Vulnerability index

Browse CVEs

17 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Libreswan MEDIUM 5.9
CVE-2026-50721

Libreswan, via the function RSA_authenticate_hash_signature_raw_rsa(), did not correctly verify the length of the authentication hash when the SIG pa…

Fix: 5.3.1+
Fix from $1,600 2026-07-02
Libreswan MEDIUM 5.9
CVE-2026-50722

Libreswan, via the function RSA_authenticate_hash_signature_pkcs1_1_5_rsa(), did not correctly verify the DER encoding of the ASN.1 digest when the I…

Fix: 5.3.1+
Fix from $1,600 2026-07-02
Libreswan HIGH 7.5
CVE-2026-12413

An invalidly formatted IKEv2 fragment causes the Libreswan pluto daemon to crash and restart. Continued exploitation would cause a denial of service.…

Fix: 5.3.1+
Fix from $1,950 2026-07-02
Libreswan MEDIUM 6.5
CVE-2024-3652

The Libreswan Project was notified of an issue causing libreswan to restart when using IKEv1 without specifying an esp= line. When the peer requests …

Fix: 4.15+
Fix from $1,600 2024-04-11
Libreswan MEDIUM 6.5
CVE-2023-38710

An issue was discovered in Libreswan before 4.12. When an IKEv2 Child SA REKEY packet contains an invalid IPsec protocol ID number of 0 or 1, an erro…

Fix: 4.12+
Fix from $1,600 2023-08-25
Libreswan MEDIUM 6.5
CVE-2023-38711

An issue was discovered in Libreswan before 4.12. When an IKEv1 Quick Mode connection configured with ID_IPV4_ADDR or ID_IPV6_ADDR receives an IDcr p…

Fix: 4.12+
Fix from $1,600 2023-08-25
Libreswan MEDIUM 6.5
CVE-2023-38712

An issue was discovered in Libreswan 3.x and 4.x before 4.12. When an IKEv1 ISAKMP SA Informational Exchange packet contains a Delete/Notify payload …

Fix: 4.0 / 4.12+
Fix from $1,600 2023-08-25
Libreswan HIGH 7.5
CVE-2023-30570

pluto in Libreswan before 4.11 allows a denial of service (responder SPI mishandling and daemon crash) via unauthenticated IKEv1 Aggressive Mode pack…

Fix: after 4.10
Fix from $1,950 2023-05-29
Libreswan HIGH 7.5
CVE-2020-1763

An out-of-bounds buffer read flaw was found in the pluto daemon of libreswan from versions 3.27 till 3.31 where, an unauthenticated attacker could us…

Fix: after 3.31
Fix from $1,950 2020-05-12
Libreswan HIGH 7.5
CVE-2019-12312

In Libreswan 3.27 an assertion failure can lead to a pluto IKE daemon restart. An attacker can trigger a NULL pointer dereference by initiating an IK…

Fix: 3.28+
Fix from $1,950 2019-05-24
Libreswan HIGH 7.5
CVE-2016-5361

programs/pluto/ikev1.c in libreswan before 3.17 retransmits in initial-responder states, which allows remote attackers to cause a denial of service (…

Fix: after 3.16
Fix from $1,950 2016-06-16
Libreswan MEDIUM 5.0
CVE-2015-3204

libreswan 3.9 through 3.12 allows remote attackers to cause a denial of service (daemon restart) via an IKEv1 packet with (1) unassigned bits set in …

Mitigation only
Fix from $1,600 2015-07-01
Libreswan MEDIUM 5.0
CVE-2013-6467

Libreswan 3.7 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon restart) via IKEv2 packets th…

Fix: after 3.7
Fix from $1,600 2014-01-26
Libreswan MEDIUM 5.0
CVE-2013-7294

The ikev2parent_inI1outR1 function in pluto/ikev2_parent.c in libreswan before 3.7 allows remote attackers to cause a denial of service (restart) via…

Fix: after 3.6
Fix from $1,600 2014-01-16
Libreswan HIGH 9.3
CVE-2013-7283

Race condition in the libreswan.spec files for Red Hat Enterprise Linux (RHEL) and Fedora packages in libreswan 3.6 has unspecified impact and attack…

Patch available
Fix from $1,950 2014-01-09
Libreswan MEDIUM 5.0
CVE-2013-4564

Libreswan 3.6 allows remote attackers to cause a denial of service (crash) via a small length value and (1) no version or (2) an invalid major number…

Patch available
Fix from $1,600 2014-01-07
Libreswan MEDIUM 5.1
CVE-2013-2052

Buffer overflow in the atodn function in libreswan 3.0 and 3.1, when Opportunistic Encryption is enabled and an RSA key is being used, allows remote …

Patch available
Fix from $1,600 2013-07-09