CVE-2013-4147
23Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 3.7%
from disclosure to weapon0 days
Published on NVDAug 9
1st PoCJun 30
exploitation probability
3.7%top 11% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Multiple format string vulnerabilities in Yet Another Radius Daemon (YARD RADIUS) 1.1.2 allow context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via format string specifiers in a request in the (1) log_msg function in log.c or (2) version or (3) build_version function in version.c.
Affected products
n/a · n/apublic PoCs found — 1✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/38672⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.