Vulnerability index

Browse CVEs

176 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

OpenBSD MEDIUM 5.0
CVE-2011-2168

Multiple integer overflows in the glob implementation in libc in OpenBSD before 4.9 might allow context-dependent attackers to have an unspecified im…

Fix: after 4.8
Fix from $1,600 2011-05-24
Openssh HIGH 7.5
CVE-2011-0539

The key_certify function in usr.bin/ssh/key.c in OpenSSH 5.6 and 5.7, when generating legacy certificates using the -t command-line option in ssh-key…

Patch available
Fix from $1,950 2011-02-10
Openssh CRITICAL 9.8
CVE-2010-4478

OpenSSH 5.6 and earlier, when J-PAKE is enabled, does not properly validate the public parameters in the J-PAKE protocol, which allows remote attacke…

Fix: after 5.6
Fix from $2,300 2010-12-06
Openssh MEDIUM 6.9
CVE-2009-2904

A certain Red Hat modification to the ChrootDirectory feature in OpenSSH 4.8, as used in sshd in OpenSSH 4.3 in Red Hat Enterprise Linux (RHEL) 5.4 a…

Mitigation only
Fix from $1,600 2009-10-01
OpenBSD MEDIUM 5.0
CVE-2009-0780

The aspath_prepend function in rde_attr.c in bgpd in OpenBSD 4.3 and 4.4 allows remote attackers to cause a denial of service (application crash) via…

Patch available
Fix from $1,600 2009-03-04
Openssh MEDIUM 5.0
CVE-2008-4109EPSS 29%

A certain Debian patch for OpenSSH before 4.3p2-9etch3 on etch; before 4.6p1-1 on sid and lenny; and on other distributions such as SUSE uses functio…

Fix: after 4.3p2
Fix from $1,600 2008-09-18
Openssh HIGH 9.3
CVE-2008-3844

Certain Red Hat Enterprise Linux (RHEL) 4 and 5 packages for OpenSSH, as signed in August 2008 using a legitimate Red Hat GPG key, contain an externa…

Mitigation only
Fix from $1,950 2008-08-27
Openssh MEDIUM 6.5
CVE-2008-3234EPSS 6%

sshd in OpenSSH 4 on Debian GNU/Linux, and the 20070303 OpenSSH snapshot, allows remote authenticated users to obtain access to arbitrary SELinux rol…

No fix yet
Fix from $1,600 2008-07-18
Openssh MEDIUM 6.5
CVE-2008-1657

OpenSSH 4.4 up to versions before 4.9 allows remote authenticated users to bypass the sshd_config ForceCommand directive by modifying the .ssh/rc ses…

Patch available
Fix from $1,600 2008-04-02
Openssh MEDIUM 6.9
CVE-2008-1483

OpenSSH 4.3p2, and probably other versions, allows local users to hijack forwarded X connections by causing ssh to set DISPLAY to :10, even when anot…

Mitigation only
Fix from $1,600 2008-03-24
OpenBSD HIGH 7.8
CVE-2008-1057

The ip6_check_rh0hdr function in netinet6/ip6_input.c in OpenBSD 4.2 allows attackers to cause a denial of service (panic) via malformed IPv6 routing…

Patch available
Fix from $1,950 2008-02-28
OpenBSD HIGH 7.8
CVE-2008-1058

The tcp_respond function in netinet/tcp_subr.c in OpenBSD 4.1 and 4.2 allows attackers to cause a denial of service (panic) via crafted TCP packets. …

Patch available
Fix from $1,950 2008-02-28
Openssh HIGH 7.5
CVE-2007-4752

ssh in OpenSSH before 4.7 does not properly handle when an untrusted cookie cannot be created and uses a trusted X11 cookie instead, which allows att…

Fix: after 4.6
Fix from $1,950 2007-09-12
Openssh MEDIUM 5.0
CVE-2007-2243

OpenSSH 4.6 and earlier, when ChallengeResponseAuthentication is enabled, allows remote attackers to determine the existence of user accounts by atte…

Mitigation only
Fix from $1,600 2007-04-25
OpenBSD HIGH 10.0
CVE-2007-1365EPSS 18%

Buffer overflow in kern/uipc_mbuf2.c in OpenBSD 3.9 and 4.0 allows remote attackers to execute arbitrary code via fragmented IPv6 packets due to "inc…

Patch available
Fix from $1,950 2007-03-10
OpenBSD MEDIUM 5.0
CVE-2007-0343

OpenBSD before 20070116 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via certain IPv6 ICMP (aka ICMP6) ec…

Fix: after 4.0
Fix from $1,600 2007-01-18
OpenBSD MEDIUM 6.0
CVE-2007-0085

Unspecified vulnerability in sys/dev/pci/vga_pci.c in the VGA graphics driver for wscons in OpenBSD 3.9 and 4.0, when the kernel is compiled with the…

Patch available
Fix from $1,600 2007-01-05
OpenBSD HIGH 7.2
CVE-2006-6164

The _dl_unsetenv function in loader.c in the ELF ld.so in OpenBSD 3.9 and 4.0 does not properly remove duplicate environment variables, which allows …

Patch available
Fix from $1,950 2006-11-29
Openssh HIGH 7.5
CVE-2006-5794

Unspecified vulnerability in the sshd Privilege Separation Monitor in OpenSSH before 4.5 causes weaker verification that authentication has been succ…

Fix: after 4.4
Fix from $1,950 2006-11-08
Openssh MEDIUM 5.0
CVE-2006-4925EPSS 15%

packet.c in ssh in OpenSSH allows remote attackers to cause a denial of service (crash) by sending an invalid protocol sequence with USERAUTH_SUCCESS…

Patch available
Fix from $1,600 2006-09-29
Openssh MEDIUM 5.0
CVE-2006-5052

Unspecified vulnerability in portable OpenSSH before 4.4, when running on some platforms, allows remote attackers to determine the validity of userna…

Patch available
Fix from $1,600 2006-09-27
Openssh HIGH 7.8
CVE-2006-4924EPSS 35%

sshd in OpenSSH before 4.4, when using the version 1 SSH protocol, allows remote attackers to cause a denial of service (CPU consumption) via an SSH …

Patch available
Fix from $1,950 2006-09-27
OpenBSD MEDIUM 5.0
CVE-2006-4436

isakmpd in OpenBSD 3.8, 3.9, and possibly earlier versions, creates Security Associations (SA) with a replay window of size 0 when isakmpd acts as a …

Patch available
Fix from $1,600 2006-08-29
Openssh MEDIUM 5.0
CVE-2005-2797

OpenSSH 4.0, and other versions before 4.2, does not properly handle dynamic port forwarding ("-D" option) when a listen address is not provided, whi…

Patch available
Fix from $1,600 2005-09-06
Openssh MEDIUM 5.0
CVE-2005-2798

sshd in OpenSSH before 4.2, when GSSAPIDelegateCredentials is enabled, allows GSSAPI credentials to be delegated to clients who log in using non-GSSA…

Patch available
Fix from $1,600 2005-09-06
OpenBSD MEDIUM 5.0
CVE-2005-0637

The copy functions in locore.s such as copyout in OpenBSD 3.5 and 3.6, and possibly other BSD based operating systems, may allow attackers to exceed …

Patch available
Fix from $1,600 2005-05-02
OpenBSD MEDIUM 5.0
CVE-2005-0960

Multiple vulnerabilities in the SACK functionality in (1) tcp_input.c and (2) tcp_usrreq.c OpenBSD 3.5 and 3.6 allow remote attackers to cause a deni…

Patch available
Fix from $1,600 2005-05-02
OpenBSD MEDIUM 5.0
CVE-2005-0740

The TCP stack (tcp_input.c) in OpenBSD 3.5 and 3.6 allows remote attackers to cause a denial of service (system panic) via crafted values in the TCP …

Patch available
Fix from $1,600 2005-01-13
OpenBSD HIGH 7.5
CVE-2004-1799

PF in certain OpenBSD versions, when stateful filtering is enabled, does not limit packets for a session to the original interface, which allows remo…

Mitigation only
Fix from $1,950 2004-12-31
OpenBSD HIGH 7.5
CVE-2004-2163

login_radius on OpenBSD 3.2, 3.5, and possibly other versions does not verify the shared secret in a response packet from a RADIUS server, which allo…

Patch available
Fix from $1,950 2004-12-31