Madwifi

Madwifi

10 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 2.45%
  • Veröffentlicht 14.10.2007 18:17:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Madwifi 0.9.3.2 and earlier allows remote attackers to cause a denial of service (panic) via a beacon frame with a large length value in the extended supported rates (xrates) element, which triggers an assertion error, related to net80211/ieee80211_s...

  • EPSS 4.63%
  • Veröffentlicht 24.05.2007 02:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The 802.11 network stack in net80211/ieee80211_input.c in MadWifi before 0.9.3.1 allows remote attackers to cause a denial of service (system hang) via a crafted length field in nested 802.3 Ethernet frames in Fast Frame packets, which results in a N...

  • EPSS 4.63%
  • Veröffentlicht 24.05.2007 02:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The ath_beacon_config function in if_ath.c in MadWifi before 0.9.3.1 allows remote attackers to cause a denial of service (system crash) via crafted beacon interval information when scanning for access points, which triggers a divide-by-zero error.

  • EPSS 2.17%
  • Veröffentlicht 24.05.2007 02:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Array index error in the (1) ieee80211_ioctl_getwmmparams and (2) ieee80211_ioctl_setwmmparams functions in net80211/ieee80211_wireless.c in MadWifi before 0.9.3.1 allows local users to cause a denial of service (system crash), possibly obtain kernel...

  • EPSS 3.29%
  • Veröffentlicht 30.03.2007 01:19:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

MadWifi, when Ad-Hoc mode is used, allows remote attackers to cause a denial of service (system crash) via unspecified vectors that lead to a kernel panic in the ieee80211_input function, related to "packets coming from a 'malicious' WinXP system."

  • EPSS 6.33%
  • Veröffentlicht 30.03.2007 01:19:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

MadWifi before 0.9.3 does not properly handle reception of an AUTH frame by an IBSS node, which allows remote attackers to cause a denial of service (system crash) via a certain AUTH frame.

  • EPSS 7.73%
  • Veröffentlicht 30.03.2007 01:19:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

ieee80211_input.c in MadWifi before 0.9.3 does not properly process Channel Switch Announcement Information Elements (CSA IEs), which allows remote attackers to cause a denial of service (loss of communication) via a Channel Switch Count less than or...

  • EPSS 5.62%
  • Veröffentlicht 30.03.2007 01:19:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

ieee80211_output.c in MadWifi before 0.9.3 sends unencrypted packets before WPA authentication succeeds, which allows remote attackers to obtain sensitive information (related to network structure), and possibly cause a denial of service (disrupted a...

  • EPSS 60.84%
  • Veröffentlicht 10.12.2006 11:28:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Stack-based buffer overflow in net80211/ieee80211_wireless.c in MadWifi before 0.9.2.1 allows remote attackers to execute arbitrary code via unspecified vectors, related to the encode_ie and giwscan_cb functions.

  • EPSS 0.74%
  • Veröffentlicht 31.12.2005 05:00:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

The ath_rate_sample function in the ath_rate/sample/sample.c sample code in MadWifi before 0.9.3 allows remote attackers to cause a denial of service (failed KASSERT and system crash) by moving a connected system to a location with low signal strengt...