Page 4 of 17 results (0.003 seconds)

CVSS: 7.2EPSS: 2%CPEs: 2EXPL: 0

Stack-based buffer overflow in the get_internal_addresses function in the pluto application for Openswan 1.x before 1.0.9, and Openswan 2.x before 2.3.0, when compiled with XAUTH and PAM enabled, allows remote authenticated attackers to execute arbitrary code. • http://secunia.com/advisories/14038 http://secunia.com/advisories/14062 http://securitytracker.com/id?1013014 http://www.idefense.com/application/poi/display?id=190&type=vulnerabilities http://www.openswan.org/support/vuln/IDEF0785 http://www.osvdb.org/13195 http://www.redhat.com/archives/fedora-announce-list/2005-January/msg00103.html http://www.securityfocus.com/bid/12377 https://exchange.xforce.ibmcloud.com/vulnerabilities/19078 •

CVSS: 10.0EPSS: 1%CPEs: 6EXPL: 0

FreeS/WAN 1.x and 2.x, and other related products including superfreeswan 1.x, openswan 1.x before 1.0.6, openswan 2.x before 2.1.4, and strongSwan before 2.1.3, allows remote attackers to authenticate using spoofed PKCS#7 certificates in which a self-signed certificate identifies an alternate Certificate Authority (CA) and spoofed issuer and subject. FreeS/WAN 1.x y 2.x, y otros productos relacionados, incluyendo superfreeswan 1.x, openswan 1.x anteriores a 1.0.6, openswan 2.x anteriores a 2.1.4 y strongSwan anteriores a 2.1.3 permite a atacantes remotos autenticarse usando certificados PKCS#7 falsificados en los que un certificado auto-firmado identifica a una Autoridad Certificadora (CA) y a un usuario y asunto suplantados. • http://security.gentoo.org/glsa/glsa-200406-20.xml http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:070 http://www.openswan.org/support/vuln/can-2004-0590 https://exchange.xforce.ibmcloud.com/vulnerabilities/16515 •