Vulnerabilities > W1 FI > Medium

DATE CVE VULNERABILITY TITLE RISK
2015-06-15 CVE-2015-4144 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
The EAP-pwd server and peer implementation in hostapd and wpa_supplicant 1.0 through 2.4 does not validate that a message is long enough to contain the Total-Length field, which allows remote attackers to cause a denial of service (crash) via a crafted message.
network
low complexity
opensuse w1-fi CWE-119
5.0
2015-06-15 CVE-2015-4143 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
The EAP-pwd server and peer implementation in hostapd and wpa_supplicant 1.0 through 2.4 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted (1) Commit or (2) Confirm message payload.
network
low complexity
w1-fi opensuse CWE-119
5.0
2015-06-15 CVE-2015-4142 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
Integer underflow in the WMM Action frame parser in hostapd 0.5.5 through 2.4 and wpa_supplicant 0.7.0 through 2.4, when used for AP mode MLME/SME functionality, allows remote attackers to cause a denial of service (crash) via a crafted frame, which triggers an out-of-bounds read.
4.3
2015-06-15 CVE-2015-4141 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
The WPS UPnP function in hostapd, when using WPS AP, and wpa_supplicant, when using WPS external registrar (ER), 0.7.0 through 2.4 allows remote attackers to cause a denial of service (crash) via a negative chunk length, which triggers an out-of-bounds read or heap-based buffer overflow.
4.3
2015-04-28 CVE-2015-1863 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
Heap-based buffer overflow in wpa_supplicant 1.0 through 2.4 allows remote attackers to cause a denial of service (crash), read memory, or possibly execute arbitrary code via crafted SSID information in a management frame when creating or updating P2P entries.
5.8
2014-10-16 CVE-2014-3686 Improper Input Validation vulnerability in multiple products
wpa_supplicant and hostapd 0.7.2 through 2.2, when running with certain configurations and using wpa_cli or hostapd_cli with action scripts, allows remote attackers to execute arbitrary commands via a crafted frame.
6.8