Vulnerability index

Browse CVEs

32 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Frrouting MEDIUM 6.5
CVE-2026-37458

Missing input validation in the MP_REACH_NLRI component of FRRouting (FRR) stable/10.0 to stable/10.6 allows authenticated attackers to cause a Denia…

Fix: after 10.6.0
Fix from $1,600 2026-05-04
Frrouting HIGH 7.5
CVE-2026-37457

An off-by-one out-of-bounds write vulnerability in the bgp_flowspec_op_decode() function (bgpd/bgp_flowspec_util.c) of FRRouting (FRR) stable/10.0 al…

Patch available
Fix from $1,950 2026-05-01
Frrouting MEDIUM 6.5
CVE-2026-28532

FRRouting before 10.5.3 contains an integer overflow vulnerability in seven OSPF Traffic Engineering and Segment Routing TLV parser functions where a…

Fix: 10.5.3+
Fix from $1,600 2026-04-30
Frrouting HIGH 7.5
CVE-2025-61104

FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_unknown_tlv function at ospf_ext.c. Thi…

Fix: after 10.4.1
Fix from $1,950 2025-10-28
Frrouting HIGH 7.5
CVE-2025-61106

FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_pref_pref_sid function at ospf_ext.…

Fix: after 10.4.1
Fix from $1,950 2025-10-28
Frrouting HIGH 7.5
CVE-2025-61107

FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_pref_pref_sid function at ospf_ext.…

Fix: after 10.4.1
Fix from $1,950 2025-10-28
Frrouting HIGH 7.5
CVE-2025-61103

FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_link_lan_adj_sid function at ospf_e…

Fix: after 10.4.1
Fix from $1,950 2025-10-28
Frrouting HIGH 7.5
CVE-2025-61101

FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_link_rmt_itf_addr function at ospf_…

Fix: after 10.4.1
Fix from $1,950 2025-10-27
Frrouting HIGH 7.5
CVE-2025-61102

FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_link_adj_sid function at ospf_ext.c…

Fix: after 10.4.1
Fix from $1,950 2025-10-27
Frrouting HIGH 7.5
CVE-2025-61105

FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_link_info function at ospf_ext.c. This …

Fix: after 10.4.1
Fix from $1,950 2025-10-27
Frrouting HIGH 7.5
CVE-2025-61100

FRRouting/frr from v2.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the ospf_opaque_lsa_dump function at ospf_opaque.c. …

Fix: after 10.4.1
Fix from $1,950 2025-10-27
Frrouting HIGH 7.5
CVE-2025-61099

FRRouting/frr from v2.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the opaque_info_detail function at ospf_opaque.c. Th…

Fix: after 10.4.1
Fix from $1,950 2025-10-27
Frrouting HIGH 7.5
CVE-2024-34088

In FRRouting (FRR) through 9.1, it is possible for the get_edge() function in ospf_te.c in the OSPF daemon to return a NULL pointer. In cases where c…

Fix: after 9.1
Fix from $1,950 2024-04-30
Frrouting MEDIUM 6.5
CVE-2024-31948

In FRRouting (FRR) through 9.1, an attacker using a malformed Prefix SID attribute in a BGP UPDATE packet can cause the bgpd daemon to crash.

Fix: after 9.1
Fix from $1,600 2024-04-07
Frrouting MEDIUM 6.5
CVE-2024-31949

In FRRouting (FRR) through 9.1, an infinite loop can occur when receiving a MP/GR capability as a dynamic capability because malformed data results i…

Fix: after 9.1
Fix from $1,600 2024-04-07
Frrouting MEDIUM 6.5
CVE-2024-31950

In FRRouting (FRR) through 9.1, there can be a buffer overflow and daemon crash in ospf_te_parse_ri for OSPF LSA packets during an attempt to read Se…

Fix: after 9.1
Fix from $1,600 2024-04-07
Frrouting MEDIUM 6.5
CVE-2024-31951

In the Opaque LSA Extended Link parser in FRRouting (FRR) through 9.1, there can be a buffer overflow and daemon crash in ospf_te_parse_ext_link for …

Fix: after 9.1
Fix from $1,600 2024-04-07
Frrouting MEDIUM 6.5
CVE-2024-27913

ospf_te_parse_te in ospfd/ospf_te.c in FRRouting (FRR) through 9.1 allows remote attackers to cause a denial of service (ospfd daemon crash) via a ma…

Fix: 9.0+
Fix from $1,600 2024-02-28
Frrouting CRITICAL 9.8
CVE-2023-38406

bgpd/bgp_flowspec.c in FRRouting (FRR) before 8.4.3 mishandles an nlri length of zero, aka a "flowspec overflow."

Fix: 8.4.3+
Fix from $2,300 2023-11-06
Frrouting HIGH 7.5
CVE-2023-38407

bgpd/bgp_label.c in FRRouting (FRR) before 8.5 attempts to read beyond the end of the stream during labeled unicast parsing.

Fix: 8.5+
Fix from $1,950 2023-11-06
Frrouting HIGH 7.5
CVE-2023-47234

An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur when processing a crafted BGP UPDATE message with a MP_UNREACH_NLRI attribu…

Fix: after 9.0.1
Fix from $1,950 2023-11-03
Frrouting HIGH 7.5
CVE-2023-47235

An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur when a malformed BGP UPDATE message with an EOR is processed, because the p…

Fix: after 9.0.1
Fix from $1,950 2023-11-03
Frrouting MEDIUM 5.9
CVE-2023-46752

An issue was discovered in FRRouting FRR through 9.0.1. It mishandles malformed MP_REACH_NLRI data, leading to a crash.

Fix: after 9.0.1
Fix from $1,600 2023-10-26
Frrouting MEDIUM 5.9
CVE-2023-46753

An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur for a crafted BGP UPDATE message without mandatory attributes, e.g., one wi…

Fix: after 9.0.1
Fix from $1,600 2023-10-26
Frrouting HIGH 7.5
CVE-2023-3748

A flaw was found in FRRouting when parsing certain babeld unicast hello messages that are intended to be ignored. This issue may allow an attacker to…

Fix: 8.5+
Fix from $1,950 2023-07-24
Frrouting HIGH 8.1
CVE-2022-37035

An issue was discovered in bgpd in FRRouting (FRR) 8.3. In bgp_notify_send_with_data() and bgp_process_packet() in bgp_packet.c, there is a possible …

No fix yet
Fix from $1,950 2022-08-02
Frrouting HIGH 7.8
CVE-2022-26125

Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to wrong checks on the input packet length in isisd/isis_tlvs.c.

Fix: after 8.1
Fix from $1,950 2022-03-03
Frrouting HIGH 7.8
CVE-2022-26127

A buffer overflow vulnerability exists in FRRouting through 8.1.0 due to missing a check on the input packet length in the babel_packet_examin functi…

Fix: after 8.1
Fix from $1,950 2022-03-03
Frrouting HIGH 7.8
CVE-2022-26128

A buffer overflow vulnerability exists in FRRouting through 8.1.0 due to a wrong check on the input packet length in the babel_packet_examin function…

Fix: after 8.1
Fix from $1,950 2022-03-03
Frrouting HIGH 7.8
CVE-2022-26129

Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to wrong checks on the subtlv length in the functions, parse_hello_subtlv, parse…

Fix: after 8.1
Fix from $1,950 2022-03-03