Vulnerability index

Browse CVEs

37 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ftpd HIGH 7.5
CVE-2023-45198

ftpd before "NetBSD-ftpd 20230930" can leak information about the host filesystem before authentication via an MLSD or MLST command. tnftpd (the port…

Fix: 2023-09-30 / 2023-10-01+
Fix from $1,950 2023-10-05
Netbsd HIGH 7.5
CVE-2021-45484

In NetBSD through 9.2, the IPv6 fragment ID generation algorithm employs a weak cryptographic PRNG.

Fix: after 9.2
Fix from $1,950 2021-12-25
Netbsd HIGH 7.5
CVE-2021-45487

In NetBSD through 9.2, the IPv4 ID generation algorithm does not use appropriate cryptographic measures.

Fix: after 9.2
Fix from $1,950 2021-12-25
Netbsd HIGH 7.5
CVE-2021-45488

In NetBSD through 9.2, there is an information leak in the TCP ISN (ISS) generation algorithm.

Fix: after 9.2
Fix from $1,950 2021-12-25
Netbsd HIGH 7.5
CVE-2021-45489

In NetBSD through 9.2, the IPv6 Flow Label generation algorithm employs a weak cryptographic PRNG.

Fix: after 9.2
Fix from $1,950 2021-12-25
Netbsd CRITICAL 9.8
CVE-2017-1000374

A flaw exists in NetBSD's implementation of the stack guard page that allows attackers to bypass it resulting in arbitrary code execution using certa…

Fix: after 7.1
Fix from $2,300 2017-06-19
Netbsd CRITICAL 9.8
CVE-2017-1000375EPSS 19%

NetBSD maps the run-time link-editor ld.so directly below the stack region, even if ASLR is enabled, this allows attackers to more easily manipulate …

Fix: after 7.1
Fix from $2,300 2017-06-19
Netbsd CRITICAL 9.8
CVE-2017-1000378

The NetBSD qsort() function is recursive, and not randomized, an attacker can construct a pathological input array of N elements that causes qsort() …

Fix: after 7.1
Fix from $2,300 2017-06-19
Netbsd HIGH 7.8
CVE-2016-6253

mail.local in NetBSD versions 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows local users to change ownership of or append data to arbitrary fil…

No fix yet
Fix from $1,950 2017-01-20
Netbsd CRITICAL 9.8
CVE-2015-8212

CGI handling flaw in bozohttpd in NetBSD 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows remote attackers to execute arbitrary code via crafted …

Mitigation only
Fix from $2,300 2017-01-19
Tnftpd MEDIUM 5.0
CVE-2015-5917

The glob implementation in tnftpd (formerly lukemftpd), as used in Apple OS X before 10.11, allows remote attackers to cause a denial of service (mem…

No fix yet
Fix from $1,600 2015-10-09
Netbsd MEDIUM 6.8
CVE-2011-1547EPSS 5%

Multiple stack consumption vulnerabilities in the kernel in NetBSD 4.0, 5.0 before 5.0.3, and 5.1 before 5.1.1, when IPsec is enabled, allow remote a…

Mitigation only
Fix from $1,600 2011-05-09
Netbsd MEDIUM 6.9
CVE-2009-2482

The pam_unix module in OpenPAM in NetBSD 4.0 before 4.0.2 and 5.0 before 5.0.1 allows local users to change the current root password if it is alread…

Mitigation only
Fix from $1,600 2009-07-16
Netbsd HIGH 9.3
CVE-2008-3584

NetBSD 3.0, 3.1, and 4.0, when a pppoe instance exists, does not properly check the length of a PPPoE packet tag, which allows remote attackers to ca…

Mitigation only
Fix from $1,950 2008-09-11
Netbsd HIGH 9.3
CVE-2008-1335

The ipsec4_get_ulp function in the kernel in NetBSD 2.0 through 3.1 and NetBSD-current before 20071028, when the fast_ipsec subsystem is enabled, all…

Fix: after 20071027
Fix from $1,950 2008-03-13
Netbsd HIGH 7.5
CVE-2007-1523

Heap-based buffer overflow in the kernel in NetBSD 3.0, certain versions of FreeBSD and OpenBSD, and possibly other BSD derived operating systems all…

No fix yet
Fix from $1,950 2007-03-20
Netbsd MEDIUM 6.6
CVE-2006-6730

OpenBSD and NetBSD permit usermode code to kill the display server and write to the X.Org /dev/xf86 device, which allows local users with root privil…

Mitigation only
Fix from $1,600 2006-12-26
Netbsd HIGH 7.2
CVE-2006-6014

The NetBSD-current kernel before 20061028 does not properly perform bounds checking of an unspecified userspace parameter in the ptrace system call d…

Patch available
Fix from $1,950 2006-11-21
Netbsd HIGH 7.5
CVE-2005-4741

NetBSD 1.6, NetBSD 2.0 through 2.1, and NetBSD-current before 20051031 allows local users to gain privileges by attaching a debugger to a setuid/setg…

Patch available
Fix from $1,950 2005-12-31
Netbsd HIGH 7.2
CVE-2005-4776

Integer overflow in the FreeBSD compatibility code (freebsd_misc.c) in NetBSD-current, NetBSD-3, NetBSD-2.0, and NetBSD-2 before 20050913; and NetBSD…

Patch available
Fix from $1,950 2005-12-31
Netbsd HIGH 7.2
CVE-2004-1374

Multiple buffer overflows in NetBSD kernel may allow local users to execute arbitrary code and gain privileges.

No fix yet
Fix from $1,950 2004-12-18
Netbsd MEDIUM 5.0
CVE-2004-0257

OpenBSD 3.4 and NetBSD 1.6 and 1.6.1 allow remote attackers to cause a denial of service (crash) by sending an IPv6 packet with a small MTU to a list…

Patch available
Fix from $1,600 2004-11-23
Netbsd MEDIUM 5.0
CVE-2003-0653

The OSI networking kernel (sys/netiso) in NetBSD 1.6.1 and earlier does not use a BSD-required "PKTHDR" mbuf when sending certain error responses to …

Mitigation only
Fix from $1,600 2003-08-27
Netbsd HIGH 7.2
CVE-2002-1500

Buffer overflow in (1) mrinfo, (2) mtrace, and (3) pppd in NetBSD 1.4.x through 1.6 allows local users to gain privileges by executing the programs a…

Patch available
Fix from $1,950 2003-04-02
Ftpd MEDIUM 5.0
CVE-2002-2245

ftpd in NetBSD 1.5 through 1.5.3 and 1.6 does not properly quote a digit in response to a STAT command for a filename that contains a carriage return…

Mitigation only
Fix from $1,600 2002-12-31
Netbsd HIGH 7.5
CVE-2002-1194

Buffer overflow in talkd on NetBSD 1.6 and earlier, and possibly other operating systems, may allow remote attackers to execute arbitrary code via a …

Mitigation only
Fix from $1,950 2002-10-28
Netbsd HIGH 7.2
CVE-2001-0734

Hitachi Super-H architecture in NetBSD 1.5 and 1.4.1 allows a local user to gain privileges via modified Status Register contents, which are not prop…

Patch available
Fix from $1,950 2001-10-18
Netbsd HIGH 7.2
CVE-2001-1091

The (1) dump and (2) dump_lfs commands in NetBSD 1.4.x through 1.5.1 do not properly drop privileges, which could allow local users to gain privilege…

Mitigation only
Fix from $1,950 2001-08-23
Netbsd HIGH 7.2
CVE-2001-0268

The i386_set_ldt system call in NetBSD 1.5 and earlier, and OpenBSD 2.8 and earlier, when the USER_LDT kernel option is enabled, does not validate a …

Fix: after 2.8
Fix from $1,950 2001-05-03
Netbsd HIGH 7.2
CVE-2000-0997

Format string vulnerabilities in eeprom program in OpenBSD, NetBSD, and possibly other operating systems allows local attackers to gain root privileg…

Patch available
Fix from $1,950 2000-12-19