Eapmd5pass is a focused security tool that performs dictionary attacks against EAP-MD5 authentication, with vulnerability exposure concentrated in a single utility product. The durable signal centers on memory-safety issues such as out-of-bounds reads and writes, which are characteristic of attack-tool codebases where performance and complexity can outpace defensive coding practices. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Eapmd5pass Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-11670HIGH A length validation (leading to out-of-bounds read and write) flaw was found in the way eapmd5pass 1.4 handled network traffic in the extract_eapusername function. A remote attacke | Jul 31, 2017 | 7.5 | 23 | NO | NO |
CVE-2017-11668HIGH An out-of-bounds read flaw related to the assess_packet function in eapmd5pass.c:134 was found in the way eapmd5pass 1.4 handled processing of network packets. A remote attacker co | Jul 31, 2017 | 7.5 | 23 | NO | NO |
CVE-2017-11669HIGH An out-of-bounds read flaw related to the assess_packet function in eapmd5pass.c:211 was found in the way eapmd5pass 1.4 handled processing of network packets. A remote attacker co | Jul 31, 2017 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Eapmd5pass Project.
Media articles that mention a CVE ID that affects a product developed by Eapmd5pass Project — matched by CVE ID, not by vendor name.