Vulnerabilities > GNU > Radius

DATE CVE VULNERABILITY TITLE RISK
2006-11-28 CVE-2006-4181 Remote Format String vulnerability in GNU Radius SQLLog
Format string vulnerability in the sqllog function in the SQL accounting code for radiusd in GNU Radius 1.2 and 1.3 allows remote attackers to execute arbitrary code via unknown vectors.
network
low complexity
gnu
critical
10.0
2004-12-23 CVE-2004-0849 Unspecified vulnerability in GNU Radius
Integer overflow in the asn_decode_string() function defined in asn1.c in radiusd for GNU Radius 1.1 and 1.2 before 1.2.94, when compiled with the --enable-snmp option, allows remote attackers to cause a denial of service (daemon crash) via certain SNMP requests.
network
low complexity
gnu
5.0
2004-12-06 CVE-2004-0576 Unspecified vulnerability in GNU Radius 1.1
The radius daemon (radiusd) for GNU Radius 1.1, when compiled with the -enable-snmp option, allows remote attackers to cause a denial of service (server crash) via malformed SNMP messages containing an invalid OID.
network
low complexity
gnu
5.0
2004-03-03 CVE-2004-0131 Remote Denial Of Service vulnerability in GNU Radius 1.1
The rad_print_request function in logger.c for GNU Radius daemon (radiusd) before 1.2 allows remote attackers to cause a denial of service (crash) via a UDP packet with an Acct-Status-Type attribute without a value and no Acct-Session-Id attribute, which causes a null dereference.
network
low complexity
gnu
5.0
2002-03-04 CVE-2001-1377 Denial Of Service vulnerability in Multiple Vendor Radius Short Vendor-Length Field
Multiple RADIUS implementations do not properly validate the Vendor-Length of the Vendor-Specific attribute, which allows remote attackers to cause a denial of service (crash) via a Vendor-Length that is less than 2.
5.0
2002-03-04 CVE-2001-1376 Buffer Overflow vulnerability in Multiple Vendor RADIUS Digest Calculation
Buffer overflow in digest calculation function of multiple RADIUS implementations allows remote attackers to cause a denial of service and possibly execute arbitrary code via shared secret data.
7.5