Racoon
Vendor:
First CVE: Mar 3, 2004 · Active for 22 years
6
Total CVEs
More Total CVEs than 83% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 78% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 29% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Racoon over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 3, 2004
22 years ago
Most Recent CVE
Mar 14, 2005
7,806 days ago
CVE Severity & Scoring
Racoon6 CVEs
67%
33%
All CVEs353,240 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown6 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown6 (100.0%)
User Interaction
None0 (0.0%)
Unknown6 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown6 (100.0%)
Top CVEs
Signals from CVEs in this product scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-0607HIGH The eay_check_x509cert function in KAME Racoon successfully verifies certificates even when OpenSSL validation fails, which could allow remote attackers to bypass authentication. | Dec 6, 2004 | 10.0 | 26 | NO | NO |
CVE-2004-0164MEDIUM KAME IKE daemon (racoon) does not properly handle hash values, which allows remote attackers to delete certificates via (1) a certain delete message that is not properly handled in | Mar 3, 2004 | 5.0 | 25 | NO | YES |
CVE-2004-0155HIGH The KAME IKE Daemon Racoon, when authenticating a peer during Phase 1, validates the X.509 certificate but does not verify the RSA signature authentication, which allows remote att | Jun 1, 2004 | 7.5 | 20 | NO | NO |
CVE-2004-0392MEDIUM racoon before 20040407b allows remote attackers to cause a denial of service (infinite loop and dropped connections) via an IKE message with a malformed Generic Payload Header cont | Jun 14, 2004 | 5.0 | 17 | NO | NO |
CVE-2004-0403MEDIUM Racoon before 20040408a allows remote attackers to cause a denial of service (memory consumption) via an ISAKMP packet with a large length field. | Jun 1, 2004 | 5.0 | 16 | NO | NO |
CVE-2005-0398MEDIUM The KAME racoon daemon in ipsec-tools before 0.5 allows remote attackers to cause a denial of service (crash) via malformed ISAKMP packets. | Mar 14, 2005 | 5.0 | 15 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (6 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
16.7% of CVEs· 87th percentile
Social Chatter
Signals from CVEs in this product scope (6 CVEs).
Media Mentions
Signals from CVEs in this product scope (6 CVEs).
Top CNAs Publishing CVEs For Racoon
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| all_versions | 1 | 5.0 | 6.7% | 0 | 1 |
| 2005-03-07 | 1 | 5.0 | 2.4% | 0 | 0 |
| 2005-02-28 | 1 | 5.0 | 2.4% | 0 | 0 |
| 2005-02-21 | 1 | 5.0 | 2.4% | 0 | 0 |
| 2005-02-14 | 1 | 5.0 | 2.4% | 0 | 0 |
| 2005-02-07 | 1 | 5.0 | 2.4% | 0 | 0 |
| 2005-01-31 | 1 | 5.0 | 2.4% | 0 | 0 |
| 2005-01-24 | 1 | 5.0 | 2.4% | 0 | 0 |
| 2005-01-17 | 1 | 5.0 | 2.4% | 0 | 0 |
| 2005-01-10 | 1 | 5.0 | 2.4% | 0 | 0 |
| 2005-01-03 | 1 | 5.0 | 2.4% | 0 | 0 |
| 2004-05-03 | 2 | 7.5 | 3.9% | 0 | 0 |
| 2004-04-07b | 2 | 7.5 | 3.9% | 0 | 0 |
| 2004-04-05 | 2 | 7.5 | 3.9% | 0 | 0 |
| 2003-07-11 | 2 | 7.5 | 3.9% | 0 | 0 |