The Point to Point Protocol Project maintains a foundational network communication protocol that, despite its narrow product scope, underlies dial-up, VPN, and other point-to-point connectivity implementations across diverse endpoints and systems. Vulnerabilities affecting this protocol reflect the parsing and state-management demands inherent to a legacy, widely implemented network standard. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Point To Point Protocol Project over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-8597CRITICAL eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions. | Feb 3, 2020 | 9.8 | 41 | NO | NO |
CVE-2018-11574CRITICAL Improper input validation together with an integer overflow in the EAP-TLS protocol implementation in PPPD may cause a crash, information disclosure, or authentication bypass. This | Jun 14, 2018 | 9.8 | 29 | NO | NO |
CVE-2014-3158HIGH Integer overflow in the getword function in options.c in pppd in Paul's PPP Package (ppp) before 2.4.7 allows attackers to "access privileged options" via a long word in an options | Nov 15, 2014 | 7.5 | 20 | NO | NO |
CVE-2004-2695HIGH SQL injection vulnerability in the Authorize.net callback code (subscriptions/authorize.php) in Jelsoft vBulletin 3.0 through 3.0.3 allows remote attackers to execute arbitrary SQL | Dec 31, 2004 | 7.5 | 20 | NO | NO |
CVE-2006-2194HIGH The winbind plugin in pppd for ppp 2.4.4 and earlier does not check the return code from the setuid function call, which might allow local users to gain privileges by causing setui | Jul 5, 2006 | 7.2 | 18 | NO | NO |
CVE-2015-3310MEDIUM Buffer overflow in the rc_mksid function in plugins/radius/util.c in Paul's PPP Package (ppp) 2.4.6 and earlier, when the PID for pppd is greater than 65535, allows remote attacker | Apr 24, 2015 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Point To Point Protocol Project.
Media articles that mention a CVE ID that affects a product developed by Point To Point Protocol Project — matched by CVE ID, not by vendor name.