W1.fi
w1.fi
50 CVEs • 2 products
Products (2)
Click to collapseToggle
Products (2)
Click to collapse
CVEs (50)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Opensuse W1.fi3Hostapd OpensuseWpa SupplicantMay 6, 2026 Jun 15, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The EAP-pwd peer implementation in hostapd and wpa_supplicant 1.0 through 2.4 does not clear the L (Length) and M (More) flags before determining if a response should be fragmented, which allows remote attackers to cause...Show more |
2Opensuse W1.fi3Hostapd OpensuseWpa SupplicantMay 6, 2026 Jun 15, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The EAP-pwd server and peer implementation in hostapd and wpa_supplicant 1.0 through 2.4 does not validate a fragment is already being processed, which allows remote attackers to cause a denial of service (memory leak) v...Show more |
2Opensuse W1.fi3Hostapd OpensuseWpa SupplicantMay 6, 2026 Jun 15, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The EAP-pwd server and peer implementation in hostapd and wpa_supplicant 1.0 through 2.4 does not validate that a message is long enough to contain the Total-Length field, which allows remote attackers to cause a denial...Show more |
2Opensuse W1.fi3Hostapd OpensuseWpa SupplicantMay 6, 2026 Jun 15, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The EAP-pwd server and peer implementation in hostapd and wpa_supplicant 1.0 through 2.4 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted (1) Commit or (2) Confirm message...Show more |
3Opensuse RedhatW1.fi7Enterprise Linux Desktop Enterprise Linux Hpc NodeEnterprise Linux Server+4 moreMay 6, 2026 Jun 15, 2015 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Integer underflow in the WMM Action frame parser in hostapd 0.5.5 through 2.4 and wpa_supplicant 0.7.0 through 2.4, when used for AP mode MLME/SME functionality, allows remote attackers to cause a denial of service (cras...Show more |
2Opensuse W1.fi3Hostapd OpensuseWpa SupplicantMay 6, 2026 Jun 15, 2015 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The WPS UPnP function in hostapd, when using WPS AP, and wpa_supplicant, when using WPS external registrar (ER), 0.7.0 through 2.4 allows remote attackers to cause a denial of service (crash) via a negative chunk length,...Show more |
5Canonical DebianOpensuse+2 more10Debian Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+7 moreMay 6, 2026 Apr 28, 2015 N/A· v4 N/A· v3 5.8 MEDIUM· v2 Heap-based buffer overflow in wpa_supplicant 1.0 through 2.4 allows remote attackers to cause a denial of service (crash), read memory, or possibly execute arbitrary code via crafted SSID information in a management fram...Show more |
3Canonical DebianW1.fi4Debian Linux HostapdUbuntu Linux+1 moreMay 6, 2026 Oct 16, 2014 N/A· v4 N/A· v3 6.8 MEDIUM· v2 wpa_supplicant and hostapd 0.7.2 through 2.2, when running with certain configurations and using wpa_cli or hostapd_cli with action scripts, allows remote attackers to execute arbitrary commands via a crafted frame. |
Heap-based buffer overflow in the eap_server_tls_process_fragment function in eap_server_tls_common.c in the EAP authentication server in hostapd 0.6 through 1.0 allows remote attackers to cause a denial of service (cras...Show more |
hostapd 0.7.3, and possibly other versions before 1.0, uses 0644 permissions for /etc/hostapd/hostapd.conf, which might allow local users to obtain sensitive information such as credentials. |