← Back

Freeradius

freeradius

Vendor: Freeradius • 47 CVEs

CVEs (47)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Freeradius
Redhat
3Enterprise Linux
Fedora CoreFreeradius
Apr 16, 2026
Feb 9, 2005
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Memory leak in FreeRADIUS before 1.0.1 allows remote attackers to cause a denial of service (memory exhaustion) via a series of Access-Request packets with (1) Ascend-Send-Secret, (2) Ascend-Recv-Secret, or (3) Tunnel-Pa...Show more
Memory leak in FreeRADIUS before 1.0.1 allows remote attackers to cause a denial of service (memory exhaustion) via a series of Access-Request packets with (1) Ascend-Send-Secret, (2) Ascend-Recv-Secret, or (3) Tunnel-Password attributes.Show less
2Freeradius
Redhat
3Enterprise Linux
Fedora CoreFreeradius
Apr 16, 2026
Feb 9, 2005
N/A· v4
N/A· v3
5.0 MEDIUM· v2
FreeRADIUS before 1.0.1 allows remote attackers to cause a denial of service (core dump) via malformed USR vendor-specific attributes (VSA) that cause a memcpy operation with a -1 argument.
1Freeradius
1Freeradius
Apr 16, 2026
Nov 3, 2004
N/A· v4
N/A· v3
5.0 MEDIUM· v2
FreeRADIUS before 1.0.1 allows remote attackers to cause a denial of service (server crash) by sending an Ascend-Send-Secret attribute without the required leading packet.
1Freeradius
1Freeradius
Apr 16, 2026
Dec 15, 2003
N/A· v4
N/A· v3
5.0 MEDIUM· v2
rad_decode in FreeRADIUS 0.9.2 and earlier allows remote attackers to cause a denial of service (crash) via a short RADIUS string attribute with a tag, which causes memcpy to be called with a -1 length argument, as demon...Show more
rad_decode in FreeRADIUS 0.9.2 and earlier allows remote attackers to cause a denial of service (crash) via a short RADIUS string attribute with a tag, which causes memcpy to be called with a -1 length argument, as demonstrated using the Tunnel-Password attribute.Show less
1Freeradius
1Freeradius
Apr 16, 2026
Jun 25, 2002
N/A· v4
N/A· v3
5.0 MEDIUM· v2
FreeRADIUS RADIUS server allows remote attackers to cause a denial of service (CPU consumption) via a flood of Access-Request packets.
11Freeradius
GnuIcradius+8 more
11Freeradius
IcradiusOpenradius+8 more
Apr 16, 2026
Mar 4, 2002
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Multiple RADIUS implementations do not properly validate the Vendor-Length of the Vendor-Specific attribute, which allows remote attackers to cause a denial of service (crash) via a Vendor-Length that is less than 2.
12Ascend
FreeradiusGnu+9 more
12Freeradius
IcradiusOpenradius+9 more
Apr 16, 2026
Mar 4, 2002
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in digest calculation function of multiple RADIUS implementations allows remote attackers to cause a denial of service and possibly execute arbitrary code via shared secret data.