Esnet
Products
2- 7 CVEs
- 4 CVEs
Recent CVEs
11| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2016-4303 | Cri | 0.64 | 9.8 | 0.07 | Sep 26, 2016 | The parse_string function in cjson.c in the cJSON library mishandles UTF8/16 strings, which allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a non-hex character in a JSON string, which triggers a heap-based buffer overflow. | ||
| CVE-2024-53580 | Hig | 0.49 | 7.5 | 0.01 | Dec 18, 2024 | iperf v3.17.1 was discovered to contain a segmentation violation via the iperf_exchange_parameters() function. | ||
| CVE-2026-71217 | Hig | 0.42 | 7.5 | 0.00 | Aug 11, 2026 | A flaw was found in iperf3. A remote attacker can exploit this vulnerability by sending crafted control-channel JSON with oversized numeric parameters, such as `parallel` and `len`, which are not properly validated by the server. This improper input validation can lead to… | ||
| CVE-2018-12525 | Med | 0.38 | 5.3 | 0.07 | Jun 18, 2018 | An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /images/ provides a directory listing. | ||
| CVE-2018-12524 | Med | 0.38 | 5.3 | 0.07 | Jun 18, 2018 | An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /lib/ provides a directory listing. | ||
| CVE-2018-12523 | Med | 0.38 | 5.3 | 0.07 | Jun 18, 2018 | An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /etc/ provides a directory listing. | ||
| CVE-2018-12522 | Med | 0.38 | 5.3 | 0.07 | Jun 18, 2018 | An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /style/ provides a directory listing. | ||
| CVE-2026-71218 | Med | 0.27 | 5.3 | 0.00 | Aug 11, 2026 | A flaw was found in iperf3. A remote unauthenticated attacker can exploit a vulnerability in the `JSON_read()` function, which accepts a peer-controlled message length and allocates memory without an upper bound. This allows the attacker to trigger excessive memory consumption,… | ||
| CVE-2025-54351 | Hig | 0.00 | 8.9 | 0.00 | Aug 3, 2025 | In iperf before 3.19.1, net.c has a buffer overflow when --skip-rx-copy is used (for MSG_TRUNC in recv). | ||
| CVE-2025-54350 | Low | 0.00 | 3.7 | 0.00 | Aug 3, 2025 | In iperf before 3.19.1, iperf_auth.c has a Base64Decode assertion failure and application exit upon a malformed authentication attempt. | ||
| CVE-2025-54349 | Med | 0.00 | 6.5 | 0.00 | Aug 3, 2025 | In iperf before 3.19.1, iperf_auth.c has an off-by-one error and resultant heap-based buffer overflow. |
- risk 0.64cvss 9.8epss 0.07
The parse_string function in cjson.c in the cJSON library mishandles UTF8/16 strings, which allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a non-hex character in a JSON string, which triggers a heap-based buffer overflow.
- risk 0.49cvss 7.5epss 0.01
iperf v3.17.1 was discovered to contain a segmentation violation via the iperf_exchange_parameters() function.
- risk 0.42cvss 7.5epss 0.00
A flaw was found in iperf3. A remote attacker can exploit this vulnerability by sending crafted control-channel JSON with oversized numeric parameters, such as `parallel` and `len`, which are not properly validated by the server. This improper input validation can lead to…
- risk 0.38cvss 5.3epss 0.07
An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /images/ provides a directory listing.
- risk 0.38cvss 5.3epss 0.07
An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /lib/ provides a directory listing.
- risk 0.38cvss 5.3epss 0.07
An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /etc/ provides a directory listing.
- risk 0.38cvss 5.3epss 0.07
An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /style/ provides a directory listing.
- risk 0.27cvss 5.3epss 0.00
A flaw was found in iperf3. A remote unauthenticated attacker can exploit a vulnerability in the `JSON_read()` function, which accepts a peer-controlled message length and allocates memory without an upper bound. This allows the attacker to trigger excessive memory consumption,…
- risk 0.00cvss 8.9epss 0.00
In iperf before 3.19.1, net.c has a buffer overflow when --skip-rx-copy is used (for MSG_TRUNC in recv).
- risk 0.00cvss 3.7epss 0.00
In iperf before 3.19.1, iperf_auth.c has a Base64Decode assertion failure and application exit upon a malformed authentication attempt.
- risk 0.00cvss 6.5epss 0.00
In iperf before 3.19.1, iperf_auth.c has an off-by-one error and resultant heap-based buffer overflow.