Vulnerabilities (CVE)

Filtered by vendor Opennds Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-41102 1 Opennds 1 Opennds 2023-11-25 N/A 7.5 HIGH
An issue was discovered in the captive portal in OpenNDS before version 10.1.3. It has multiple memory leaks due to not freeing up allocated memory. This may lead to a Denial-of-Service condition due to the consumption of all available memory.
CVE-2023-38322 1 Opennds 1 Captive Portal 2023-11-23 N/A 7.5 HIGH
An issue was discovered in OpenNDS Captive Portal before version 10.1.2. It has a do_binauth NULL pointer dereference that be triggered with a crafted GET HTTP request with a missing User-Agent HTTP header. Triggering this issue results in crashing OpenNDS (a Denial-of-Service condition). The issue occurs when the client is about to be authenticated, and can be triggered only when the BinAuth option is set.
CVE-2023-38313 1 Opennds 1 Captive Portal 2023-11-23 N/A 7.5 HIGH
An issue was discovered in OpenNDS Captive Portal before 10.1.2. it has a do_binauth NULL pointer dereference that can be triggered with a crafted GET HTTP request with a missing client redirect query string parameter. Triggering this issue results in crashing openNDS (a Denial-of-Service condition). The issue occurs when the client is about to be authenticated, and can be triggered only when the BinAuth option is set.
CVE-2023-38320 1 Opennds 1 Captive Portal 2023-11-23 N/A 7.5 HIGH
An issue was discovered in OpenNDS Captive Portal before version 10.1.2. It has a show_preauthpage NULL pointer dereference that can be triggered with a crafted GET HTTP with a missing User-Agent header. Triggering this issue results in crashing OpenNDS (a Denial-of-Service condition).
CVE-2023-38315 1 Opennds 1 Captive Portal 2023-11-23 N/A 7.5 HIGH
An issue was discovered in OpenNDS Captive Portal before version 10.1.2. It has a try_to_authenticate NULL pointer dereference that can be triggered with a crafted GET HTTP with a missing client token query string parameter. Triggering this issue results in crashing OpenNDS (a Denial-of-Service condition).