Xsupplicant is a narrowly scoped IEEE 802.1X authentication client whose vulnerability footprint centers on its core implementation, with the principal observed weakness class being improper memory-buffer boundary management. The product's role as an authentication agent at the network edge places it in sensitive contexts where input validation and memory safety are critical; current exposure counts and severity details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xsupplicant over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-5601HIGH Stack-based buffer overflow in the eap_do_notify function in eap.c in xsupplicant before 1.2.6, and possibly other versions, allows remote authenticated users to execute arbitrary | Oct 28, 2006 | 9.0 | 24 | NO | NO |
CVE-2006-5602MEDIUM Multiple memory leaks in xsupplicant before 1.2.6, and possibly other versions, allow attackers to cause a denial of service (memory consumption) via unspecified vectors. | Oct 28, 2006 | 4.0 | 14 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xsupplicant.
Media articles that mention a CVE ID that affects a product developed by Xsupplicant — matched by CVE ID, not by vendor name.