Racoon

Vendor:

First CVE: Mar 3, 2004 · Active for 22 years

6
Total CVEs
More Total CVEs than 83% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 78% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 29% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Racoon over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 3, 2004
22 years ago
Most Recent CVE
Mar 14, 2005
7,806 days ago

CVE Severity & Scoring

Racoon6 CVEs
All CVEs353,240 CVEs
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown6 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown6 (100.0%)
User Interaction
None0 (0.0%)
Unknown6 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown6 (100.0%)

Top CVEs

Signals from CVEs in this product scope (6 CVEs).

6 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The eay_check_x509cert function in KAME Racoon successfully verifies certificates even when OpenSSL validation fails, which could allow remote attackers to bypass authentication.
Dec 6, 200410.026NONO
KAME IKE daemon (racoon) does not properly handle hash values, which allows remote attackers to delete certificates via (1) a certain delete message that is not properly handled in
Mar 3, 20045.025NOYES
The KAME IKE Daemon Racoon, when authenticating a peer during Phase 1, validates the X.509 certificate but does not verify the RSA signature authentication, which allows remote att
Jun 1, 20047.520NONO
racoon before 20040407b allows remote attackers to cause a denial of service (infinite loop and dropped connections) via an IKE message with a malformed Generic Payload Header cont
Jun 14, 20045.017NONO
Racoon before 20040408a allows remote attackers to cause a denial of service (memory consumption) via an ISAKMP packet with a large length field.
Jun 1, 20045.016NONO
The KAME racoon daemon in ipsec-tools before 0.5 allows remote attackers to cause a denial of service (crash) via malformed ISAKMP packets.
Mar 14, 20055.015NONO

Exploit Exposure

Signals from CVEs in this product scope (6 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
16.7% of CVEs· 87th percentile

Social Chatter

Signals from CVEs in this product scope (6 CVEs).

Media Mentions

Signals from CVEs in this product scope (6 CVEs).

Top CNAs Publishing CVEs For Racoon

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
all_versions15.06.7%01
2005-03-0715.02.4%00
2005-02-2815.02.4%00
2005-02-2115.02.4%00
2005-02-1415.02.4%00
2005-02-0715.02.4%00
2005-01-3115.02.4%00
2005-01-2415.02.4%00
2005-01-1715.02.4%00
2005-01-1015.02.4%00
2005-01-0315.02.4%00
2004-05-0327.53.9%00
2004-04-07b27.53.9%00
2004-04-0527.53.9%00
2003-07-1127.53.9%00