Search
Total
7 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2013-7294 | 1 Libreswan | 1 Libreswan | 2018-01-03 | 5.0 MEDIUM | N/A |
| The ikev2parent_inI1outR1 function in pluto/ikev2_parent.c in libreswan before 3.7 allows remote attackers to cause a denial of service (restart) via an IKEv2 I1 notification without a KE payload. | |||||
| CVE-2013-6467 | 1 Libreswan | 1 Libreswan | 2017-08-29 | 5.0 MEDIUM | N/A |
| Libreswan 3.7 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon restart) via IKEv2 packets that lack expected payloads. | |||||
| CVE-2015-3240 | 1 Libreswan | 1 Libreswan | 2016-12-03 | 4.3 MEDIUM | N/A |
| The pluto IKE daemon in libreswan before 3.15 and Openswan before 2.6.45, when built with NSS, allows remote attackers to cause a denial of service (assertion failure and daemon restart) via a zero DH g^x value in a KE payload in a IKE packet. | |||||
| CVE-2015-3204 | 1 Libreswan | 1 Libreswan | 2016-12-03 | 5.0 MEDIUM | N/A |
| libreswan 3.9 through 3.12 allows remote attackers to cause a denial of service (daemon restart) via an IKEv1 packet with (1) unassigned bits set in the IPSEC DOI value or (2) the next payload value set to ISAKMP_NEXT_SAK. | |||||
| CVE-2013-4564 | 1 Libreswan | 1 Libreswan | 2014-02-25 | 5.0 MEDIUM | N/A |
| Libreswan 3.6 allows remote attackers to cause a denial of service (crash) via a small length value and (1) no version or (2) an invalid major number in an IKE packet. | |||||
| CVE-2013-7283 | 1 Libreswan | 1 Libreswan | 2014-01-10 | 9.3 HIGH | N/A |
| Race condition in the libreswan.spec files for Red Hat Enterprise Linux (RHEL) and Fedora packages in libreswan 3.6 has unspecified impact and attack vectors, involving the /var/tmp/libreswan-nss-pwd temporary file. | |||||
| CVE-2013-2052 | 1 Libreswan | 1 Libreswan | 2013-10-11 | 5.1 MEDIUM | N/A |
| Buffer overflow in the atodn function in libreswan 3.0 and 3.1, when Opportunistic Encryption is enabled and an RSA key is being used, allows remote attackers to cause a denial of service (pluto IKE daemon crash) and possibly execute arbitrary code via crafted DNS TXT records. NOTE: this might be the same vulnerability as CVE-2013-2053 and CVE-2013-2054. | |||||
