Vendorscipherdynefwknop2.0.1
Vulnerabilities

cipherdyne fwknop 2.0.1

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2012-4436
Buffer overflow in the run_last_args function in client/fwknop.c in fwknop before 2.0.3, when processing --last, might allow local users to cause a denial of service (client crash) and possibly execute arbitrary code via many .fwknop.run arguments.
Published 2012-10-22 · Modified
4.4EPSS 0.007
CVE-2012-4435
fwknop before 2.0.3 does not properly validate IP addresses, which allows remote authenticated users to cause a denial of service (server crash) via a long IP address.
Published 2012-10-22 · Modified
4.0EPSS 0.023