Vulnerabilities > Icon Labs

DATE CVE VULNERABILITY TITLE RISK
2011-01-28 CVE-2011-0651 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Icon-Labs Iconfidant SSL Server
Buffer overflow in the key exchange functionality in Icon Labs Iconfidant SSL Server before 1.3.0 allows remote attackers to execute arbitrary code via a client master key packet in which the sum of unspecified length fields is greater than a certain value.
network
low complexity
icon-labs CWE-119
7.5
2008-05-22 CVE-2008-0536 Improper Authentication vulnerability in multiple products
Unspecified vulnerability in the SSH server in (1) Cisco Service Control Engine (SCE) 3.0.x before 3.0.7 and 3.1.x before 3.1.0, and (2) Icon Labs Iconfidant SSH before 2.3.8, allows remote attackers to cause a denial of service (management interface outage) via SSH traffic that occurs during management operations and triggers "illegal I/O operations," aka Bug ID CSCsh49563.
network
low complexity
cisco icon-labs CWE-287
7.8
2008-05-22 CVE-2008-0535 Credentials Management vulnerability in multiple products
Unspecified vulnerability in the SSH server in (1) Cisco Service Control Engine (SCE) before 3.1.6, and (2) Icon Labs Iconfidant SSH before 2.3.8, allows remote attackers to cause a denial of service (device instability) via "SSH credentials that attempt to change the authentication method," aka Bug ID CSCsm14239.
network
low complexity
cisco icon-labs CWE-255
7.8
2008-05-22 CVE-2008-0534 Improper Input Validation vulnerability in multiple products
The SSH server in (1) Cisco Service Control Engine (SCE) before 3.1.6, and (2) Icon Labs Iconfidant SSH before 2.3.8, allows remote attackers to cause a denial of service (device restart or daemon outage) via a high rate of login attempts, aka Bug ID CSCsi68582.
network
low complexity
cisco icon-labs CWE-20
7.8