CVE-2013-2054
- EPSS 2.02%
- Veröffentlicht 09.07.2013 17:55:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
Buffer overflow in the atodn function in strongSwan 2.0.0 through 4.3.4, when Opportunistic Encryption is enabled and an RSA key is being used, allows remote attackers to cause a denial of service (pluto IKE daemon crash) and possibly execute arbitra...
CVE-2013-2944
- EPSS 1.59%
- Veröffentlicht 02.05.2013 14:55:05
- Zuletzt bearbeitet 29.04.2026 01:13:23
strongSwan 4.3.5 through 5.0.3, when using the OpenSSL plugin for ECDSA signature verification, allows remote attackers to authenticate as other users via an invalid signature.
CVE-2012-2388
- EPSS 3.32%
- Veröffentlicht 27.06.2012 21:55:02
- Zuletzt bearbeitet 16.06.2026 23:41:28
The GMP Plugin in strongSwan 4.2.0 through 4.6.3 allows remote attackers to bypass authentication via a (1) empty or (2) zeroed RSA signature, aka "RSA signature verification vulnerability."
CVE-2010-2628
- EPSS 4.05%
- Veröffentlicht 20.08.2010 18:00:02
- Zuletzt bearbeitet 16.06.2026 23:21:06
The IKE daemon in strongSwan 4.3.x before 4.3.7 and 4.4.x before 4.4.1 does not properly check the return values of snprintf calls, which allows remote attackers to execute arbitrary code via crafted (1) certificate or (2) identity data that triggers...
- EPSS 1.58%
- Veröffentlicht 04.08.2009 16:30:00
- Zuletzt bearbeitet 16.06.2026 23:09:56
The asn1_length function in strongSwan 2.8 before 2.8.11, 4.2 before 4.2.17, and 4.3 before 4.3.3 does not properly handle X.509 certificates with crafted Relative Distinguished Names (RDNs), which allows remote attackers to cause a denial of service...
- EPSS 2.37%
- Veröffentlicht 25.06.2009 02:00:00
- Zuletzt bearbeitet 16.06.2026 23:08:57
The ASN.1 parser (pluto/asn1.c, libstrongswan/asn1/asn1.c, libstrongswan/asn1/asn1_parser.c) in (a) strongSwan 2.8 before 2.8.10, 4.2 before 4.2.16, and 4.3 before 4.3.2; and (b) openSwan 2.6 before 2.6.22 and 2.4 before 2.4.15 allows remote attacker...
- EPSS 2.95%
- Veröffentlicht 08.06.2009 01:00:00
- Zuletzt bearbeitet 16.06.2026 23:08:26
charon/sa/tasks/child_create.c in the charon daemon in strongSWAN before 4.3.1 switches the NULL checks for TSi and TSr payloads, which allows remote attackers to cause a denial of service via an IKE_AUTH request without a (1) TSi or (2) TSr traffic ...
- EPSS 2.95%
- Veröffentlicht 08.06.2009 01:00:00
- Zuletzt bearbeitet 16.06.2026 23:08:26
charon/sa/ike_sa.c in the charon daemon in strongSWAN before 4.3.1 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an invalid IKE_SA_INIT request that triggers "an incomplete state," followed by a CREATE_...
- EPSS 3.21%
- Veröffentlicht 01.04.2009 10:30:00
- Zuletzt bearbeitet 16.06.2026 23:05:49
The pluto IKE daemon in Openswan and Strongswan IPsec 2.6 before 2.6.21 and 2.4 before 2.4.14, and Strongswan 4.2 before 4.2.14 and 2.8 before 2.8.9, allows remote attackers to cause a denial of service (daemon crash and restart) via a crafted (1) R_...
- EPSS 2.52%
- Veröffentlicht 14.10.2008 20:00:01
- Zuletzt bearbeitet 16.06.2026 22:58:03
strongSwan 4.2.6 and earlier allows remote attackers to cause a denial of service (daemon crash) via an IKE_SA_INIT message with a large number of NULL values in a Key Exchange payload, which triggers a NULL pointer dereference for the return value o...