Madwifi is a legacy open-source wireless driver project with a narrowly scoped product footprint that achieved prominence as a widely deployed alternative for Wi-Fi device support on Linux systems. Its vulnerabilities cluster around memory-safety and input-validation weaknesses characteristic of kernel-level networking code, and a moderate tendency toward public exploit availability reflects the accessibility of the driver to local and remote attackers on affected systems. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Madwifi over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-6332HIGH Stack-based buffer overflow in net80211/ieee80211_wireless.c in MadWifi before 0.9.2.1 allows remote attackers to execute arbitrary code via unspecified vectors, related to the enc | Dec 10, 2006 | 7.5 | 41 | NO | YES |
CVE-2007-2831HIGH Array index error in the (1) ieee80211_ioctl_getwmmparams and (2) ieee80211_ioctl_setwmmparams functions in net80211/ieee80211_wireless.c in MadWifi before 0.9.3.1 allows local use | May 24, 2007 | 10.0 | 25 | NO | NO |
CVE-2006-7177HIGH MadWifi, when Ad-Hoc mode is used, allows remote attackers to cause a denial of service (system crash) via unspecified vectors that lead to a kernel panic in the ieee80211_input fu | Mar 30, 2007 | 7.8 | 20 | NO | NO |
CVE-2006-7178HIGH MadWifi before 0.9.3 does not properly handle reception of an AUTH frame by an IBSS node, which allows remote attackers to cause a denial of service (system crash) via a certain AU | Mar 30, 2007 | 7.8 | 20 | NO | NO |
CVE-2006-7179HIGH ieee80211_input.c in MadWifi before 0.9.3 does not properly process Channel Switch Announcement Information Elements (CSA IEs), which allows remote attackers to cause a denial of s | Mar 30, 2007 | 7.8 | 20 | NO | NO |
CVE-2005-4835HIGH The ath_rate_sample function in the ath_rate/sample/sample.c sample code in MadWifi before 0.9.3 allows remote attackers to cause a denial of service (failed KASSERT and system cra | Dec 31, 2005 | 7.1 | 19 | NO | NO |
CVE-2006-7180MEDIUM ieee80211_output.c in MadWifi before 0.9.3 sends unencrypted packets before WPA authentication succeeds, which allows remote attackers to obtain sensitive information (related to n | Mar 30, 2007 | 6.8 | 18 | NO | NO |
CVE-2007-2829MEDIUM The 802.11 network stack in net80211/ieee80211_input.c in MadWifi before 0.9.3.1 allows remote attackers to cause a denial of service (system hang) via a crafted length field in ne | May 24, 2007 | 5.0 | 16 | NO | NO |
CVE-2007-2830MEDIUM The ath_beacon_config function in if_ath.c in MadWifi before 0.9.3.1 allows remote attackers to cause a denial of service (system crash) via crafted beacon interval information whe | May 24, 2007 | 5.0 | 15 | NO | NO |
CVE-2007-5448MEDIUM Madwifi 0.9.3.2 and earlier allows remote attackers to cause a denial of service (panic) via a beacon frame with a large length value in the extended supported rates (xrates) eleme | Oct 14, 2007 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Madwifi.
Media articles that mention a CVE ID that affects a product developed by Madwifi — matched by CVE ID, not by vendor name.