VYPR

VPN Client

by Shrew

CVEs (3)

  • CVE-2019-25283HigFeb 5, 2026
    risk 0.51cvss 7.8epss 0.00

    Shrew Soft VPN Client 2.2.2 contains an unquoted service path vulnerability that allows local users to execute arbitrary code with elevated system privileges. Attackers can place malicious executables in the unquoted service path to gain elevated access during service startup or…

  • CVE-2010-3361Oct 20, 2010
    risk 0.00cvss epss 0.00

    The (1) iked, (2) ikea, and (3) ikec scripts in Shrew Soft IKE 2.1.5 place a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.

  • CVE-2002-2225Dec 31, 2002
    risk 0.00cvss epss 0.03

    SafeNet VPN client allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted Internet Key Exchange (IKE) response packets, possibly involving buffer overflows using (1) a large Security Parameter Index (SPI) field, (2) a large number of…