Search CVE reports


Toggle filters

1 – 9 of 9 results


CVE-2025-54351

Medium priority
Needs evaluation

In iperf before 3.19.1, net.c has a buffer overflow when --skip-rx-copy is used (for MSG_TRUNC in recv).

1 affected package

iperf3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
iperf3 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-54350

Medium priority

Some fixes available 4 of 5

In iperf before 3.19.1, iperf_auth.c has a Base64Decode assertion failure and application exit upon a malformed authentication attempt.

1 affected package

iperf3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
iperf3 Fixed Fixed Fixed Not affected
Show less packages

CVE-2025-54349

Medium priority

Some fixes available 4 of 5

In iperf before 3.19.1, iperf_auth.c has an off-by-one error and resultant heap-based buffer overflow.

1 affected package

iperf3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
iperf3 Fixed Fixed Fixed Not affected
Show less packages

CVE-2024-53580

Medium priority

Some fixes available 3 of 14

iperf v3.17.1 was discovered to contain a segmentation violation via the iperf_exchange_parameters() function.

2 affected packages

iperf, iperf3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
iperf Needs evaluation Needs evaluation Needs evaluation Needs evaluation
iperf3 Fixed Fixed Fixed Ignored
Show less packages

CVE-2024-26306

Medium priority

Some fixes available 3 of 8

iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA authentication, allows a timing side channel in RSA decryption operations. This side channel could be sufficient for an attacker to recover credential...

1 affected package

iperf3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
iperf3 Fixed Fixed Fixed Ignored
Show less packages

CVE-2023-26306

Medium priority

Some fixes available 3 of 8

iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA authentication, allows a timing side channel in RSA decryption operations. This side channel could be sufficient for an attacker to recover credential...

1 affected package

iperf3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
iperf3 Fixed Fixed Fixed Ignored
Show less packages

CVE-2023-7250

Medium priority

Some fixes available 4 of 5

A flaw was found in iperf, a utility for testing network performance using TCP, UDP, and SCTP. A malicious or malfunctioning client can send less than the expected amount of data to the iperf server, which can cause the server to...

1 affected package

iperf3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
iperf3 Not affected Fixed Fixed Fixed
Show less packages

CVE-2023-38403

Medium priority

Some fixes available 5 of 11

iperf3 before 3.14 allows peers to cause an integer overflow and heap corruption via a crafted length field.

1 affected package

iperf3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
iperf3 Needs evaluation Fixed Fixed Fixed
Show less packages

CVE-2016-4303

Medium priority

Some fixes available 1 of 5

The parse_string function in cjson.c in the cJSON library mishandles UTF8/16 strings, which allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a non-hex character in a JSON string, which...

2 affected packages

iperf, iperf3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
iperf Not affected Not affected Not affected
iperf3 Not affected Not affected Not affected
Show less packages