Vulnerability index

Browse CVEs

40 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.5 CVE-2021-34999 OpenBSD Kernel Multicast Routing Uninitialized Memory Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sen… OpenBSD Mitigation only Fix from $1,6002024-05-07 HIGH 7.5 CVE-2010-4816 It was found in FreeBSD 8.0, 6.3 and 4.9, and OpenBSD 4.6 that a null pointer dereference in ftpd/popen.c may lead to remote denial of service of the… OpenBSD No fix yet Fix from $1,9502021-06-22 MEDIUM 5.3 CVE-2020-26142 An issue was discovered in the kernel in OpenBSD 6.6. The WEP, WPA, WPA2, and WPA3 implementations treat fragmented frames as full frames. An adversa… OpenBSD Mitigation only Fix from $1,6002021-05-11 CRITICAL 9.8 CVE-2019-19521 libc in OpenBSD 6.6 allows authentication bypass via the -schallenge username, as demonstrated by smtpd, ldapd, or radiusd. This is related to gen/au… OpenBSD No fix yet Fix from $2,3002019-12-05 HIGH 7.8 CVE-2019-19519 In OpenBSD 6.6, local users can use the su -L option to achieve any login class (often excluding root) because there is a logic error in the main fun… OpenBSD No fix yet Fix from $1,9502019-12-05 HIGH 7.8 CVE-2019-19520 xlock in OpenBSD 6.6 allows local users to gain the privileges of the auth group by providing a LIBGL_DRIVERS_PATH environment variable, because xeno… OpenBSD No fix yet Fix from $1,9502019-12-05 HIGH 7.8 CVE-2019-19522 OpenBSD 6.6, in a non-default configuration where S/Key or YubiKey authentication is enabled, allows local users to become root by leveraging members… OpenBSD No fix yet Fix from $1,9502019-12-05 HIGH 7.8 CVE-2016-6240 Integer truncation error in the amap_alloc function in OpenBSD 5.8 and 5.9 allows local users to execute arbitrary code with kernel privileges via a … OpenBSD No fix yet Fix from $1,9502017-03-07 HIGH 7.8 CVE-2016-6241 Integer overflow in the amap_alloc1 function in OpenBSD 5.8 and 5.9 allows local users to execute arbitrary code with kernel privileges via a large s… OpenBSD No fix yet Fix from $1,9502017-03-07 MEDIUM 5.5 CVE-2016-6239 The mmap extension __MAP_NOFAULT in OpenBSD 5.8 and 5.9 allows attackers to cause a denial of service (kernel panic and crash) via a large size value. OpenBSD No fix yet Fix from $1,6002017-03-07 MEDIUM 5.5 CVE-2016-6242 OpenBSD 5.8 and 5.9 allows local users to cause a denial of service (assertion failure and kernel panic) via a large ident value in a kevent system c… OpenBSD No fix yet Fix from $1,6002017-03-07 MEDIUM 5.5 CVE-2016-6243 thrsleep in kern/kern_synch.c in OpenBSD 5.8 and 5.9 allows local users to cause a denial of service (kernel panic) via a crafted value in the tsp pa… OpenBSD No fix yet Fix from $1,6002017-03-07 MEDIUM 5.5 CVE-2016-6245 OpenBSD 5.8 and 5.9 allows local users to cause a denial of service (kernel panic) via a large size in a getdents system call. OpenBSD No fix yet Fix from $1,6002017-03-07 MEDIUM 5.5 CVE-2016-6247 OpenBSD 5.8 and 5.9 allows certain local users to cause a denial of service (kernel panic) by unmounting a filesystem with an open vnode on the mnt_v… OpenBSD No fix yet Fix from $1,6002017-03-07 HIGH 7.5 CVE-2016-6244 The sys_thrsigdivert function in kern/kern_sig.c in the OpenBSD kernel 5.9 allows remote attackers to cause a denial of service (panic) via a negativ… OpenBSD No fix yet Fix from $1,9502017-03-07 MEDIUM 5.3 CVE-2016-1907EPSS 14% The ssh_packet_read_poll2 function in packet.c in OpenSSH before 7.1p2 allows remote attackers to cause a denial of service (out-of-bounds read and a… Openssh Mitigation only Fix from $1,6002016-01-19 HIGH 7.2 CVE-2015-6565 sshd in OpenSSH 6.8 and 6.9 uses world-writable permissions for TTY devices, which allows local users to cause a denial of service (terminal disrupti… Openssh No fix yet Fix from $1,9502015-08-24 MEDIUM 6.0 CVE-2013-4548 The mm_newkeys_from_blob function in monitor_wrap.c in sshd in OpenSSH 6.2 and 6.3, when an AES-GCM cipher is used, does not properly initialize memo… Openssh Mitigation only Fix from $1,6002013-11-08 MEDIUM 6.9 CVE-2009-2904 A certain Red Hat modification to the ChrootDirectory feature in OpenSSH 4.8, as used in sshd in OpenSSH 4.3 in Red Hat Enterprise Linux (RHEL) 5.4 a… Openssh Mitigation only Fix from $1,6002009-10-01 HIGH 9.3 CVE-2008-3844 Certain Red Hat Enterprise Linux (RHEL) 4 and 5 packages for OpenSSH, as signed in August 2008 using a legitimate Red Hat GPG key, contain an externa… Openssh Mitigation only Fix from $1,9502008-08-27 MEDIUM 6.5 CVE-2008-3234EPSS 6% sshd in OpenSSH 4 on Debian GNU/Linux, and the 20070303 OpenSSH snapshot, allows remote authenticated users to obtain access to arbitrary SELinux rol… Openssh No fix yet Fix from $1,6002008-07-18 MEDIUM 6.9 CVE-2008-1483 OpenSSH 4.3p2, and probably other versions, allows local users to hijack forwarded X connections by causing ssh to set DISPLAY to :10, even when anot… Openssh Mitigation only Fix from $1,6002008-03-24 MEDIUM 5.0 CVE-2007-2243 OpenSSH 4.6 and earlier, when ChallengeResponseAuthentication is enabled, allows remote attackers to determine the existence of user accounts by atte… Openssh Mitigation only Fix from $1,6002007-04-25 HIGH 7.5 CVE-2004-1799 PF in certain OpenBSD versions, when stateful filtering is enabled, does not limit packets for a session to the original interface, which allows remo… OpenBSD Mitigation only Fix from $1,9502004-12-31 MEDIUM 6.8 CVE-2004-2760EPSS 9% sshd in OpenSSH 3.5p1, when PermitRootLogin is disabled, immediately closes the TCP connection after a root login attempt with the correct password, … Openssh Mitigation only Fix from $1,6002004-12-31 MEDIUM 5.0 CVE-2004-2069 sshd.c in OpenSSH 3.6.1p2 and 3.7.1p2 and possibly other versions, when using privilege separation, does not properly signal the non-privileged proce… Openssh Mitigation only Fix from $1,6002004-12-31 HIGH 7.6 CVE-2003-1562EPSS 6% sshd in OpenSSH 3.6.1p2 and earlier, when PermitRootLogin is disabled and using PAM keyboard-interactive authentication, does not insert a delay afte… Openssh Mitigation only Fix from $1,9502003-12-31 HIGH 10.0 CVE-2003-0786 The SSH1 PAM challenge response authentication in OpenSSH 3.7.1 and 3.7.1p1, when Privilege Separation is disabled, does not check the result of the … Openssh Mitigation only Fix from $1,9502003-11-17 HIGH 7.5 CVE-2003-0787 The PAM conversation function in OpenSSH 3.7.1 and 3.7.1p1 interprets an array of structures as an array of pointers, which allows attackers to modif… Openssh Mitigation only Fix from $1,9502003-11-17 MEDIUM 5.0 CVE-2002-0514 PF in OpenBSD 3.0 with the return-rst rule sets the TTL to 128 in the RST packet, which allows remote attackers to determine if a port is being filte… OpenBSD No fix yet Fix from $1,6002002-08-12