ipsec-tools records
9 published records for vendor ipsec-tools.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-399 Resource Management Errors3
- CWE-407 Inefficient Algorithmic Complexity1
- CWE-476 NULL Pointer Dereference1
The weakness classes this vendor ships most often: where to look.
CWEAll records
9 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
42Plan | CVE-2004-0607No exploit | The eay_check_x509cert function in KAME Racoon successfully verifies certificates even when OpenSSL validation fails, which could allow remokame · racoon | Critical10.0 | — | 5.4% | Dec 6, 2004 |
34Monitor | CVE-2015-4047No exploit | racoon/gssapi.c in IPsec-Tools 0.8.2 allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon crash) viipsec-tools · ipsec-tools · CWE-476 | High7.8 | — | 9.8% | May 29, 2015 |
32Monitor | CVE-2005-3732No exploit | The Internet Key Exchange version 1 (IKEv1) implementation (isakmp_agg.c) in racoon in ipsec-tools before 0.6.3, when running in aggressive ipsec-tools · ipsec-tools · CWE-399 | High7.8 | — | 4.4% | Nov 21, 2005 |
32Monitor | CVE-2008-3652No exploit | src/racoon/handler.c in racoon in ipsec-tools does not remove an "orphaned ph1" (phase 1) handle when it has been initiated remotely, which ipsec-tools · ipsec-tools · CWE-399 | High7.8 | — | 3.4% | Aug 12, 2008 |
31Monitor | CVE-2016-10396No exploit | The racoon daemon in IPsec-Tools 0.8.2 contains a remotely exploitable computational-complexity attack when parsing and storing ISAKMP fragmipsec-tools · ipsec-tools · CWE-407 | High7.5 | — | 2.9% | Jul 5, 2017 |
23Monitor | CVE-2009-1574Proof of concept | racoon/isakmp_frag.c in ipsec-tools before 0.7.2 allows remote attackers to cause a denial of service (crash) via crafted fragmented packetsipsec-tools · ipsec-tools | Medium5.0 | — | 11.6% | May 6, 2009 |
21Monitor | CVE-2005-0398No exploit | The KAME racoon daemon in ipsec-tools before 0.5 allows remote attackers to cause a denial of service (crash) via malformed ISAKMP packets.ipsec-tools · ipsec-tools | Medium5.0 | — | 2.4% | Mar 14, 2005 |
21Monitor | CVE-2009-1632No exploit | Multiple memory leaks in Ipsec-tools before 0.7.2 allow remote attackers to cause a denial of service (memory consumption) via vectors involipsec-tools · ipsec-tools · CWE-399 | Medium5.0 | — | 2.0% | May 14, 2009 |
18Monitor | CVE-2007-1841No exploit | The isakmp_info_recv function in src/racoon/isakmp_inf.c in racoon in Ipsec-tools before 0.6.7 allows remote attackers to cause a denial of ipsec-tools · ipsec-tools | Medium4.3 | — | 2.9% | Apr 10, 2007 |
- CVE-2004-060742Plan
The eay_check_x509cert function in KAME Racoon successfully verifies certificates even when OpenSSL validation fails, which could allow remo
CriticalCVSS 10.0No exploitEPSS 5%kame · racoonDec 6, 2004
- CVE-2015-404734Monitor
racoon/gssapi.c in IPsec-Tools 0.8.2 allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon crash) vi
HighCVSS 7.8No exploitEPSS 10%ipsec-tools · ipsec-toolsMay 29, 2015
- CVE-2005-373232Monitor
The Internet Key Exchange version 1 (IKEv1) implementation (isakmp_agg.c) in racoon in ipsec-tools before 0.6.3, when running in aggressive
HighCVSS 7.8No exploitEPSS 4%ipsec-tools · ipsec-toolsNov 21, 2005
- CVE-2008-365232Monitor
src/racoon/handler.c in racoon in ipsec-tools does not remove an "orphaned ph1" (phase 1) handle when it has been initiated remotely, which
HighCVSS 7.8No exploitEPSS 3%ipsec-tools · ipsec-toolsAug 12, 2008
- CVE-2016-1039631Monitor
The racoon daemon in IPsec-Tools 0.8.2 contains a remotely exploitable computational-complexity attack when parsing and storing ISAKMP fragm
HighCVSS 7.5No exploitEPSS 3%ipsec-tools · ipsec-toolsJul 5, 2017
- CVE-2009-157423Monitor
racoon/isakmp_frag.c in ipsec-tools before 0.7.2 allows remote attackers to cause a denial of service (crash) via crafted fragmented packets
MediumCVSS 5.0Proof of conceptEPSS 12%ipsec-tools · ipsec-toolsMay 6, 2009
- CVE-2005-039821Monitor
The KAME racoon daemon in ipsec-tools before 0.5 allows remote attackers to cause a denial of service (crash) via malformed ISAKMP packets.
MediumCVSS 5.0No exploitEPSS 2%ipsec-tools · ipsec-toolsMar 14, 2005
- CVE-2009-163221Monitor
Multiple memory leaks in Ipsec-tools before 0.7.2 allow remote attackers to cause a denial of service (memory consumption) via vectors invol
MediumCVSS 5.0No exploitEPSS 2%ipsec-tools · ipsec-toolsMay 14, 2009
- CVE-2007-184118Monitor
The isakmp_info_recv function in src/racoon/isakmp_inf.c in racoon in Ipsec-tools before 0.6.7 allows remote attackers to cause a denial of
MediumCVSS 4.3No exploitEPSS 3%ipsec-tools · ipsec-toolsApr 10, 2007