Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Quagga

First CVE: Dec 15, 2003Active for: 23 yearsTotal CVEs: 36
39.1
VTI Score
Medium

Quagga is an open-source routing software suite that implements dynamic routing protocols for Unix-like systems and is widely embedded in network appliances, routers, and infrastructure where it handles BGP, OSPF, and RIP functions. Despite its focused product scope, the software occupies a prominent role in network infrastructure and has accumulated meaningful vulnerability exposure centered on memory-safety and input-handling defects. The recurring weakness classes—buffer-boundary violations, improper input validation, and double-free conditions—reflect the low-level packet parsing and protocol-state management inherent to a routing daemon that processes untrusted network traffic. Vulnerabilities affecting this vendor lean toward serious outcomes and have shown a moderate tendency to acquire public exploit code, making timely patching important for network operators maintaining Quagga deployments. Current exploitation activity, severity breakdown, and exposure counts are shown alongside this summary.

FAUCET AI Generated
36
Total CVEs
More Total CVEs than 98% of tracked vendors
1.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 76% of tracked vendors
5.6
Avg CVSS Score
Higher Avg CVSS Score than 24% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Quagga over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 15, 2003
22 years ago
Most Recent CVE
Nov 19, 2021
1,709 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (36 CVEs).

36 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-5378MEDIUM
The Quagga BGP daemon (bgpd) prior to version 1.2.3 does not properly bounds check the data sent with a NOTIFY to a peer, if an attribute length is invalid. Arbitrary data from the
Feb 19, 20185.959NONO
CVE-2018-5379CRITICAL
The Quagga BGP daemon (bgpd) prior to version 1.2.3 can double-free memory when processing certain forms of UPDATE message, containing cluster-list and/or unknown attributes. A suc
Feb 19, 20189.851NONO
CVE-2018-5381HIGH
The Quagga BGP daemon (bgpd) prior to version 1.2.3 has a bug in its parsing of "Capabilities" in BGP OPEN messages, in the bgp_packet.c:bgp_capability_msg_parse function. The pars
Feb 19, 20187.539NONO
CVE-2017-5495HIGH
All versions of Quagga, 0.93 through 1.1.0, are vulnerable to an unbounded memory allocation in the telnet 'vty' CLI, leading to a Denial-of-Service of Quagga daemons, or even the
Jan 24, 20177.535NONO
CVE-2017-16227HIGH
The aspath_put function in bgpd/bgp_aspath.c in Quagga before 1.2.2 allows remote attackers to cause a denial of service (session drop) via BGP UPDATE messages, because AS_PATH siz
Oct 29, 20177.533NONO
CVE-2016-2342HIGH
The bgp_nlri_parse_vpnv4 function in bgp_mplsvpn.c in the VPNv4 NLRI parser in bgpd in Quagga before 1.0.20160309, when a certain VPNv4 configuration is used, relies on a Labeled-V
Mar 17, 20168.132NONO
CVE-2016-4049HIGH
The bgp_dump_routes_func function in bgpd/bgp_dump.c in Quagga does not perform size checks when dumping data, which might allow remote attackers to cause a denial of service (asse
May 23, 20167.528NONO
CVE-2006-2223MEDIUM
RIPd in Quagga 0.98 and 0.99 before 20060503 does not properly implement configurations that (1) disable RIPv1 or (2) require plaintext or MD5 authentication, which allows remote a
May 5, 20065.027NOYES
CVE-2006-2224MEDIUM
RIPd in Quagga 0.98 and 0.99 before 20060503 does not properly enforce RIPv2 authentication requirements, which allows remote attackers to modify routing state via RIPv1 RESPONSE p
May 5, 20065.026NOYES
CVE-2021-44038HIGH
An issue was discovered in Quagga through 1.2.4. Unsafe chown/chmod operations in the suggested spec file allow users (with control of the non-root-owned directory /etc/quagga) to
Nov 19, 20217.825NONO
View all 36 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products36 CVEs
17%
56%
22%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (2.8%)
Network9 (25.0%)
Unknown24 (66.7%)
Physical0 (0.0%)
Adjacent Network2 (5.6%)
Attack Complexity
Low9 (25.0%)
High3 (8.3%)
Unknown24 (66.7%)
User Interaction
None12 (33.3%)
Unknown24 (66.7%)
Required0 (0.0%)
Privileges Required
Low3 (8.3%)
High0 (0.0%)
None9 (25.0%)
Unknown24 (66.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (36 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
8.3% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Quagga.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Quagga — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Quagga's Products

View all 4 CNAs →

Top CWEs