Infradead
6 CVEs tracked since 2010. Since Oct 2010, none of them reached CISA KEV.
Infradead CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2010-10 | 4 | 0 |
| 2010-11 | null or fewer | |
| 2010-12 | null or fewer | |
| 2011-01 | null or fewer | |
| 2011-02 | null or fewer | |
| 2011-03 | null or fewer | |
| 2011-04 | null or fewer | |
| 2011-05 | null or fewer | |
| 2011-06 | null or fewer | |
| 2011-07 | null or fewer | |
| 2011-08 | null or fewer | |
| 2011-09 | null or fewer | |
| 2011-10 | null or fewer | |
| 2011-11 | null or fewer | |
| 2011-12 | null or fewer | |
| 2012-01 | null or fewer | |
| 2012-02 | null or fewer | |
| 2012-03 | null or fewer | |
| 2012-04 | null or fewer | |
| 2012-05 | null or fewer | |
| 2012-06 | 1 | 0 |
| 2012-07 | null or fewer | |
| 2012-08 | null or fewer | |
| 2012-09 | null or fewer | |
| 2012-10 | null or fewer | |
| 2012-11 | null or fewer | |
| 2012-12 | null or fewer | |
| 2013-01 | null or fewer | |
| 2013-02 | 1 | 0 |
Products
The products that kept showing up in Infradead's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 10 most recently published vulnerabilities affecting Infradead.
- CVE-2020-12823OpenConnect 8.09 has a buffer overflow, causing a denial of service (application crash) or possibly unspecified other impact, via crafted certificate data to get_cert_name in gnutls.c.9.8
- CVE-2020-12105OpenConnect through 8.08 mishandles negative return values from X509_check_ function calls, which might assist attackers in performing man-in-the-middle attacks.5.9
- CVE-2013-7098OpenConnect VPN client with GnuTLS before 5.02 contains a heap overflow if MTU is increased on reconnection.9.8
- CVE-2019-16239process_http_response in OpenConnect before 8.05 has a Buffer Overflow when a malicious server uses HTTP chunked encoding with crafted chunk sizes.9.8
- CVE-2012-6128Multiple stack-based buffer overflows in http.c in OpenConnect before 4.08 allow remote VPN gateways to cause a denial of service (application crash) via a long (1) hostname, (2) path, or (3) cooki...5.0
- CVE-2012-3291Heap-based buffer overflow in OpenConnect 3.18 allows remote servers to cause a denial of service via a crafted greeting banner.7.8
- CVE-2010-3903Unspecified vulnerability in OpenConnect before 2.23 allows remote AnyConnect SSL VPN servers to cause a denial of service (application crash) via a 404 HTTP status code.5.0
- CVE-2010-3902OpenConnect before 2.26 places the webvpn cookie value in the debugging output, which might allow remote attackers to obtain sensitive information by reading this output, as demonstrated by output ...5.0
- CVE-2010-3901OpenConnect before 2.25 does not properly validate X.509 certificates, which allows man-in-the-middle attackers to spoof arbitrary AnyConnect SSL VPN servers via a crafted server certificate that (...6.4
- CVE-2009-5009Double free vulnerability in OpenConnect before 1.40 might allow remote AnyConnect SSL VPN servers to cause a denial of service (application crash) or possibly have unspecified other impact via a c...5.0
The record
- Peak rank
- #22 in Oct 2010
- Busiest month shown
- Oct 2010, 4 CVEs
- Months with a KEV entry
- 0 since Oct 2010
- Monthly snapshots
- 3 since 2010