Show filters
98 Total Results
Displaying 71-80 of 98
Sort by:
Attacker Value
Unknown
CVE-2007-2028
Disclosure Date: April 13, 2007 (last updated October 04, 2023)
Memory leak in freeRADIUS 1.1.5 and earlier allows remote attackers to cause a denial of service (memory consumption) via a large number of EAP-TTLS tunnel connections using malformed Diameter format attributes, which causes the authentication request to be rejected but does not reclaim VALUE_PAIR data structures.
0
Attacker Value
Unknown
CVE-2007-0080
Disclosure Date: January 05, 2007 (last updated November 08, 2023)
Buffer overflow in the SMB_Connect_Server function in FreeRadius 1.1.3 and earlier allows attackers to execute arbitrary code related to the server desthost field of an SMB_Handle_Type instance. NOTE: the impact of this issue has been disputed by a reliable third party and the vendor, who states that exploitation is limited "only to local administrators who have write access to the server configuration files." CVE concurs with the dispute
0
Attacker Value
Unknown
CVE-2006-4181
Disclosure Date: November 28, 2006 (last updated October 04, 2023)
Format string vulnerability in the sqllog function in the SQL accounting code for radiusd in GNU Radius 1.2 and 1.3 allows remote attackers to execute arbitrary code via unknown vectors.
0
Attacker Value
Unknown
CVE-2006-1354
Disclosure Date: March 22, 2006 (last updated February 22, 2025)
Unspecified vulnerability in FreeRADIUS 1.0.0 up to 1.1.0 allows remote attackers to bypass authentication or cause a denial of service (server crash) via "Insufficient input validation" in the EAP-MSCHAPv2 state machine module.
0
Attacker Value
Unknown
CVE-2005-4744
Disclosure Date: December 31, 2005 (last updated February 22, 2025)
Off-by-one error in the sql_error function in sql_unixodbc.c in FreeRADIUS 1.0.2.5-5, and possibly other versions including 1.0.4, might allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by causing the external database query to fail. NOTE: this single issue is part of a larger-scale disclosure, originally by SUSE, which reported multiple issues that were disputed by FreeRADIUS. Disputed issues included file descriptor leaks, memory disclosure, LDAP injection, and other issues. Without additional information, the most recent FreeRADIUS report is being regarded as the authoritative source for this CVE identifier.
0
Attacker Value
Unknown
CVE-2005-4746
Disclosure Date: December 31, 2005 (last updated February 22, 2025)
Multiple buffer overflows in FreeRADIUS 1.0.3 and 1.0.4 allow remote attackers to cause denial of service (crash) via (1) the rlm_sqlcounter module or (2) unknown vectors "while expanding %t".
0
Attacker Value
Unknown
CVE-2005-4745
Disclosure Date: December 31, 2005 (last updated February 22, 2025)
SQL injection vulnerability in the rlm_sqlcounter module in FreeRADIUS 1.0.3 and 1.0.4 allows remote attackers to execute arbitrary SQL commands via unknown attack vectors.
0
Attacker Value
Unknown
CVE-2005-1455
Disclosure Date: May 19, 2005 (last updated February 22, 2025)
Buffer overflow in the sql_escape_func function in the SQL module for FreeRADIUS 1.0.2 and earlier allows remote attackers to cause a denial of service (crash).
0
Attacker Value
Unknown
CVE-2005-1454
Disclosure Date: May 19, 2005 (last updated February 22, 2025)
SQL injection vulnerability in the radius_xlat function in the SQL module for FreeRADIUS 1.0.2 and earlier allows remote authenticated users to execute arbitrary SQL commands via (1) group_membership_query, (2) simul_count_query, or (3) simul_verify_query configuration entries.
0
Attacker Value
Unknown
CVE-2004-0960
Disclosure Date: February 09, 2005 (last updated February 22, 2025)
FreeRADIUS before 1.0.1 allows remote attackers to cause a denial of service (core dump) via malformed USR vendor-specific attributes (VSA) that cause a memcpy operation with a -1 argument.
0