Vulnerabilities > Libreswan > Libreswan > 3.7

DATE CVE VULNERABILITY TITLE RISK
2023-08-25 CVE-2023-38712 NULL Pointer Dereference vulnerability in Libreswan
An issue was discovered in Libreswan 3.x and 4.x before 4.12.
network
low complexity
libreswan CWE-476
6.5
2019-06-12 CVE-2019-10155 Improper Validation of Integrity Check Value vulnerability in multiple products
The Libreswan Project has found a vulnerability in the processing of IKEv1 informational exchange packets which are encrypted and integrity protected using the established IKE SA encryption and integrity keys, but as a receiver, the integrity check value was not verified.
3.1
2019-05-24 CVE-2019-12312 Reachable Assertion vulnerability in Libreswan
In Libreswan 3.27 an assertion failure can lead to a pluto IKE daemon restart.
network
low complexity
libreswan CWE-617
5.0
2017-06-13 CVE-2016-5391 NULL Pointer Dereference vulnerability in multiple products
libreswan before 3.18 allows remote attackers to cause a denial of service (NULL pointer dereference and pluto daemon restart).
network
low complexity
libreswan fedoraproject CWE-476
7.5
2016-06-16 CVE-2016-5361 Improper Input Validation vulnerability in Libreswan
programs/pluto/ikev1.c in libreswan before 3.17 retransmits in initial-responder states, which allows remote attackers to cause a denial of service (traffic amplification) via a spoofed UDP packet.
network
low complexity
libreswan CWE-20
5.0
2014-01-26 CVE-2013-6467 Remote Denial of Service vulnerability in Libreswan 'IKEv2' Payloads
Libreswan 3.7 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon restart) via IKEv2 packets that lack expected payloads.
network
low complexity
libreswan
5.0