Skip to content
Noroxi

IETF records

17 published records for vendor ietf.

Researcher profile

Entered KEV
1 · 5.9%
Weaponized
1 · 5.9%
Pre-auth RCE
0
With a fix record
23.5%
Median publish → KEV
0 days

All records

17 records
  • The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as

    HighCVSS 7.5KEVWeaponizedEPSS 100%

    siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmwareOct 10, 2023

  • The MD5 Message-Digest Algorithm is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attac

    CriticalCVSS 9.8Proof of conceptEPSS 10%

    ietf · md5Jan 5, 2009

  • An issue was discovered in the IPv6 protocol specification, related to ICMP Packet Too Big (PTB) messages.

    HighCVSS 8.6No exploitEPSS 3%

    ietf · ipv6Jan 14, 2017

  • CVE-2007-2242
    33Monitor

    The IPv6 protocol allows remote attackers to cause a denial of service via crafted IPv6 type 0 route headers (IPV6_RTHDR_TYPE_0) that create

    HighCVSS 7.8No exploitEPSS 5%

    openbsd · openbsdApr 25, 2007

  • CVE-2015-8960
    33Monitor

    The TLS protocol 1.2 and earlier supports the rsa_fixed_dh, dss_fixed_dh, rsa_fixed_ecdh, and ecdsa_fixed_ecdh values for ClientCertificateT

    HighCVSS 8.1No exploitEPSS 2%

    ietf · transport layer securitySep 20, 2016

  • CVE-2024-7595
    26Monitor

    GRE and GRE6 Protocols (RFC2784) do not validate or verify the source of a network packet

    MediumCVSS 6.5Proof of conceptEPSS 2%

    ietf · generic routing encapsulationFeb 5, 2025

  • IPv4-in-IPv6 and IPv6-in-IPv6 tunneling (RFC 2473) do not require the validation or verification of the source of a network packet, allowing

    MediumCVSS 6.5No exploitEPSS 1%

    ietf · ipv6Jan 14, 2025

  • IPv6-in-IPv4 tunneling (RFC 4213) allows an attacker to spoof and route traffic via an exposed network interface.

    MediumCVSS 6.5No exploitEPSS 1%

    ietf · ipv6Jan 14, 2025

  • CVE-2024-7596
    26Monitor

    Generic UDP Encapsulation (GUE) (IETF Draft) do not validate or verify the source of a network packet

    MediumCVSS 6.5No exploitEPSS 1%

    ietf · generic udp encapsulationFeb 5, 2025

  • CVE-2018-5389
    24Monitor

    The Internet Key Exchange v1 main mode is vulnerable to offline dictionary or brute force attacks.

    MediumCVSS 5.9No exploitEPSS 3%

    ietf · internet key exchangeSep 6, 2018

  • Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in STM32 cryptographic firmware library software expansion for STM32Cube (UM1924).

    MediumCVSS 5.9No exploitEPSS 1%

    st · stm32cubef0Jan 20, 2021

  • Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in Microchip Libraries for Applications 2018-11-26 All up to 2018-11-26.

    MediumCVSS 5.9No exploitEPSS 1%

    microchip · microchip libraries for applicationsJan 19, 2021

  • L2 network filtering can be bypassed using stacked VLAN0 and LLC/SNAP headers

    MediumCVSS 4.7No exploitEPSS 1%

    ieee · ieee 802.2Sep 27, 2022

  • L2 network filtering bypass using stacked VLAN0, LLC/SNAP headers, and Ethernet to Wifi frame translation

    MediumCVSS 4.7No exploitEPSS 1%

    ieee · ieee 802.2Sep 27, 2022

  • L2 network filtering bypass using stacked VLAN0 and LLC/SNAP headers with an invalid length during Ethernet to Wifi frame translation

    MediumCVSS 4.7No exploitEPSS 1%

    ieee · ieee 802.2Sep 27, 2022

  • L2 network filtering bypass using stacked VLAN0 and LLC/SNAP headers with invalid lengths

    MediumCVSS 4.7No exploitEPSS 1%

    ieee · ieee 802.2Sep 27, 2022

  • The TCP protocol in RFC 9293 has a timing side channel that makes it easier for remote attackers to infer the content of one TCP connection

    MediumCVSS 4.3No exploitEPSS 1%

    Jul 3, 2024