Show filters
18 Total Results
Displaying 11-18 of 18
Sort by:
Attacker Value
Unknown
CVE-2011-2701
Disclosure Date: August 04, 2011 (last updated October 04, 2023)
The ocsp_check function in rlm_eap_tls.c in FreeRADIUS 2.1.11, when OCSP is enabled, does not properly parse replies from OCSP responders, which allows remote attackers to bypass authentication by using the EAP-TLS protocol with a revoked X.509 client certificate.
0
Attacker Value
Unknown
CVE-2010-3697
Disclosure Date: October 07, 2010 (last updated October 04, 2023)
The wait_for_child_to_die function in main/event.c in FreeRADIUS 2.1.x before 2.1.10, in certain circumstances involving long-term database outages, does not properly handle long queue times for requests, which allows remote attackers to cause a denial of service (daemon crash) by sending many requests.
0
Attacker Value
Unknown
CVE-2010-3696
Disclosure Date: October 07, 2010 (last updated November 08, 2023)
The fr_dhcp_decode function in lib/dhcp.c in FreeRADIUS 2.1.9, in certain non-default builds, does not properly handle the DHCP Relay Agent Information option, which allows remote attackers to cause a denial of service (infinite loop and daemon outage) via a packet that has more than one sub-option. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2001-1377
Disclosure Date: March 04, 2002 (last updated February 22, 2025)
Multiple RADIUS implementations do not properly validate the Vendor-Length of the Vendor-Specific attribute, which allows remote attackers to cause a denial of service (crash) via a Vendor-Length that is less than 2.
0
Attacker Value
Unknown
CVE-2001-1376
Disclosure Date: March 04, 2002 (last updated February 22, 2025)
Buffer overflow in digest calculation function of multiple RADIUS implementations allows remote attackers to cause a denial of service and possibly execute arbitrary code via shared secret data.
0
Attacker Value
Unknown
CVE-2001-0534
Disclosure Date: July 21, 2001 (last updated February 22, 2025)
Multiple buffer overflows in RADIUS daemon radiusd in (1) Merit 3.6b and (2) Lucent 2.1-2 RADIUS allow remote attackers to cause a denial of service or execute arbitrary commands.
0
Attacker Value
Unknown
CVE-2001-1082
Disclosure Date: July 13, 2001 (last updated February 22, 2025)
Directory traversal vulnerability in Livingston/Lucent RADIUS before 2.1.va.1 may allow attackers to read arbitrary files via a .. (dot dot) attack.
0
Attacker Value
Unknown
CVE-2001-1081
Disclosure Date: July 06, 2001 (last updated February 22, 2025)
Format string vulnerabilities in Livingston/Lucent RADIUS before 2.1.va.1 may allow local or remote attackers to cause a denial of service and possibly execute arbitrary code via format specifiers that are injected into log messages.
0