← Back

Es

es

8 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Iperf3
iperf3

CVEs (8)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Es
1Iperf3
Jun 17, 2026
Aug 3, 2025
N/A· v4
10.0 CRITICAL· v3
N/A· v2
In iperf before 3.19.1, net.c has a buffer overflow when --skip-rx-copy is used (for MSG_TRUNC in recv).
1Es
1Iperf3
Jun 17, 2026
Aug 3, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
In iperf before 3.19.1, iperf_auth.c has a Base64Decode assertion failure and application exit upon a malformed authentication attempt.
1Es
1Iperf3
Jun 17, 2026
Aug 3, 2025
N/A· v4
10.0 CRITICAL· v3
N/A· v2
In iperf before 3.19.1, iperf_auth.c has an off-by-one error and resultant heap-based buffer overflow.
2Es
Netapp
3Hci Compute Node
Iperf3Ontap 9
Jun 17, 2026
Dec 18, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
iperf v3.17.1 was discovered to contain a segmentation violation via the iperf_exchange_parameters() function.
2Es
Netapp
2Bootstrap Os
Iperf3
Jun 17, 2026
May 14, 2024
N/A· v4
5.9 MEDIUM· v3
N/A· v2
iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA authentication, allows a timing side channel in RSA decryption operations. This side channel could be sufficient for an attacker to recover cre...Show more
iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA authentication, allows a timing side channel in RSA decryption operations. This side channel could be sufficient for an attacker to recover credential plaintext. It requires the attacker to send a large number of messages for decryption, as described in "Everlasting ROBOT: the Marvin Attack" by Hubert Kario.Show less
2Es
Redhat
5Enterprise Linux
Enterprise Linux For Arm 64Enterprise Linux For Ibm Z Systems+2 more
Jun 17, 2026
Mar 18, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
A flaw was found in iperf, a utility for testing network performance using TCP, UDP, and SCTP. A malicious or malfunctioning client can send less than the expected amount of data to the iperf server, which can cause the...Show more
A flaw was found in iperf, a utility for testing network performance using TCP, UDP, and SCTP. A malicious or malfunctioning client can send less than the expected amount of data to the iperf server, which can cause the server to hang indefinitely waiting for the remainder or until the connection gets closed. This will prevent other connections to the server, leading to a denial of service.Show less
5Apple
DebianEs+2 more
6Clustered Data Ontap
Debian LinuxFedora+3 more
Jun 17, 2026
Jul 17, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
iperf3 before 3.14 allows peers to cause an integer overflow and heap corruption via a crafted length field.
4Debian
EsNovell+1 more
5Debian Linux
Iperf3Leap+2 more
May 6, 2026
Sep 26, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The parse_string function in cjson.c in the cJSON library mishandles UTF8/16 strings, which allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a non-hex character in a JSON string,...Show more
The parse_string function in cjson.c in the cJSON library mishandles UTF8/16 strings, which allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a non-hex character in a JSON string, which triggers a heap-based buffer overflow.Show less