threat
engine
.sh
Back
·
··:··
Home
/
Product
/
es iperf3
Product
es iperf3
8 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
Sort
Newest first
Oldest first
Highest CVSS
Lowest CVSS
Min CVSS
Any
4.0+
7.0+ (High)
9.0+ (Critical)
Published since
Reset
CVE-2025-54351
all versions
In iperf before 3.19.1, net.c has a buffer overflow when --skip-rx-copy is used (for MSG_TRUNC in recv).
8.9
HIGH
CVE-2025-54350
>= 3.2 and < 3.19.1
In iperf before 3.19.1, iperf_auth.c has a Base64Decode assertion failure and application exit upon a malformed authentication att
3.7
LOW
CVE-2025-54349
>= 3.2 and < 3.19.1
In iperf before 3.19.1, iperf_auth.c has an off-by-one error and resultant heap-based buffer overflow.
6.5
MEDIUM
CVE-2024-53580
all versions
iperf v3.17.1 was discovered to contain a segmentation violation via the iperf_exchange_parameters() function.
7.5
HIGH
CVE-2024-26306
< 3.17
iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA authentication, allows a timing side channel in RSA d
5.9
MEDIUM
CVE-2023-7250
< 3.15
A flaw was found in iperf, a utility for testing network performance using TCP, UDP, and SCTP. A malicious or malfunctioning clien
5.3
MEDIUM
CVE-2023-38403
< 3.14
iperf3 before 3.14 allows peers to cause an integer overflow and heap corruption via a crafted length field.
7.5
HIGH
CVE-2016-4303
>= 3.0 and < 3.0.12
The parse_string function in cjson.c in the cJSON library mishandles UTF8/16 strings, which allows remote attackers to cause a den
9.8
CRITICAL
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh · Open-source threat intelligence platform · 100+ authoritative sources · Every fact traces to its origin