Vulnerabilities
Vulnerable Software
Freeradius:  >> Freeradius  >> 1.0.2  Security Vulnerabilities
Buffer overflow in the SMB_Connect_Server function in FreeRadius 1.1.3 and earlier allows attackers to execute arbitrary code related to the server desthost field of an SMB_Handle_Type instance. NOTE: the impact of this issue has been disputed by a reliable third party and the vendor, who states that exploitation is limited "only to local administrators who have write access to the server configuration files." CVE concurs with the dispute
CVSS Score
6.6
EPSS Score
0.0
Published
2007-01-05
Unspecified vulnerability in FreeRADIUS 1.0.0 up to 1.1.0 allows remote attackers to bypass authentication or cause a denial of service (server crash) via "Insufficient input validation" in the EAP-MSCHAPv2 state machine module.
CVSS Score
7.5
EPSS Score
0.048
Published
2006-03-22
SQL injection vulnerability in the radius_xlat function in the SQL module for FreeRADIUS 1.0.2 and earlier allows remote authenticated users to execute arbitrary SQL commands via (1) group_membership_query, (2) simul_count_query, or (3) simul_verify_query configuration entries.
CVSS Score
7.5
EPSS Score
0.008
Published
2005-05-19
Buffer overflow in the sql_escape_func function in the SQL module for FreeRADIUS 1.0.2 and earlier allows remote attackers to cause a denial of service (crash).
CVSS Score
7.5
EPSS Score
0.015
Published
2005-05-19
FreeRADIUS RADIUS server allows remote attackers to cause a denial of service (CPU consumption) via a flood of Access-Request packets.
CVSS Score
5.0
EPSS Score
0.01
Published
2002-06-25


Contact Us

Shodan ® - All rights reserved