 SQL injection vulnerability in the rlm_sqlcounter module in FreeRADIUS 1.0.3 and 1.0.4 allows remote attackers to execute arbitrary SQL commands via … Freeradius Mitigation only Fix from $1,9502005-12-31