Vulnerability index

Browse CVEs

40 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

OpenBSD MEDIUM 5.5
CVE-2021-34999

OpenBSD Kernel Multicast Routing Uninitialized Memory Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sen…

Mitigation only
Fix from $1,600 2024-05-07
OpenBSD HIGH 7.5
CVE-2010-4816

It was found in FreeBSD 8.0, 6.3 and 4.9, and OpenBSD 4.6 that a null pointer dereference in ftpd/popen.c may lead to remote denial of service of the…

No fix yet
Fix from $1,950 2021-06-22
OpenBSD MEDIUM 5.3
CVE-2020-26142

An issue was discovered in the kernel in OpenBSD 6.6. The WEP, WPA, WPA2, and WPA3 implementations treat fragmented frames as full frames. An adversa…

Mitigation only
Fix from $1,600 2021-05-11
OpenBSD CRITICAL 9.8
CVE-2019-19521

libc in OpenBSD 6.6 allows authentication bypass via the -schallenge username, as demonstrated by smtpd, ldapd, or radiusd. This is related to gen/au…

No fix yet
Fix from $2,300 2019-12-05
OpenBSD HIGH 7.8
CVE-2019-19519

In OpenBSD 6.6, local users can use the su -L option to achieve any login class (often excluding root) because there is a logic error in the main fun…

No fix yet
Fix from $1,950 2019-12-05
OpenBSD HIGH 7.8
CVE-2019-19520

xlock in OpenBSD 6.6 allows local users to gain the privileges of the auth group by providing a LIBGL_DRIVERS_PATH environment variable, because xeno…

No fix yet
Fix from $1,950 2019-12-05
OpenBSD HIGH 7.8
CVE-2019-19522

OpenBSD 6.6, in a non-default configuration where S/Key or YubiKey authentication is enabled, allows local users to become root by leveraging members…

No fix yet
Fix from $1,950 2019-12-05
OpenBSD HIGH 7.8
CVE-2016-6240

Integer truncation error in the amap_alloc function in OpenBSD 5.8 and 5.9 allows local users to execute arbitrary code with kernel privileges via a …

No fix yet
Fix from $1,950 2017-03-07
OpenBSD HIGH 7.8
CVE-2016-6241

Integer overflow in the amap_alloc1 function in OpenBSD 5.8 and 5.9 allows local users to execute arbitrary code with kernel privileges via a large s…

No fix yet
Fix from $1,950 2017-03-07
OpenBSD MEDIUM 5.5
CVE-2016-6239

The mmap extension __MAP_NOFAULT in OpenBSD 5.8 and 5.9 allows attackers to cause a denial of service (kernel panic and crash) via a large size value.

No fix yet
Fix from $1,600 2017-03-07
OpenBSD MEDIUM 5.5
CVE-2016-6242

OpenBSD 5.8 and 5.9 allows local users to cause a denial of service (assertion failure and kernel panic) via a large ident value in a kevent system c…

No fix yet
Fix from $1,600 2017-03-07
OpenBSD MEDIUM 5.5
CVE-2016-6243

thrsleep in kern/kern_synch.c in OpenBSD 5.8 and 5.9 allows local users to cause a denial of service (kernel panic) via a crafted value in the tsp pa…

No fix yet
Fix from $1,600 2017-03-07
OpenBSD MEDIUM 5.5
CVE-2016-6245

OpenBSD 5.8 and 5.9 allows local users to cause a denial of service (kernel panic) via a large size in a getdents system call.

No fix yet
Fix from $1,600 2017-03-07
OpenBSD MEDIUM 5.5
CVE-2016-6247

OpenBSD 5.8 and 5.9 allows certain local users to cause a denial of service (kernel panic) by unmounting a filesystem with an open vnode on the mnt_v…

No fix yet
Fix from $1,600 2017-03-07
OpenBSD HIGH 7.5
CVE-2016-6244

The sys_thrsigdivert function in kern/kern_sig.c in the OpenBSD kernel 5.9 allows remote attackers to cause a denial of service (panic) via a negativ…

No fix yet
Fix from $1,950 2017-03-07
Openssh MEDIUM 5.3
CVE-2016-1907EPSS 14%

The ssh_packet_read_poll2 function in packet.c in OpenSSH before 7.1p2 allows remote attackers to cause a denial of service (out-of-bounds read and a…

Mitigation only
Fix from $1,600 2016-01-19
Openssh HIGH 7.2
CVE-2015-6565

sshd in OpenSSH 6.8 and 6.9 uses world-writable permissions for TTY devices, which allows local users to cause a denial of service (terminal disrupti…

No fix yet
Fix from $1,950 2015-08-24
Openssh MEDIUM 6.0
CVE-2013-4548

The mm_newkeys_from_blob function in monitor_wrap.c in sshd in OpenSSH 6.2 and 6.3, when an AES-GCM cipher is used, does not properly initialize memo…

Mitigation only
Fix from $1,600 2013-11-08
Openssh MEDIUM 6.9
CVE-2009-2904

A certain Red Hat modification to the ChrootDirectory feature in OpenSSH 4.8, as used in sshd in OpenSSH 4.3 in Red Hat Enterprise Linux (RHEL) 5.4 a…

Mitigation only
Fix from $1,600 2009-10-01
Openssh HIGH 9.3
CVE-2008-3844

Certain Red Hat Enterprise Linux (RHEL) 4 and 5 packages for OpenSSH, as signed in August 2008 using a legitimate Red Hat GPG key, contain an externa…

Mitigation only
Fix from $1,950 2008-08-27
Openssh MEDIUM 6.5
CVE-2008-3234EPSS 6%

sshd in OpenSSH 4 on Debian GNU/Linux, and the 20070303 OpenSSH snapshot, allows remote authenticated users to obtain access to arbitrary SELinux rol…

No fix yet
Fix from $1,600 2008-07-18
Openssh MEDIUM 6.9
CVE-2008-1483

OpenSSH 4.3p2, and probably other versions, allows local users to hijack forwarded X connections by causing ssh to set DISPLAY to :10, even when anot…

Mitigation only
Fix from $1,600 2008-03-24
Openssh MEDIUM 5.0
CVE-2007-2243

OpenSSH 4.6 and earlier, when ChallengeResponseAuthentication is enabled, allows remote attackers to determine the existence of user accounts by atte…

Mitigation only
Fix from $1,600 2007-04-25
OpenBSD HIGH 7.5
CVE-2004-1799

PF in certain OpenBSD versions, when stateful filtering is enabled, does not limit packets for a session to the original interface, which allows remo…

Mitigation only
Fix from $1,950 2004-12-31
Openssh MEDIUM 6.8
CVE-2004-2760EPSS 9%

sshd in OpenSSH 3.5p1, when PermitRootLogin is disabled, immediately closes the TCP connection after a root login attempt with the correct password, …

Mitigation only
Fix from $1,600 2004-12-31
Openssh MEDIUM 5.0
CVE-2004-2069

sshd.c in OpenSSH 3.6.1p2 and 3.7.1p2 and possibly other versions, when using privilege separation, does not properly signal the non-privileged proce…

Mitigation only
Fix from $1,600 2004-12-31
Openssh HIGH 7.6
CVE-2003-1562EPSS 6%

sshd in OpenSSH 3.6.1p2 and earlier, when PermitRootLogin is disabled and using PAM keyboard-interactive authentication, does not insert a delay afte…

Mitigation only
Fix from $1,950 2003-12-31
Openssh HIGH 10.0
CVE-2003-0786

The SSH1 PAM challenge response authentication in OpenSSH 3.7.1 and 3.7.1p1, when Privilege Separation is disabled, does not check the result of the …

Mitigation only
Fix from $1,950 2003-11-17
Openssh HIGH 7.5
CVE-2003-0787

The PAM conversation function in OpenSSH 3.7.1 and 3.7.1p1 interprets an array of structures as an array of pointers, which allows attackers to modif…

Mitigation only
Fix from $1,950 2003-11-17
OpenBSD MEDIUM 5.0
CVE-2002-0514

PF in OpenBSD 3.0 with the return-rst rule sets the TTL to 128 in the RST packet, which allows remote attackers to determine if a port is being filte…

No fix yet
Fix from $1,600 2002-08-12