Nufw is a narrowly scoped open-source firewall and filtering framework whose vulnerability profile centers on its core firewall product and is characterized by memory-buffer handling issues and boundary-enforcement weaknesses. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nufw over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-3950MEDIUM nuauth in NuFW 1.0.x before 1.0.16 and 1.1 allows authenticated users to cause a denial of service via malformed packets. | Dec 1, 2005 | 6.8 | 18 | NO | NO |
CVE-2007-5723MEDIUM Heap-based buffer overflow in the samp_send function in nuauth/sasl.c in NuFW before 2.2.7 allows remote attackers to cause a denial of service via unspecified input on which base6 | Oct 30, 2007 | 5.0 | 15 | NO | NO |
CVE-2007-4461MEDIUM NuFW 2.2.3, and certain other versions after 2.0, allows remote attackers to bypass time-based packet filtering rules via certain "out of period" choices of packet transmission tim | Aug 21, 2007 | 4.3 | 14 | NO | NO |
nuauth in NuFW before 1.0.21 does not properly handle blocking TLS sockets, which allows remote authenticated users to cause a denial of service (service hang) by flooding packets | Mar 2, 2006 | 1.7 | 13 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nufw.
Media articles that mention a CVE ID that affects a product developed by Nufw — matched by CVE ID, not by vendor name.