CVE-2010-3752
- EPSS 0.65%
- Veröffentlicht 05.10.2010 22:00:05
- Zuletzt bearbeitet 11.04.2025 00:51:21
programs/pluto/xauth.c in the client in Openswan 2.6.25 through 2.6.28 allows remote authenticated gateways to execute arbitrary commands via shell metacharacters in (1) cisco_dns_info or (2) cisco_domain_info data in a packet, a different vulnerabil...
- EPSS 8.23%
- Veröffentlicht 25.06.2009 02:00:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The ASN.1 parser (pluto/asn1.c, libstrongswan/asn1/asn1.c, libstrongswan/asn1/asn1_parser.c) in (a) strongSwan 2.8 before 2.8.10, 4.2 before 4.2.16, and 4.3 before 4.3.2; and (b) openSwan 2.6 before 2.6.22 and 2.4 before 2.4.15 allows remote attacker...
- EPSS 10.86%
- Veröffentlicht 01.04.2009 10:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The pluto IKE daemon in Openswan and Strongswan IPsec 2.6 before 2.6.21 and 2.4 before 2.4.14, and Strongswan 4.2 before 4.2.14 and 2.8 before 2.8.9, allows remote attackers to cause a denial of service (daemon crash and restart) via a crafted (1) R_...
CVE-2008-4190
- EPSS 0.17%
- Veröffentlicht 24.09.2008 11:42:25
- Zuletzt bearbeitet 09.04.2025 00:30:58
The IPSEC livetest tool in Openswan 2.4.12 and earlier, and 2.6.x through 2.6.16, allows local users to overwrite arbitrary files and execute arbitrary code via a symlink attack on the (1) ipseclive.conn and (2) ipsec.olts.remote.log temporary files....
CVE-2005-3671
- EPSS 6.72%
- Veröffentlicht 18.11.2005 21:03:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
The Internet Key Exchange version 1 (IKEv1) implementation in Openswan 2 (openswan-2) before 2.4.4, and freeswan in SUSE LINUX 9.1 before 2.04_1.5.4-1.23, allow remote attackers to cause a denial of service via (1) a crafted packet using 3DES with an...
CVE-2005-0162
- EPSS 4.3%
- Veröffentlicht 26.01.2005 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Stack-based buffer overflow in the get_internal_addresses function in the pluto application for Openswan 1.x before 1.0.9, and Openswan 2.x before 2.3.0, when compiled with XAUTH and PAM enabled, allows remote authenticated attackers to execute arbit...