Vulnerability index

Browse CVEs

13 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Hostapd HIGH 7.1
CVE-2026-58374

In hostapd before 2.12, a missing bounds check in AP-mode Wi-Fi 7 (IEEE 802.11be) Multi-Link Operation (MLO) association request processing allows an…

Fix: after 2.11
Fix from $1,950 2026-06-30
Hostapd MEDIUM 6.5
CVE-2022-37660

In hostapd 2.10 and earlier, the PKEX code remains active even after a successful PKEX association. An attacker that successfully bootstrapped public…

Fix: after 2.10
Fix from $1,600 2025-02-11
Wpa Supplicant HIGH 7.8
CVE-2024-5290

An issue was discovered in Ubuntu wpa_supplicant that resulted in loading of arbitrary shared objects, which allows a local unprivileged attacker to …

No fix yet
Fix from $1,950 2024-08-07
Hostapd MEDIUM 5.3
CVE-2021-30004

In wpa_supplicant and hostapd 2.9, forging attacks may occur because AlgorithmIdentifier parameters are mishandled in tls/pkcs1.c and tls/x509v3.c.

Patch available
Fix from $1,600 2021-04-02
Hostapd MEDIUM 6.5
CVE-2019-5061

An exploitable denial-of-service vulnerability exists in the hostapd 2.6, where an attacker could trigger AP to send IAPP location updates for statio…

Mitigation only
Fix from $1,600 2019-12-12
Hostapd MEDIUM 6.5
CVE-2019-5062

An exploitable denial-of-service vulnerability exists in the 802.11w security state handling for hostapd 2.6 connected clients with valid 802.11w ses…

Mitigation only
Fix from $1,600 2019-12-12
Hostapd MEDIUM 5.9
CVE-2019-11555

The EAP-pwd implementation in hostapd (EAP server) before 2.8 and wpa_supplicant (EAP peer) before 2.8 does not validate fragmentation reassembly sta…

Fix: 2.8+
Fix from $1,600 2019-04-26
Hostapd HIGH 7.5
CVE-2016-10743

hostapd before 2.6 does not prevent use of the low-quality PRNG that is reached by an os_random() function call.

Fix: 2.6+
Fix from $1,950 2019-03-23
Wpa Supplicant MEDIUM 5.9
CVE-2015-0210

wpa_supplicant 2.0-16 does not properly check certificate subject name, which allows remote attackers to cause a man-in-the-middle attack.

Patch available
Fix from $1,600 2017-08-28
Wpa Supplicant MEDIUM 5.0
CVE-2015-8041

Multiple integer overflows in the NDEF record parser in hostapd before 2.5 and wpa_supplicant before 2.5 allow remote attackers to cause a denial of …

Fix: after 2.4
Fix from $1,600 2015-11-09
Wpa Supplicant MEDIUM 5.0
CVE-2015-4146

The EAP-pwd peer implementation in hostapd and wpa_supplicant 1.0 through 2.4 does not clear the L (Length) and M (More) flags before determining if …

Patch available
Fix from $1,600 2015-06-15
Hostapd MEDIUM 5.0
CVE-2015-4145

The EAP-pwd server and peer implementation in hostapd and wpa_supplicant 1.0 through 2.4 does not validate a fragment is already being processed, whi…

Mitigation only
Fix from $1,600 2015-06-15
Wpa Supplicant MEDIUM 5.0
CVE-2015-4143

The EAP-pwd server and peer implementation in hostapd and wpa_supplicant 1.0 through 2.4 allows remote attackers to cause a denial of service (out-of…

Mitigation only
Fix from $1,600 2015-06-15