CVEs (8)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In iperf before 3.19.1, net.c has a buffer overflow when --skip-rx-copy is used (for MSG_TRUNC in recv). |
In iperf before 3.19.1, iperf_auth.c has a Base64Decode assertion failure and application exit upon a malformed authentication attempt. |
In iperf before 3.19.1, iperf_auth.c has an off-by-one error and resultant heap-based buffer overflow. |
2Es Netapp3Hci Compute Node Iperf3Ontap 9Jun 17, 2026 Dec 18, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 iperf v3.17.1 was discovered to contain a segmentation violation via the iperf_exchange_parameters() function. |
iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA authentication, allows a timing side channel in RSA decryption operations. This side channel could be sufficient for an attacker to recover cre...Show more |
2Es Redhat5Enterprise Linux Enterprise Linux For Arm 64Enterprise Linux For Ibm Z Systems+2 moreJun 17, 2026 Mar 18, 2024 N/A· v4 5.3 MEDIUM· v3 N/A· v2 A flaw was found in iperf, a utility for testing network performance using TCP, UDP, and SCTP. A malicious or malfunctioning client can send less than the expected amount of data to the iperf server, which can cause the...Show more |
5Apple DebianEs+2 more6Clustered Data Ontap Debian LinuxFedora+3 moreJun 17, 2026 Jul 17, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 iperf3 before 3.14 allows peers to cause an integer overflow and heap corruption via a crafted length field. |
4Debian EsNovell+1 more5Debian Linux Iperf3Leap+2 moreMay 6, 2026 Sep 26, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The parse_string function in cjson.c in the cJSON library mishandles UTF8/16 strings, which allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a non-hex character in a JSON string,...Show more |