Show filters
13 Total Results
Displaying 1-10 of 13
Sort by:
Attacker Value
Unknown

CVE-2012-1820

Disclosure Date: June 13, 2012 (last updated October 04, 2023)
The bgp_capability_orf function in bgpd in Quagga 0.99.20.1 and earlier allows remote attackers to cause a denial of service (assertion failure and daemon exit) by leveraging a BGP peering relationship and sending a malformed Outbound Route Filtering (ORF) capability TLV in an OPEN message.
0
Attacker Value
Unknown

CVE-2012-0250

Disclosure Date: April 05, 2012 (last updated October 04, 2023)
Buffer overflow in the OSPFv2 implementation in ospfd in Quagga before 0.99.20.1 allows remote attackers to cause a denial of service (daemon crash) via a Link State Update (aka LS Update) packet containing a network-LSA link-state advertisement for which the data-structure length is smaller than the value in the Length header field.
0
Attacker Value
Unknown

CVE-2012-0255

Disclosure Date: April 05, 2012 (last updated October 04, 2023)
The BGP implementation in bgpd in Quagga before 0.99.20.1 does not properly use message buffers for OPEN messages, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a message associated with a malformed Four-octet AS Number Capability (aka AS4 capability).
0
Attacker Value
Unknown

CVE-2012-0249

Disclosure Date: April 05, 2012 (last updated October 04, 2023)
Buffer overflow in the ospf_ls_upd_list_lsa function in ospf_packet.c in the OSPFv2 implementation in ospfd in Quagga before 0.99.20.1 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a Link State Update (aka LS Update) packet that is smaller than the length specified in its header.
0
Attacker Value
Unknown

CVE-2011-3326

Disclosure Date: October 10, 2011 (last updated October 04, 2023)
The ospf_flood function in ospf_flood.c in ospfd in Quagga before 0.99.19 allows remote attackers to cause a denial of service (daemon crash) via an invalid Link State Advertisement (LSA) type in an IPv4 Link State Update message.
0
Attacker Value
Unknown

CVE-2011-3323

Disclosure Date: October 10, 2011 (last updated October 04, 2023)
The OSPFv3 implementation in ospf6d in Quagga before 0.99.19 allows remote attackers to cause a denial of service (out-of-bounds memory access and daemon crash) via a Link State Update message with an invalid IPv6 prefix length.
0
Attacker Value
Unknown

CVE-2011-3325

Disclosure Date: October 10, 2011 (last updated October 04, 2023)
ospf_packet.c in ospfd in Quagga before 0.99.19 allows remote attackers to cause a denial of service (daemon crash) via (1) a 0x0a type field in an IPv4 packet header or (2) a truncated IPv4 Hello packet.
0
Attacker Value
Unknown

CVE-2011-3324

Disclosure Date: October 10, 2011 (last updated October 04, 2023)
The ospf6_lsa_is_changed function in ospf6_lsa.c in the OSPFv3 implementation in ospf6d in Quagga before 0.99.19 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via trailing zero values in the Link State Advertisement (LSA) header list of an IPv6 Database Description message.
0
Attacker Value
Unknown

CVE-2011-3327

Disclosure Date: October 10, 2011 (last updated October 04, 2023)
Heap-based buffer overflow in the ecommunity_ecom2str function in bgp_ecommunity.c in bgpd in Quagga before 0.99.19 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code by sending a crafted BGP UPDATE message over IPv4.
0
Attacker Value
Unknown

CVE-2010-1674

Disclosure Date: March 29, 2011 (last updated October 04, 2023)
The extended-community parser in bgpd in Quagga before 0.99.18 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a malformed Extended Communities attribute.
0