Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
175 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.3% | — | Freeradius | 31/12/2005 | 16/6/2026 | SQL injection vulnerability in the rlm_sqlcounter module in FreeRADIUS 1.0.3 and 1.0.4 allows remote attackers to execute arbitrary SQL commands via unknown attack vectors. | |
| Modificada | Alta (7.8) | 2.4% | — | Freeradius | 31/12/2005 | 16/6/2026 | Multiple buffer overflows in FreeRADIUS 1.0.3 and 1.0.4 allow remote attackers to cause denial of service (crash) via (1) the rlm_sqlcounter module or (2) unknown vectors "while expanding %t". | |
| Modificada | Media (6.4) | 4.5% | — | Freeradius | 31/12/2005 | 16/6/2026 | Off-by-one error in the sql_error function in sql_unixodbc.c in FreeRADIUS 1.0.2.5-5, and possibly other versions including 1.0.4, might allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by causing the external database query to fail. NOTE: this single issue is part of a… | |
| Modificada | Alta (7.5) | 1.8% | — | Freeradius | 19/5/2005 | 16/6/2026 | SQL injection vulnerability in the radius_xlat function in the SQL module for FreeRADIUS 1.0.2 and earlier allows remote authenticated users to execute arbitrary SQL commands via (1) group_membership_query, (2) simul_count_query, or (3) simul_verify_query configuration entries. | |
| Modificada | Alta (7.5) | 2.5% | — | Freeradius | 19/5/2005 | 16/6/2026 | Buffer overflow in the sql_escape_func function in the SQL module for FreeRADIUS 1.0.2 and earlier allows remote attackers to cause a denial of service (crash). | |
| Modificada | Media (5) | 3.3% | — | FreeradiusRedhat Enterprise LinuxRedhat Fedora Core | 9/2/2005 | 16/6/2026 | Memory leak in FreeRADIUS before 1.0.1 allows remote attackers to cause a denial of service (memory exhaustion) via a series of Access-Request packets with (1) Ascend-Send-Secret, (2) Ascend-Recv-Secret, or (3) Tunnel-Password attributes. | |
| Modificada | Media (5) | 3.2% | — | FreeradiusRedhat Enterprise LinuxRedhat Fedora Core | 9/2/2005 | 16/6/2026 | FreeRADIUS before 1.0.1 allows remote attackers to cause a denial of service (core dump) via malformed USR vendor-specific attributes (VSA) that cause a memcpy operation with a -1 argument. | |
| Modificada | Media (5) | 3.4% | — | Apache MOD Auth Radius | 11/1/2005 | 16/6/2026 | Apache mod_auth_radius 1.5.4 and libpam-radius-auth allow remote malicious RADIUS servers to cause a denial of service (crash) via a RADIUS_REPLY_MESSAGE with a RADIUS attribute length of 1, which leads to a memcpy operation with a -1 length argument. | |
| Modificada | Alta (10) | 5.2% | — | Yard RadiusYard Radius Project Yard Radius | 10/1/2005 | 16/6/2026 | Buffer overflow in the process_menu function in yardradius 1.0.20 allows remote attackers to execute arbitrary code. | |
| Modificada | Media (5) | 1.6% | — | GNU Radius | 23/12/2004 | 16/6/2026 | Integer overflow in the asn_decode_string() function defined in asn1.c in radiusd for GNU Radius 1.1 and 1.2 before 1.2.94, when compiled with the --enable-snmp option, allows remote attackers to cause a denial of service (daemon crash) via certain SNMP requests. | |
| Modificada | Media (5) | 1.6% | — | GNU Radius | 6/12/2004 | 16/6/2026 | The radius daemon (radiusd) for GNU Radius 1.1, when compiled with the -enable-snmp option, allows remote attackers to cause a denial of service (server crash) via malformed SNMP messages containing an invalid OID. | |
| Modificada | Media (5) | 3.7% | — | Freeradius | 3/11/2004 | 16/6/2026 | FreeRADIUS before 1.0.1 allows remote attackers to cause a denial of service (server crash) by sending an Ascend-Send-Secret attribute without the required leading packet. | |
| Modificada | Media (5) | 3.5% | — | GNU Radius | 3/3/2004 | 16/6/2026 | The rad_print_request function in logger.c for GNU Radius daemon (radiusd) before 1.2 allows remote attackers to cause a denial of service (crash) via a UDP packet with an Acct-Status-Type attribute without a value and no Acct-Session-Id attribute, which causes a null dereference. | |
| Modificada | Media (5) | 4.6% | 💥 Exploit | Freeradius | 15/12/2003 | 16/6/2026 | rad_decode in FreeRADIUS 0.9.2 and earlier allows remote attackers to cause a denial of service (crash) via a short RADIUS string attribute with a tag, which causes memcpy to be called with a -1 length argument, as demonstrated using the Tunnel-Password attribute. | |
| Modificada | Alta (10) | 3.7% | — | FreeradiusAI | 15/12/2003 | 16/6/2026 | Stack-based buffer overflow in SMB_Logon_Server of the rlm_smb experimental module for FreeRADIUS 0.9.3 and earlier allows remote attackers to execute arbitrary code via a long User-Password attribute. | |
| Modificada | Alta (7.5) | 4.2% | — | Cistron Radius Daemon | 7/8/2003 | 16/6/2026 | Cistron RADIUS daemon (radiusd-cistron) 1.6.6 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large value in an NAS-Port attribute, which is interpreted as a negative number and causes a buffer overflow. | |
| Modificada | Media (5) | 1.4% | — | Freeradius | 25/6/2002 | 16/6/2026 | FreeRADIUS RADIUS server allows remote attackers to cause a denial of service (CPU consumption) via a flood of Access-Request packets. | |
| Modificada | Media (5) | 5.4% | — | FreeradiusGNU RadiusIcradiusLivingston Radius+7 | 4/3/2002 | 16/6/2026 | Multiple RADIUS implementations do not properly validate the Vendor-Length of the Vendor-Specific attribute, which allows remote attackers to cause a denial of service (crash) via a Vendor-Length that is less than 2. | |
| Modificada | Alta (7.5) | 8.5% | — | Ascend RadiusFreeradiusGNU RadiusIcradius+8 | 4/3/2002 | 16/6/2026 | Buffer overflow in digest calculation function of multiple RADIUS implementations allows remote attackers to cause a denial of service and possibly execute arbitrary code via shared secret data. | |
| Modificada | Baja (2.1) | 0.85% | 💥 Exploit | Merit AAA Radius Server | 7/9/2001 | 16/6/2026 | rlmadmin RADIUS management utility in Merit AAA Server 3.8M, 5.01, and possibly other versions, allows local users to read arbitrary files via a symlink attack on the rlmadmin.help file. | |
| Modificada | Alta (10) | 6.7% | — | Lucent RadiusMerit Radius | 21/7/2001 | 16/6/2026 | Multiple buffer overflows in RADIUS daemon radiusd in (1) Merit 3.6b and (2) Lucent 2.1-2 RADIUS allow remote attackers to cause a denial of service or execute arbitrary commands. | |
| Modificada | Media (5) | 1.4% | — | Lucent RadiusSimon Horms Radius | 13/7/2001 | 16/6/2026 | Directory traversal vulnerability in Livingston/Lucent RADIUS before 2.1.va.1 may allow attackers to read arbitrary files via a .. (dot dot) attack. | |
| Modificada | Alta (7.5) | 2.8% | — | Lucent RadiusSimon Horms Radius | 6/7/2001 | 16/6/2026 | Format string vulnerabilities in Livingston/Lucent RADIUS before 2.1.va.1 may allow local or remote attackers to cause a denial of service and possibly execute arbitrary code via format specifiers that are injected into log messages. | |
| Modificada | Media (5) | 1.4% | — | Icradius | 24/4/2000 | 16/6/2026 | Buffer overflow in IC Radius package allows a remote attacker to cause a denial of service via a long user name. | |
| Modificada | Alta (7.5) | 3.0% | — | Livingston Radius | 1/12/1997 | 16/6/2026 | Livingston RADIUS code has a buffer overflow which can allow remote execution of commands as root. |