- Weak default key in config_auth() - CVE-2014-9293 - non-cryptographic random number generator with weak seed used by ntp-keygen to generate symmetric keys - CVE-2014-9294 - Buffer overflow in crypto_recv() - CVE-2014-9295 - Buffer overflow in ctl_putdata() - CVE-2014-9295 - Buffer overflow in configure() - CVE-2014-9295 - receive(): missing return on error - CVE-2014-9296 ok naddy@