Yard Radius is a narrowly scoped vendor with a focused product line, where the observed vulnerability record centers on its core offering. The durable exposure profile reflects the product's functional scope rather than a broad attack surface; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Yard Radius over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-0987HIGH Buffer overflow in the process_menu function in yardradius 1.0.20 allows remote attackers to execute arbitrary code. | Jan 10, 2005 | 10.0 | 32 | NO | NO |
CVE-2013-4147HIGH Multiple format string vulnerabilities in Yet Another Radius Daemon (YARD RADIUS) 1.1.2 allow context-dependent attackers to cause a denial of service (crash) or possibly execute a | Aug 9, 2013 | 7.5 | 29 | NO | YES |
CVE-2001-1376HIGH Buffer overflow in digest calculation function of multiple RADIUS implementations allows remote attackers to cause a denial of service and possibly execute arbitrary code via share | Mar 4, 2002 | 7.5 | 22 | NO | NO |
CVE-2001-1377MEDIUM Multiple RADIUS implementations do not properly validate the Vendor-Length of the Vendor-Specific attribute, which allows remote attackers to cause a denial of service (crash) via | Mar 4, 2002 | 5.0 | 21 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Yard Radius.
Media articles that mention a CVE ID that affects a product developed by Yard Radius — matched by CVE ID, not by vendor name.