Vulnerability index

Browse CVEs

17 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Quagga HIGH 7.8
CVE-2021-44038

An issue was discovered in Quagga through 1.2.4. Unsafe chown/chmod operations in the suggested spec file allow users (with control of the non-root-o…

Fix: after 1.2.4
Fix from $1,950 2021-11-19
Quagga HIGH 7.5
CVE-2017-5495EPSS 19%

All versions of Quagga, 0.93 through 1.1.0, are vulnerable to an unbounded memory allocation in the telnet 'vty' CLI, leading to a Denial-of-Service …

Fix: after 1.1.0
Fix from $1,950 2017-01-24
Quagga HIGH 7.5
CVE-2016-4049

The bgp_dump_routes_func function in bgpd/bgp_dump.c in Quagga does not perform size checks when dumping data, which might allow remote attackers to …

Mitigation only
Fix from $1,950 2016-05-23
Quagga MEDIUM 5.0
CVE-2012-0255

The BGP implementation in bgpd in Quagga before 0.99.20.1 does not properly use message buffers for OPEN messages, which allows remote attackers to c…

Fix: after 0.99.20
Fix from $1,600 2012-04-05
Quagga HIGH 7.5
CVE-2011-3327EPSS 8%

Heap-based buffer overflow in the ecommunity_ecom2str function in bgp_ecommunity.c in bgpd in Quagga before 0.99.19 allows remote attackers to cause …

Fix: after 0.99.18
Fix from $1,950 2011-10-10
Quagga MEDIUM 5.0
CVE-2011-3323

The OSPFv3 implementation in ospf6d in Quagga before 0.99.19 allows remote attackers to cause a denial of service (out-of-bounds memory access and da…

Fix: after 0.99.18
Fix from $1,600 2011-10-10
Quagga MEDIUM 5.0
CVE-2011-3324

The ospf6_lsa_is_changed function in ospf6_lsa.c in the OSPFv3 implementation in ospf6d in Quagga before 0.99.19 allows remote attackers to cause a d…

Fix: after 0.99.18
Fix from $1,600 2011-10-10
Quagga MEDIUM 5.0
CVE-2011-3325

ospf_packet.c in ospfd in Quagga before 0.99.19 allows remote attackers to cause a denial of service (daemon crash) via (1) a 0x0a type field in an I…

Fix: after 0.99.18
Fix from $1,600 2011-10-10
Quagga MEDIUM 5.0
CVE-2011-3326

The ospf_flood function in ospf_flood.c in ospfd in Quagga before 0.99.19 allows remote attackers to cause a denial of service (daemon crash) via an …

Fix: after 0.99.18
Fix from $1,600 2011-10-10
Quagga MEDIUM 5.0
CVE-2010-1674EPSS 13%

The extended-community parser in bgpd in Quagga before 0.99.18 allows remote attackers to cause a denial of service (NULL pointer dereference and app…

Fix: after 0.99.17
Fix from $1,600 2011-03-29
Quagga MEDIUM 5.0
CVE-2010-1675

bgpd in Quagga before 0.99.18 allows remote attackers to cause a denial of service (session reset) via a malformed AS_PATHLIMIT path attribute.

Fix: after 0.99.17
Fix from $1,600 2011-03-29
Quagga MEDIUM 6.5
CVE-2010-2948

Stack-based buffer overflow in the bgp_route_refresh_receive function in bgp_packet.c in bgpd in Quagga before 0.99.17 allows remote authenticated us…

Fix: after 0.99.16
Fix from $1,600 2010-09-10
Quagga MEDIUM 5.0
CVE-2010-2949

bgpd in Quagga before 0.99.17 does not properly parse AS paths, which allows remote attackers to cause a denial of service (NULL pointer dereference …

Fix: after 0.99.16
Fix from $1,600 2010-09-10
Quagga MEDIUM 5.0
CVE-2009-1572

The BGP daemon (bgpd) in Quagga 0.99.11 and earlier allows remote attackers to cause a denial of service (crash) via an AS path containing ASN elemen…

Fix: after 0.99.11
Fix from $1,600 2009-05-06
Quagga MEDIUM 6.3
CVE-2007-1995

bgpd/bgp_attr.c in Quagga 0.98.6 and earlier, and 0.99.6 and earlier 0.99 versions, does not validate length values in the MP_REACH_NLRI and MP_UNREA…

Fix: after 0.98.6
Fix from $1,600 2007-04-12
Quagga MEDIUM 5.0
CVE-2006-2223EPSS 11%

RIPd in Quagga 0.98 and 0.99 before 20060503 does not properly implement configurations that (1) disable RIPv1 or (2) require plaintext or MD5 authen…

Patch available
Fix from $1,600 2006-05-05
Quagga Routing Software Suite MEDIUM 5.0
CVE-2006-2224EPSS 10%

RIPd in Quagga 0.98 and 0.99 before 20060503 does not properly enforce RIPv2 authentication requirements, which allows remote attackers to modify rou…

Fix: after 0.99.3
Fix from $1,600 2006-05-05