TCP/IP stack
by Treck
CVEs (20)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-11899 | 0.15 | — | 0.34 | KEV | Jun 17, 2020 | The Treck TCP/IP stack before 6.0.1.66 has an IPv6 Out-of-bounds Read. | ||
| CVE-2020-11898 | 0.05 | — | 0.58 | Jun 17, 2020 | The Treck TCP/IP stack before 6.0.1.66 improperly handles an IPv4/ICMPv4 Length Parameter Inconsistency, which might allow remote attackers to trigger an information leak. | |||
| CVE-2020-11896 | 0.03 | — | 0.43 | Jun 17, 2020 | The Treck TCP/IP stack before 6.0.1.66 allows Remote Code Execution, related to IPv4 tunneling. | |||
| CVE-2020-11901 | 0.02 | — | 0.29 | Jun 17, 2020 | The Treck TCP/IP stack before 6.0.1.66 allows Remote Code execution via a single invalid DNS response. | |||
| CVE-2002-2438 | 0.01 | — | 0.08 | May 18, 2021 | TCP firewalls could be circumvented by sending a SYN Packets with other flags (like e.g. RST flag) set, which was not correctly discarded by the Linux TCP stack after firewalling. | |||
| CVE-2020-11900 | 0.01 | — | 0.08 | Jun 17, 2020 | The Treck TCP/IP stack before 6.0.1.41 has an IPv4 tunneling Double Free. | |||
| CVE-2020-11914 | 0.00 | — | 0.01 | Jun 17, 2020 | The Treck TCP/IP stack before 6.0.1.66 has an ARP Out-of-bounds Read. | |||
| CVE-2020-11913 | 0.00 | — | 0.03 | Jun 17, 2020 | The Treck TCP/IP stack before 6.0.1.66 has an IPv6 Out-of-bounds Read. | |||
| CVE-2020-11912 | 0.00 | — | 0.02 | Jun 17, 2020 | The Treck TCP/IP stack before 6.0.1.66 has a TCP Out-of-bounds Read. | |||
| CVE-2020-11911 | 0.00 | — | 0.03 | Jun 17, 2020 | The Treck TCP/IP stack before 6.0.1.66 has Improper ICMPv4 Access Control. | |||
| CVE-2020-11910 | 0.00 | — | 0.03 | Jun 17, 2020 | The Treck TCP/IP stack before 6.0.1.66 has an ICMPv4 Out-of-bounds Read. | |||
| CVE-2020-11909 | 0.00 | — | 0.02 | Jun 17, 2020 | The Treck TCP/IP stack before 6.0.1.66 has an IPv4 Integer Underflow. | |||
| CVE-2020-11908 | 0.00 | — | 0.01 | Jun 17, 2020 | The Treck TCP/IP stack before 4.7.1.27 mishandles '\0' termination in DHCP. | |||
| CVE-2020-11907 | 0.00 | — | 0.01 | Jun 17, 2020 | The Treck TCP/IP stack before 6.0.1.66 improperly handles a Length Parameter Inconsistency in TCP. | |||
| CVE-2020-11906 | 0.00 | — | 0.01 | Jun 17, 2020 | The Treck TCP/IP stack before 6.0.1.66 has an Ethernet Link Layer Integer Underflow. | |||
| CVE-2020-11905 | 0.00 | — | 0.01 | Jun 17, 2020 | The Treck TCP/IP stack before 6.0.1.66 has a DHCPv6 Out-of-bounds Read. | |||
| CVE-2020-11904 | 0.00 | — | 0.03 | Jun 17, 2020 | The Treck TCP/IP stack before 6.0.1.66 has an Integer Overflow during Memory Allocation that causes an Out-of-Bounds Write. | |||
| CVE-2020-11903 | 0.00 | — | 0.01 | Jun 17, 2020 | The Treck TCP/IP stack before 6.0.1.28 has a DHCP Out-of-bounds Read. | |||
| CVE-2020-11902 | 0.00 | — | 0.05 | Jun 17, 2020 | The Treck TCP/IP stack before 6.0.1.66 has an IPv6OverIPv4 tunneling Out-of-bounds Read. | |||
| CVE-2020-11897 | 0.00 | — | 0.02 | Jun 17, 2020 | The Treck TCP/IP stack before 5.0.1.35 has an Out-of-Bounds Write via multiple malformed IPv6 packets. |
- risk 0.15cvss —epss 0.34
The Treck TCP/IP stack before 6.0.1.66 has an IPv6 Out-of-bounds Read.
- CVE-2020-11898Jun 17, 2020risk 0.05cvss —epss 0.58
The Treck TCP/IP stack before 6.0.1.66 improperly handles an IPv4/ICMPv4 Length Parameter Inconsistency, which might allow remote attackers to trigger an information leak.
- CVE-2020-11896Jun 17, 2020risk 0.03cvss —epss 0.43
The Treck TCP/IP stack before 6.0.1.66 allows Remote Code Execution, related to IPv4 tunneling.
- CVE-2020-11901Jun 17, 2020risk 0.02cvss —epss 0.29
The Treck TCP/IP stack before 6.0.1.66 allows Remote Code execution via a single invalid DNS response.
- CVE-2002-2438May 18, 2021risk 0.01cvss —epss 0.08
TCP firewalls could be circumvented by sending a SYN Packets with other flags (like e.g. RST flag) set, which was not correctly discarded by the Linux TCP stack after firewalling.
- CVE-2020-11900Jun 17, 2020risk 0.01cvss —epss 0.08
The Treck TCP/IP stack before 6.0.1.41 has an IPv4 tunneling Double Free.
- CVE-2020-11914Jun 17, 2020risk 0.00cvss —epss 0.01
The Treck TCP/IP stack before 6.0.1.66 has an ARP Out-of-bounds Read.
- CVE-2020-11913Jun 17, 2020risk 0.00cvss —epss 0.03
The Treck TCP/IP stack before 6.0.1.66 has an IPv6 Out-of-bounds Read.
- CVE-2020-11912Jun 17, 2020risk 0.00cvss —epss 0.02
The Treck TCP/IP stack before 6.0.1.66 has a TCP Out-of-bounds Read.
- CVE-2020-11911Jun 17, 2020risk 0.00cvss —epss 0.03
The Treck TCP/IP stack before 6.0.1.66 has Improper ICMPv4 Access Control.
- CVE-2020-11910Jun 17, 2020risk 0.00cvss —epss 0.03
The Treck TCP/IP stack before 6.0.1.66 has an ICMPv4 Out-of-bounds Read.
- CVE-2020-11909Jun 17, 2020risk 0.00cvss —epss 0.02
The Treck TCP/IP stack before 6.0.1.66 has an IPv4 Integer Underflow.
- CVE-2020-11908Jun 17, 2020risk 0.00cvss —epss 0.01
The Treck TCP/IP stack before 4.7.1.27 mishandles '\0' termination in DHCP.
- CVE-2020-11907Jun 17, 2020risk 0.00cvss —epss 0.01
The Treck TCP/IP stack before 6.0.1.66 improperly handles a Length Parameter Inconsistency in TCP.
- CVE-2020-11906Jun 17, 2020risk 0.00cvss —epss 0.01
The Treck TCP/IP stack before 6.0.1.66 has an Ethernet Link Layer Integer Underflow.
- CVE-2020-11905Jun 17, 2020risk 0.00cvss —epss 0.01
The Treck TCP/IP stack before 6.0.1.66 has a DHCPv6 Out-of-bounds Read.
- CVE-2020-11904Jun 17, 2020risk 0.00cvss —epss 0.03
The Treck TCP/IP stack before 6.0.1.66 has an Integer Overflow during Memory Allocation that causes an Out-of-Bounds Write.
- CVE-2020-11903Jun 17, 2020risk 0.00cvss —epss 0.01
The Treck TCP/IP stack before 6.0.1.28 has a DHCP Out-of-bounds Read.
- CVE-2020-11902Jun 17, 2020risk 0.00cvss —epss 0.05
The Treck TCP/IP stack before 6.0.1.66 has an IPv6OverIPv4 tunneling Out-of-bounds Read.
- CVE-2020-11897Jun 17, 2020risk 0.00cvss —epss 0.02
The Treck TCP/IP stack before 5.0.1.35 has an Out-of-Bounds Write via multiple malformed IPv6 packets.