Openswan

    Dashboard / Vendors

    Products: 2
    Vulnerabilities: 6
    Known Exploited: 0
    1
    Critical Level Threats
    2
    High Level Threats
    2
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2011-2147

    openswan: World writable pid and lock files

    Last Modified: Apr 11, 2025
    Published: May 11, 2011

    CVE-2008-4966

    linux-patch-openswan 2.4.12 allows local users to overwrite arbitrary files via a symlink attack on (a) /tmp/snap##### and (b) /tmp/nightly##### temporary files, related to the (1) maysnap and (2) maytest scripts.

    Last Modified: Apr 23, 2026
    Published: Nov 06, 2008

    CVE-2008-4190

    openswan: Insecure auxiliary /tmp file usage (symlink attack possible)

    Last Modified: Apr 23, 2026
    Published: Aug 24, 2008

    CVE-2005-3671

    The Internet Key Exchange version 1 (IKEv1) implementation in Openswan 2 (openswan-2) before 2.4.4, and freeswan in SUSE LINUX 9.1 before 2.04_1.5.4-1.23, allow remote attackers to cause a denial of service via (1) a crafted packet using 3DES with an invalid key length, or (2) unspecified inputs when Aggressive Mode is enabled and the PSK is known, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1.

    Last Modified: Apr 16, 2026
    Published: Nov 18, 2005

    CVE-2005-0162

    Stack-based buffer overflow in the get_internal_addresses function in the pluto application for Openswan 1.x before 1.0.9, and Openswan 2.x before 2.3.0, when compiled with XAUTH and PAM enabled, allows remote authenticated attackers to execute arbitrary code.

    Last Modified: Apr 16, 2026
    Published: Jan 26, 2005
    Items Per Page