Gnu Radius vulnerabilities
6 known vulnerabilities affecting gnu/radius.
Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1MEDIUM4
Vulnerabilities
Page 1 of 1
CVE-2006-4181CRITICALCVSS 10.0v1.2v1.32006-11-28
CVE-2006-4181 [CRITICAL] CVE-2006-4181: Format string vulnerability in the sqllog function in the SQL accounting code for radiusd in GNU Rad
Format string vulnerability in the sqllog function in the SQL accounting code for radiusd in GNU Radius 1.2 and 1.3 allows remote attackers to execute arbitrary code via unknown vectors.
nvd
CVE-2004-0849MEDIUMCVSS 5.0v0.92.1v0.93+5 more2004-12-23
CVE-2004-0849 [MEDIUM] CVE-2004-0849: Integer overflow in the asn_decode_string() function defined in asn1.c in radiusd for GNU Radius 1.1
Integer overflow in the asn_decode_string() function defined in asn1.c in radiusd for GNU Radius 1.1 and 1.2 before 1.2.94, when compiled with the --enable-snmp option, allows remote attackers to cause a denial of service (daemon crash) via certain SNMP requests.
nvd
CVE-2004-0576MEDIUMCVSS 5.0v1.12004-12-06
CVE-2004-0576 [MEDIUM] CVE-2004-0576: The radius daemon (radiusd) for GNU Radius 1.1, when compiled with the -enable-snmp option, allows r
The radius daemon (radiusd) for GNU Radius 1.1, when compiled with the -enable-snmp option, allows remote attackers to cause a denial of service (server crash) via malformed SNMP messages containing an invalid OID.
nvd
CVE-2004-0131MEDIUMCVSS 5.0v1.12004-03-03
CVE-2004-0131 [MEDIUM] CVE-2004-0131: The rad_print_request function in logger.c for GNU Radius daemon (radiusd) before 1.2 allows remote
The rad_print_request function in logger.c for GNU Radius daemon (radiusd) before 1.2 allows remote attackers to cause a denial of service (crash) via a UDP packet with an Acct-Status-Type attribute without a value and no Acct-Session-Id attribute, which causes a null dereference.
nvd
CVE-2001-1376HIGHCVSS 7.5v0.92.1v0.93+2 more2002-03-04
CVE-2001-1376 [HIGH] CVE-2001-1376: Buffer overflow in digest calculation function of multiple RADIUS implementations allows remote atta
Buffer overflow in digest calculation function of multiple RADIUS implementations allows remote attackers to cause a denial of service and possibly execute arbitrary code via shared secret data.
nvd
CVE-2001-1377MEDIUMCVSS 5.0v0.92.1v0.93+2 more2002-03-04
CVE-2001-1377 [MEDIUM] CVE-2001-1377: Multiple RADIUS implementations do not properly validate the Vendor-Length of the Vendor-Specific at
Multiple RADIUS implementations do not properly validate the Vendor-Length of the Vendor-Specific attribute, which allows remote attackers to cause a denial of service (crash) via a Vendor-Length that is less than 2.
nvd