Skip to main content

Vendor/product archive

xelerance / openswan CVEs

Beta · best-effort

16 CVEs tagged to xelerance / openswan0 Critical, 3 High, 12 Medium, 1 Low, 0 Unrated.

CVE-2018-15836

Published Sep 26, 2018

In verify_signed_hash() in lib/liboswkeys/signatures.c in Openswan before 2.6.50.1, the RSA implementation does not verify the value of padding string during PKCS#1 v1.5 signature…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-2037

Published Nov 26, 2014

Openswan 2.6.40 allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon restart) via IKEv2 packets that lack expected payloads. NOTE: this v…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6466

Published Jan 26, 2014

Openswan 2.6.39 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon restart) via IKEv2 packets that lack expected payloads.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-2053

Published Jul 9, 2013

Buffer overflow in the atodn function in Openswan before 2.6.39, when Opportunistic Encryption is enabled and an RSA key is being used, allows remote attackers to cause a denial o…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4073

Published Nov 17, 2011

Use-after-free vulnerability in the cryptographic helper handler functionality in Openswan 2.3.0 through 2.6.36 allows remote authenticated users to cause a denial of service (plu…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3380

Published Nov 17, 2011

Openswan 2.6.29 through 2.6.35 allows remote attackers to cause a denial of service (NULL pointer dereference and pluto IKE daemon crash) via an ISAKMP message with an invalid KEY…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3753

Published Oct 5, 2010

programs/pluto/xauth.c in the client in Openswan 2.6.26 through 2.6.28 allows remote authenticated gateways to execute arbitrary commands via shell metacharacters in the cisco_ban…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3752

Published Oct 5, 2010

programs/pluto/xauth.c in the client in Openswan 2.6.25 through 2.6.28 allows remote authenticated gateways to execute arbitrary commands via shell metacharacters in (1) cisco_dns…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3308

Published Oct 5, 2010

Buffer overflow in programs/pluto/xauth.c in the client in Openswan 2.6.26 through 2.6.28 might allow remote authenticated gateways to execute arbitrary code or cause a denial of…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3302

Published Oct 5, 2010

Buffer overflow in programs/pluto/xauth.c in the client in Openswan 2.6.25 through 2.6.28 might allow remote authenticated gateways to execute arbitrary code or cause a denial of…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2185

Published Jun 25, 2009

The ASN.1 parser (pluto/asn1.c, libstrongswan/asn1/asn1.c, libstrongswan/asn1/asn1_parser.c) in (a) strongSwan 2.8 before 2.8.10, 4.2 before 4.2.16, and 4.3 before 4.3.2; and (b)…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0790

Published Apr 1, 2009

The pluto IKE daemon in Openswan and Strongswan IPsec 2.6 before 2.6.21 and 2.4 before 2.4.14, and Strongswan 4.2 before 4.2.14 and 2.8 before 2.8.9, allows remote attackers to ca…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-4190

Published Sep 24, 2008

The IPSEC livetest tool in Openswan 2.4.12 and earlier, and 2.6.x through 2.6.16, allows local users to overwrite arbitrary files and execute arbitrary code via a symlink attack o…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0162

Published Jan 26, 2005

Stack-based buffer overflow in the get_internal_addresses function in the pluto application for Openswan 1.x before 1.0.9, and Openswan 2.x before 2.3.0, when compiled with XAUTH…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort
Showing 1-16 of 16 CVEsPage 1 of 1