Yard Radius Project maintains a narrowly scoped project centered on the Yard Radius product, a specialized networking or authentication component with observed vulnerabilities involving format-string weaknesses and other input-handling issues. Treat this as a compact vendor profile; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Yard Radius Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-0987HIGH Buffer overflow in the process_menu function in yardradius 1.0.20 allows remote attackers to execute arbitrary code. | Jan 10, 2005 | 10.0 | 32 | NO | NO |
CVE-2013-4147HIGH Multiple format string vulnerabilities in Yet Another Radius Daemon (YARD RADIUS) 1.1.2 allow context-dependent attackers to cause a denial of service (crash) or possibly execute a | Aug 9, 2013 | 7.5 | 29 | NO | YES |
CVE-2001-1376HIGH Buffer overflow in digest calculation function of multiple RADIUS implementations allows remote attackers to cause a denial of service and possibly execute arbitrary code via share | Mar 4, 2002 | 7.5 | 22 | NO | NO |
CVE-2001-1377MEDIUM Multiple RADIUS implementations do not properly validate the Vendor-Length of the Vendor-Specific attribute, which allows remote attackers to cause a denial of service (crash) via | Mar 4, 2002 | 5.0 | 21 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Yard Radius Project.
Media articles that mention a CVE ID that affects a product developed by Yard Radius Project — matched by CVE ID, not by vendor name.