Cipherdyne maintains a focused set of network-security and firewall-management tools, primarily fwknop and fwsnort, that operate at the packet-processing layer where input validation and memory-safety requirements are strict. The recurring vulnerability signals center on improper input validation, buffer-boundary issues, and default-permission weaknesses, reflecting the parsing and privilege-separation demands of low-level security software. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cipherdyne over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-4434HIGH fwknop before 2.0.3 allow remote authenticated users to cause a denial of service (server crash) or possibly execute arbitrary code. | Jan 9, 2020 | 8.8 | 29 | NO | NO |
CVE-2014-0039MEDIUM Untrusted search path vulnerability in fwsnort before 1.6.4, when not running as root, allows local users to execute arbitrary code via a Trojan horse fwsnort.conf in the current w | Feb 8, 2014 | 4.4 | 18 | NO | NO |
CVE-2012-4435MEDIUM fwknop before 2.0.3 does not properly validate IP addresses, which allows remote authenticated users to cause a denial of service (server crash) via a long IP address. | Oct 22, 2012 | 4.0 | 17 | NO | NO |
CVE-2012-4436MEDIUM Buffer overflow in the run_last_args function in client/fwknop.c in fwknop before 2.0.3, when processing --last, might allow local users to cause a denial of service (client crash) | Oct 22, 2012 | 4.4 | 16 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cipherdyne.
Media articles that mention a CVE ID that affects a product developed by Cipherdyne — matched by CVE ID, not by vendor name.