Vulnerabilities > Libreswan > Libreswan > 3.5

DATE CVE VULNERABILITY TITLE RISK
2023-08-25 CVE-2023-38712 NULL Pointer Dereference vulnerability in Libreswan
An issue was discovered in Libreswan 3.x and 4.x before 4.12.
network
low complexity
libreswan CWE-476
6.5
2020-05-12 CVE-2020-1763 Out-of-bounds Read vulnerability in Libreswan
An out-of-bounds buffer read flaw was found in the pluto daemon of libreswan from versions 3.27 till 3.31 where, an unauthenticated attacker could use this flaw to crash libreswan by sending specially-crafted IKEv1 Informational Exchange packets.
network
low complexity
libreswan CWE-125
7.5
2019-06-12 CVE-2019-10155 Improper Validation of Integrity Check Value vulnerability in multiple products
The Libreswan Project has found a vulnerability in the processing of IKEv1 informational exchange packets which are encrypted and integrity protected using the established IKE SA encryption and integrity keys, but as a receiver, the integrity check value was not verified.
3.1
2019-05-24 CVE-2019-12312 Reachable Assertion vulnerability in Libreswan
In Libreswan 3.27 an assertion failure can lead to a pluto IKE daemon restart.
network
low complexity
libreswan CWE-617
5.0
2017-06-13 CVE-2016-5391 NULL Pointer Dereference vulnerability in multiple products
libreswan before 3.18 allows remote attackers to cause a denial of service (NULL pointer dereference and pluto daemon restart).
network
low complexity
libreswan fedoraproject CWE-476
7.5
2016-06-16 CVE-2016-5361 Improper Input Validation vulnerability in Libreswan
programs/pluto/ikev1.c in libreswan before 3.17 retransmits in initial-responder states, which allows remote attackers to cause a denial of service (traffic amplification) via a spoofed UDP packet.
network
low complexity
libreswan CWE-20
5.0
2014-01-26 CVE-2013-6467 Remote Denial of Service vulnerability in Libreswan 'IKEv2' Payloads
Libreswan 3.7 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon restart) via IKEv2 packets that lack expected payloads.
network
low complexity
libreswan
5.0
2014-01-16 CVE-2013-7294 Improper Input Validation vulnerability in Libreswan
The ikev2parent_inI1outR1 function in pluto/ikev2_parent.c in libreswan before 3.7 allows remote attackers to cause a denial of service (restart) via an IKEv2 I1 notification without a KE payload.
network
low complexity
libreswan CWE-20
5.0