Vulnerabilities (CVE)

Filtered by CWE-228
Total 21 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-5381 4 Canonical, Debian, Quagga and 1 more 5 Ubuntu Linux, Debian Linux, Quagga and 2 more 2026-06-17 5.0 MEDIUM 6.5 MEDIUM
The Quagga BGP daemon (bgpd) prior to version 1.2.3 has a bug in its parsing of "Capabilities" in BGP OPEN messages, in the bgp_packet.c:bgp_capability_msg_parse function. The parser can enter an infinite loop on invalid capabilities if a Multi-Protocol capability does not have a recognized AFI/SAFI, causing a denial of service.