Show filters
22 Total Results
Displaying 11-20 of 22
Sort by:
Attacker Value
Unknown

CVE-2017-11670

Disclosure Date: July 31, 2017 (last updated November 26, 2024)
A length validation (leading to out-of-bounds read and write) flaw was found in the way eapmd5pass 1.4 handled network traffic in the extract_eapusername function. A remote attacker could potentially use this flaw to crash the eapmd5pass process by generating specially crafted network traffic.
0
Attacker Value
Unknown

CVE-2017-11668

Disclosure Date: July 31, 2017 (last updated November 26, 2024)
An out-of-bounds read flaw related to the assess_packet function in eapmd5pass.c:134 was found in the way eapmd5pass 1.4 handled processing of network packets. A remote attacker could potentially use this flaw to crash the eapmd5pass process under certain circumstances by generating specially crafted network traffic.
0
Attacker Value
Unknown

CVE-2017-11669

Disclosure Date: July 31, 2017 (last updated November 26, 2024)
An out-of-bounds read flaw related to the assess_packet function in eapmd5pass.c:211 was found in the way eapmd5pass 1.4 handled processing of network packets. A remote attacker could potentially use this flaw to crash the eapmd5pass process under certain circumstances by generating specially crafted network traffic.
0
Attacker Value
Unknown

CVE-2016-6380

Disclosure Date: October 05, 2016 (last updated November 25, 2024)
The DNS forwarder in Cisco IOS 12.0 through 12.4 and 15.0 through 15.6 and IOS XE 3.1 through 3.15 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (data corruption or device reload) via a crafted DNS response, aka Bug ID CSCup90532.
0
Attacker Value
Unknown

CVE-2016-6381

Disclosure Date: October 05, 2016 (last updated November 25, 2024)
Cisco IOS 12.4 and 15.0 through 15.6 and IOS XE 3.1 through 3.18 and 16.1 allow remote attackers to cause a denial of service (memory consumption or device reload) via fragmented IKEv1 packets, aka Bug ID CSCuy47382.
0
Attacker Value
Unknown

CVE-2016-1409

Disclosure Date: May 29, 2016 (last updated November 25, 2024)
The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in Cisco IOS XE 2.1 through 3.17S, IOS XR 2.0.0 through 5.3.2, and NX-OS allows remote attackers to cause a denial of service (packet-processing outage) via crafted ND messages, aka Bug ID CSCuz66542, as exploited in the wild in May 2016.
0
Attacker Value
Unknown

CVE-2013-5552

Disclosure Date: November 13, 2013 (last updated October 05, 2023)
Cisco IOS 12.4(24)MDB9 and earlier on Content Services Gateway (CSG) devices does not properly implement the "parse error drop" feature, which allows remote attackers to bypass intended access restrictions via a crafted series of packets, aka Bug ID CSCug90143.
0
Attacker Value
Unknown

CVE-2012-3287

Disclosure Date: June 13, 2012 (last updated October 04, 2023)
Poul-Henning Kamp md5crypt has insufficient algorithmic complexity and a consequently short runtime, which makes it easier for context-dependent attackers to discover cleartext passwords via a brute-force attack, as demonstrated by an attack using GPU hardware.
0
Attacker Value
Unknown

CVE-2004-2761

Disclosure Date: January 05, 2009 (last updated October 04, 2023)
The MD5 Message-Digest Algorithm is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attacks, as demonstrated by attacks on the use of MD5 in the signature algorithm of an X.509 certificate.
0
Attacker Value
Unknown

CVE-2005-0580

Disclosure Date: February 25, 2005 (last updated February 22, 2025)
cmd5checkpw, when running setuid, does not properly drop privileges before calling the execvp function, which allows local users to read the poppasswd file.
0