← Back

Shadowsocks Libev

shadowsocks-libev

Vendor: Shadowsocks • 4 CVEs

CVEs (4)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Shadowsocks
1Shadowsocks Libev
Nov 21, 2024
Dec 18, 2019
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
An exploitable information disclosure vulnerability exists in the network packet handling functionality of Shadowsocks-libev 3.3.2. When utilizing a Stream Cipher, a specially crafted set of network packets can cause an...Show more
An exploitable information disclosure vulnerability exists in the network packet handling functionality of Shadowsocks-libev 3.3.2. When utilizing a Stream Cipher, a specially crafted set of network packets can cause an outbound connection from the server, resulting in information disclosure. An attacker can send arbitrary packets to trigger this vulnerability.Show less
2Opensuse
Shadowsocks
3Backports Sle
LeapShadowsocks Libev
Nov 21, 2024
Dec 3, 2019
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
An exploitable code execution vulnerability exists in the ss-manager binary of Shadowsocks-libev 3.3.2. Specially crafted network packets sent to ss-manager can cause an arbitrary binary to run, resulting in code executi...Show more
An exploitable code execution vulnerability exists in the ss-manager binary of Shadowsocks-libev 3.3.2. Specially crafted network packets sent to ss-manager can cause an arbitrary binary to run, resulting in code execution and privilege escalation. An attacker can send network packets to trigger this vulnerability.Show less
2Opensuse
Shadowsocks
3Backports
LeapShadowsocks Libev
Nov 21, 2024
Dec 3, 2019
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
An exploitable denial-of-service vulnerability exists in the UDPRelay functionality of Shadowsocks-libev 3.3.2. When utilizing a Stream Cipher and a local_address, arbitrary UDP packets can cause a FATAL error code path...Show more
An exploitable denial-of-service vulnerability exists in the UDPRelay functionality of Shadowsocks-libev 3.3.2. When utilizing a Stream Cipher and a local_address, arbitrary UDP packets can cause a FATAL error code path and exit. An attacker can send arbitrary UDP packets to trigger this vulnerability.Show less
2Debian
Shadowsocks
2Debian Linux
Shadowsocks Libev
May 13, 2026
Oct 27, 2017
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
In manager.c in ss-manager in shadowsocks-libev 3.1.0, improper parsing allows command injection via shell metacharacters in a JSON configuration request received via 127.0.0.1 UDP traffic, related to the add_server, bui...Show more
In manager.c in ss-manager in shadowsocks-libev 3.1.0, improper parsing allows command injection via shell metacharacters in a JSON configuration request received via 127.0.0.1 UDP traffic, related to the add_server, build_config, and construct_command_line functions.Show less