Netfilter maintains a critical packet-filtering and connection-tracking infrastructure used across Linux-based firewalls and gateways, with its durable exposure centered on the widely deployed iptables and conntrack-tools components. The observed weakness classes recur around resource management and boundary conditions, including unthrottled resource allocation and out-of-bounds write conditions characteristic of low-level kernel-space networking code; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Netfilter over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-2663HIGH extensions/libxt_tcp.c in iptables through 1.4.21 does not match TCP SYN+FIN packets in --syn rules, which might allow remote attackers to bypass intended firewall restrictions via | Feb 15, 2014 | 7.5 | 24 | NO | NO |
CVE-2019-11360MEDIUM A buffer overflow in iptables-restore in netfilter iptables 1.8.2 allows an attacker to (at least) crash the program or potentially gain code execution via a specially crafted ipta | Jul 12, 2019 | 4.2 | 18 | NO | NO |
CVE-2001-1388MEDIUM iptables before 1.2.4 does not accurately convert rate limits that are specified on the command line, which could allow attackers or users to generate more or less traffic than int | Nov 5, 2001 | 5.0 | 17 | NO | NO |
CVE-2015-6496MEDIUM conntrackd in conntrack-tools 1.4.2 and earlier does not ensure that the optional kernel modules are loaded before using them, which allows remote attackers to cause a denial of se | Aug 24, 2015 | 5.0 | 16 | NO | NO |
iptables-save in iptables before 1.2.4 records the "--reject-with icmp-host-prohibited" rule as "--reject-with tcp-reset," which causes iptables to generate different responses tha | Nov 5, 2001 | 2.1 | 12 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Netfilter.
Media articles that mention a CVE ID that affects a product developed by Netfilter — matched by CVE ID, not by vendor name.