Point-to-point Protocol Project
Point-to-point Protocol Project Point-to-point Protocol: vulnerabilidades y CVE
Point-to-point Protocol Project Point-to-point Protocol tiene 6 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE6
Últimos 12 meses0
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2020-8597 | Crítica (9.8) | 20% | — | 3 feb 2020 | eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions. |
| CVE-2018-11574 | Crítica (9.8) | 1.9% | — | 14 jun 2018 | Improper input validation together with an integer overflow in the EAP-TLS protocol implementation in PPPD may cause a crash, information disclosure, or authentication bypass. This implementation is distributed as a… |
| CVE-2015-3310 | Media (4.3) | 5.4% | — | 24 abr 2015 | Buffer overflow in the rc_mksid function in plugins/radius/util.c in Paul's PPP Package (ppp) 2.4.6 and earlier, when the PID for pppd is greater than 65535, allows remote attackers to cause a denial of service (crash)… |
| CVE-2014-3158 | Alta (7.5) | 3.5% | — | 15 nov 2014 | Integer overflow in the getword function in options.c in pppd in Paul's PPP Package (ppp) before 2.4.7 allows attackers to "access privileged options" via a long word in an options file, which triggers a heap-based… |
| CVE-2006-2194 | Alta (7.2) | 0.40% | — | 5 jul 2006 | The winbind plugin in pppd for ppp 2.4.4 and earlier does not check the return code from the setuid function call, which might allow local users to gain privileges by causing setuid to fail, such as exceeding PAM limits… |
| CVE-2004-2695 | Alta (7.5) | 1.9% | — | 31 dic 2004 | SQL injection vulnerability in the Authorize.net callback code (subscriptions/authorize.php) in Jelsoft vBulletin 3.0 through 3.0.3 allows remote attackers to execute arbitrary SQL statements via the x_invoice_num… |