Vulnerability index

Browse CVEs

13 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.1 CVE-2026-58374 In hostapd before 2.12, a missing bounds check in AP-mode Wi-Fi 7 (IEEE 802.11be) Multi-Link Operation (MLO) association request processing allows an… Hostapd after 2.11 Fix from $1,9502026-06-30 MEDIUM 6.5 CVE-2022-37660 In hostapd 2.10 and earlier, the PKEX code remains active even after a successful PKEX association. An attacker that successfully bootstrapped public… Hostapd after 2.10 Fix from $1,6002025-02-11 HIGH 7.8 CVE-2024-5290 An issue was discovered in Ubuntu wpa_supplicant that resulted in loading of arbitrary shared objects, which allows a local unprivileged attacker to … Wpa Supplicant No fix yet Fix from $1,9502024-08-07 MEDIUM 5.3 CVE-2021-30004 In wpa_supplicant and hostapd 2.9, forging attacks may occur because AlgorithmIdentifier parameters are mishandled in tls/pkcs1.c and tls/x509v3.c. Hostapd Patch available Fix from $1,6002021-04-02 MEDIUM 6.5 CVE-2019-5061 An exploitable denial-of-service vulnerability exists in the hostapd 2.6, where an attacker could trigger AP to send IAPP location updates for statio… Hostapd Mitigation only Fix from $1,6002019-12-12 MEDIUM 6.5 CVE-2019-5062 An exploitable denial-of-service vulnerability exists in the 802.11w security state handling for hostapd 2.6 connected clients with valid 802.11w ses… Hostapd Mitigation only Fix from $1,6002019-12-12 MEDIUM 5.9 CVE-2019-11555 The EAP-pwd implementation in hostapd (EAP server) before 2.8 and wpa_supplicant (EAP peer) before 2.8 does not validate fragmentation reassembly sta… Hostapd 2.8+ Fix from $1,6002019-04-26 HIGH 7.5 CVE-2016-10743 hostapd before 2.6 does not prevent use of the low-quality PRNG that is reached by an os_random() function call. Hostapd 2.6+ Fix from $1,9502019-03-23 MEDIUM 5.9 CVE-2015-0210 wpa_supplicant 2.0-16 does not properly check certificate subject name, which allows remote attackers to cause a man-in-the-middle attack. Wpa Supplicant Patch available Fix from $1,6002017-08-28 MEDIUM 5.0 CVE-2015-8041 Multiple integer overflows in the NDEF record parser in hostapd before 2.5 and wpa_supplicant before 2.5 allow remote attackers to cause a denial of … Wpa Supplicant after 2.4 Fix from $1,6002015-11-09 MEDIUM 5.0 CVE-2015-4146 The EAP-pwd peer implementation in hostapd and wpa_supplicant 1.0 through 2.4 does not clear the L (Length) and M (More) flags before determining if … Wpa Supplicant Patch available Fix from $1,6002015-06-15 MEDIUM 5.0 CVE-2015-4145 The EAP-pwd server and peer implementation in hostapd and wpa_supplicant 1.0 through 2.4 does not validate a fragment is already being processed, whi… Hostapd Mitigation only Fix from $1,6002015-06-15 MEDIUM 5.0 CVE-2015-4143 The EAP-pwd server and peer implementation in hostapd and wpa_supplicant 1.0 through 2.4 allows remote attackers to cause a denial of service (out-of… Wpa Supplicant Mitigation only Fix from $1,6002015-06-15