Show filters
10 Total Results
Displaying 1-10 of 10
Sort by:
Attacker Value
Unknown
CVE-2024-49268
Disclosure Date: October 16, 2024 (last updated October 31, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in sunburntkamel disconnected allows Reflected XSS.This issue affects disconnected: from n/a through 1.3.0.
0
Attacker Value
Unknown
CVE-2014-6660
Disclosure Date: September 23, 2014 (last updated October 05, 2023)
The Koleksi Hadis Nabi SAW (aka com.wKoleksiHadisNabiSAW) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown
CVE-2008-2464
Disclosure Date: September 11, 2008 (last updated October 04, 2023)
The mld_input function in sys/netinet6/mld6.c in the kernel in NetBSD 4.0, FreeBSD, and KAME, when INET6 is enabled, allows remote attackers to cause a denial of service (divide-by-zero error and panic) via a malformed ICMPv6 Multicast Listener Discovery (MLD) query with a certain Maximum Response Delay value.
0
Attacker Value
Unknown
CVE-2008-0177
Disclosure Date: February 07, 2008 (last updated October 04, 2023)
The ipcomp6_input function in sys/netinet6/ipcomp_input.c in the KAME project before 20071201 does not properly check the return value of the m_pulldown function, which allows remote attackers to cause a denial of service (system crash) via an IPv6 packet with an IPComp header.
0
Attacker Value
Unknown
CVE-2005-0398
Disclosure Date: March 14, 2005 (last updated February 22, 2025)
The KAME racoon daemon in ipsec-tools before 0.5 allows remote attackers to cause a denial of service (crash) via malformed ISAKMP packets.
0
Attacker Value
Unknown
CVE-2004-0607
Disclosure Date: December 06, 2004 (last updated February 22, 2025)
The eay_check_x509cert function in KAME Racoon successfully verifies certificates even when OpenSSL validation fails, which could allow remote attackers to bypass authentication.
0
Attacker Value
Unknown
CVE-2004-0392
Disclosure Date: June 14, 2004 (last updated February 22, 2025)
racoon before 20040407b allows remote attackers to cause a denial of service (infinite loop and dropped connections) via an IKE message with a malformed Generic Payload Header containing invalid (1) "Security Association Next Payload" and (2) "RESERVED" fields.
0
Attacker Value
Unknown
CVE-2004-0403
Disclosure Date: June 01, 2004 (last updated February 22, 2025)
Racoon before 20040408a allows remote attackers to cause a denial of service (memory consumption) via an ISAKMP packet with a large length field.
0
Attacker Value
Unknown
CVE-2004-0155
Disclosure Date: June 01, 2004 (last updated February 22, 2025)
The KAME IKE Daemon Racoon, when authenticating a peer during Phase 1, validates the X.509 certificate but does not verify the RSA signature authentication, which allows remote attackers to establish unauthorized IP connections or conduct man-in-the-middle attacks using a valid, trusted X.509 certificate.
0
Attacker Value
Unknown
CVE-2004-0164
Disclosure Date: March 03, 2004 (last updated February 22, 2025)
KAME IKE daemon (racoon) does not properly handle hash values, which allows remote attackers to delete certificates via (1) a certain delete message that is not properly handled in isakmp.c or isakmp_inf.c, or (2) a certain INITIAL-CONTACT message that is not properly handled in isakmp_inf.c.
0