Vulnerabilities > Libreswan > High

DATE CVE VULNERABILITY TITLE RISK
2023-05-29 CVE-2023-30570 Resource Exhaustion vulnerability in Libreswan
pluto in Libreswan before 4.11 allows a denial of service (responder SPI mishandling and daemon crash) via unauthenticated IKEv1 Aggressive Mode packets.
network
low complexity
libreswan CWE-400
7.5
2023-05-17 CVE-2023-2295 A vulnerability was found in the libreswan library.
network
low complexity
libreswan redhat
7.5
2022-01-15 CVE-2022-23094 NULL Pointer Dereference vulnerability in multiple products
Libreswan 4.2 through 4.5 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted IKEv1 packet because pluto/ikev1.c wrongly expects that a state object exists.
network
low complexity
libreswan fedoraproject debian CWE-476
7.5
2020-05-12 CVE-2020-1763 Out-of-bounds Read vulnerability in Libreswan
An out-of-bounds buffer read flaw was found in the pluto daemon of libreswan from versions 3.27 till 3.31 where, an unauthenticated attacker could use this flaw to crash libreswan by sending specially-crafted IKEv1 Informational Exchange packets.
network
low complexity
libreswan CWE-125
7.5
2017-06-13 CVE-2016-5391 NULL Pointer Dereference vulnerability in multiple products
libreswan before 3.18 allows remote attackers to cause a denial of service (NULL pointer dereference and pluto daemon restart).
network
low complexity
libreswan fedoraproject CWE-476
7.5