shrew CVE Vulnerabilities & CVE List (2)

Products (CPE): — CVEs: 2

shrew vulnerability overview

This page aggregates publicly disclosed CVE and security risk information related to shrew, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.

Vulnerability distribution trend (last 24 months)

Showing 12 of 2 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2019-25283 Shrew Soft VPN Client 2.2.2 contains an unquoted service path vulnerability that allows local users to execute arbitrary code with elevated system privileges. Attackers can place malicious executables in the unquoted service path to gain elevated access during service startup or system reboot. [email protected] 8.5 0.16% 2026-02-04 2026-06-16
CVE-2010-3361 The (1) iked, (2) ikea, and (3) ikec scripts in Shrew Soft IKE 2.1.5 place a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory. [email protected] 6.9 0.38% 2010-10-20 2026-06-16
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence