es iperf3 CVE Vulnerabilities (8)

CVEs: 8 CPE versions: View versions table

Summary

This page lists publicly disclosed CVE vulnerabilities affecting es iperf3 (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.

Showing 18 of 8 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2025-54351 In iperf before 3.19.1, net.c has a buffer overflow when --skip-rx-copy is used (for MSG_TRUNC in recv). [email protected] 8.9 0.26% 2025-08-03 2025-10-17
CVE-2025-54350 In iperf before 3.19.1, iperf_auth.c has a Base64Decode assertion failure and application exit upon a malformed authentication attempt. [email protected] 3.7 0.12% 2025-08-03 2025-11-03
CVE-2025-54349 In iperf before 3.19.1, iperf_auth.c has an off-by-one error and resultant heap-based buffer overflow. [email protected] 6.5 0.29% 2025-08-03 2025-11-03
CVE-2024-53580 iperf v3.17.1 was discovered to contain a segmentation violation via the iperf_exchange_parameters() function. [email protected] 7.5 0.23% 2024-12-18 2025-11-03
CVE-2024-26306 iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA authentication, allows a timing side channel in RSA decryption operations. This side channel could be sufficient for an attacker to recover credential plaintext. It requires the attacker to send a large number of messages for decryption, as described in "Everlasting ROBOT: the Marvin Attack" by Hubert Kario. [email protected] 5.9 1.12% 2024-05-14 2025-11-03
CVE-2023-7250 A flaw was found in iperf, a utility for testing network performance using TCP, UDP, and SCTP. A malicious or malfunctioning client can send less than the expected amount of data to the iperf server, which can cause the server to hang indefinitely waiting for the remainder or until the connection gets closed. This will prevent other connections to the server, leading to a denial of service. [email protected] 5.3 0.05% 2024-03-18 2025-11-03
CVE-2023-38403 iperf3 before 3.14 allows peers to cause an integer overflow and heap corruption via a crafted length field. [email protected] 7.5 1.25% 2023-07-17 2024-11-21
CVE-2016-4303 The parse_string function in cjson.c in the cJSON library mishandles UTF8/16 strings, which allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a non-hex character in a JSON string, which triggers a heap-based buffer overflow. [email protected] 9.8 7.58% 2016-09-26 2026-05-06
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence