Kame is a foundational open-source implementation of IPv6 and IPsec networking protocols, with a narrow but strategically important product scope centered on its racoon IKE daemon, IPComp compression, and core stack. The vendor's disclosures frequently acquire public exploit code, reflecting the appeal of network protocol implementations to security researchers and tool developers. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kame over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-0177HIGH The ipcomp6_input function in sys/netinet6/ipcomp_input.c in the KAME project before 20071201 does not properly check the return value of the m_pulldown function, which allows remo | Feb 7, 2008 | 7.8 | 36 | NO | YES |
CVE-2004-0607HIGH The eay_check_x509cert function in KAME Racoon successfully verifies certificates even when OpenSSL validation fails, which could allow remote attackers to bypass authentication. | Dec 6, 2004 | 10.0 | 26 | NO | NO |
CVE-2004-0164MEDIUM KAME IKE daemon (racoon) does not properly handle hash values, which allows remote attackers to delete certificates via (1) a certain delete message that is not properly handled in | Mar 3, 2004 | 5.0 | 25 | NO | YES |
CVE-2004-0155HIGH The KAME IKE Daemon Racoon, when authenticating a peer during Phase 1, validates the X.509 certificate but does not verify the RSA signature authentication, which allows remote att | Jun 1, 2004 | 7.5 | 20 | NO | NO |
CVE-2008-2464HIGH The mld_input function in sys/netinet6/mld6.c in the kernel in NetBSD 4.0, FreeBSD, and KAME, when INET6 is enabled, allows remote attackers to cause a denial of service (divide-by | Sep 11, 2008 | 7.1 | 19 | NO | NO |
CVE-2004-0392MEDIUM racoon before 20040407b allows remote attackers to cause a denial of service (infinite loop and dropped connections) via an IKE message with a malformed Generic Payload Header cont | Jun 14, 2004 | 5.0 | 17 | NO | NO |
CVE-2004-0403MEDIUM Racoon before 20040408a allows remote attackers to cause a denial of service (memory consumption) via an ISAKMP packet with a large length field. | Jun 1, 2004 | 5.0 | 16 | NO | NO |
CVE-2005-0398MEDIUM The KAME racoon daemon in ipsec-tools before 0.5 allows remote attackers to cause a denial of service (crash) via malformed ISAKMP packets. | Mar 14, 2005 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kame.
Media articles that mention a CVE ID that affects a product developed by Kame — matched by CVE ID, not by vendor name.