Search CVE reports


Toggle filters

1 – 7 of 7 results


CVE-2025-54351

Medium priority
Needs evaluation

In iperf before 3.19.1, net.c has a buffer overflow when --skip-rx-copy is used (for MSG_TRUNC in recv).

1 affected package

iperf3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
iperf3 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-54350

Medium priority
Needs evaluation

In iperf before 3.19.1, iperf_auth.c has a Base64Decode assertion failure and application exit upon a malformed authentication attempt.

1 affected package

iperf3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
iperf3 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-54349

Medium priority
Needs evaluation

In iperf before 3.19.1, iperf_auth.c has an off-by-one error and resultant heap-based buffer overflow.

1 affected package

iperf3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
iperf3 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-26306

Medium priority
Needs evaluation

iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA authentication, allows a timing side channel in RSA decryption operations. This side channel could be sufficient for an attacker to recover credential...

1 affected package

iperf3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
iperf3 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2023-7250

Medium priority
Needs evaluation

A flaw was found in iperf, a utility for testing network performance using TCP, UDP, and SCTP. A malicious or malfunctioning client can send less than the expected amount of data to the iperf server, which can cause the server to...

1 affected package

iperf3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
iperf3 Not affected Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2023-38403

Medium priority

Some fixes available 5 of 10

iperf3 before 3.14 allows peers to cause an integer overflow and heap corruption via a crafted length field.

1 affected package

iperf3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
iperf3 Needs evaluation Fixed Fixed Fixed
Show less packages

CVE-2016-4303

Medium priority

Some fixes available 1 of 5

The parse_string function in cjson.c in the cJSON library mishandles UTF8/16 strings, which allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a non-hex character in a JSON string, which...

2 affected packages

iperf, iperf3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
iperf Not affected Not affected Not affected
iperf3 Not affected Not affected Not affected
Show less packages