CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

es

iperf3

7 known vulnerabilities · sorted by CVSS score

CVE-2025-54351
HIGH8.9

In iperf before 3.19.1, net.c has a buffer overflow when --skip-rx-copy is used (for MSG_TRUNC in recv).

es / iperf3
Network
Published Aug 3, 2025
CVE-2024-53580
HIGH7.5

iperf v3.17.1 was discovered to contain a segmentation violation via the iperf_exchange_parameters() function.

es / iperf3+2
Network
Published Dec 18, 2024
CVE-2023-38403
HIGH7.5

iperf3 before 3.14 allows peers to cause an integer overflow and heap corruption via a crafted length field.

es / iperf3+7
Network
Published Jul 17, 2023
CVE-2025-54349
MEDIUM6.5

In iperf before 3.19.1, iperf_auth.c has an off-by-one error and resultant heap-based buffer overflow.

es / iperf3
Network
Published Aug 3, 2025
CVE-2024-26306
MEDIUM5.9

iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA authentication, allows a timing side channel in RSA decryption operations. This side channel could be sufficient for an attacker to recover credential plaintext. It requires the attacker to send a large number of messages for decryption, as described in "Everlasting ROBOT: the Marvin Attack" by Hubert Kario.

es / iperf3+1
Network
Published May 14, 2024
CVE-2023-7250
MEDIUM5.3

A flaw was found in iperf, a utility for testing network performance using TCP, UDP, and SCTP. A malicious or malfunctioning client can send less than the expected amount of data to the iperf server, which can cause the server to hang indefinitely waiting for the remainder or until the connection gets closed. This will prevent other connections to the server, leading to a denial of service.

es / iperf3+7
Network
Published Mar 18, 2024
CVE-2025-54350
LOW3.7

In iperf before 3.19.1, iperf_auth.c has a Base64Decode assertion failure and application exit upon a malformed authentication attempt.

es / iperf3
Network
Published Aug 3, 2025