Vulnerability index

Browse CVEs

176 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

OpenBSD HIGH 7.5
CVE-2004-2338

OpenBSD 3.3 and 3.4 does not properly parse Accept and Deny rules without netmasks on big-endian 64-bit platforms such as SPARC64, which may allow re…

Patch available
Fix from $1,950 2004-12-31
Openssh MEDIUM 6.8
CVE-2004-2760EPSS 9%

sshd in OpenSSH 3.5p1, when PermitRootLogin is disabled, immediately closes the TCP connection after a root login attempt with the correct password, …

Mitigation only
Fix from $1,600 2004-12-31
Openssh MEDIUM 5.0
CVE-2004-2069

sshd.c in OpenSSH 3.6.1p2 and 3.7.1p2 and possibly other versions, when using privilege separation, does not properly signal the non-privileged proce…

Mitigation only
Fix from $1,600 2004-12-31
Openssh MEDIUM 6.4
CVE-2004-1653EPSS 12%

The default configuration for OpenSSH enables AllowTcpForwarding, which could allow remote authenticated users to perform a port bounce, when configu…

Fix: after 3.9
Fix from $1,600 2004-08-31
OpenBSD MEDIUM 5.0
CVE-2004-0819

The bridge functionality in OpenBSD 3.4 and 3.5, when running a gateway configured as a bridging firewall with the link2 option for IPSec enabled, al…

Patch available
Fix from $1,600 2004-08-25
OpenBSD HIGH 10.0
CVE-2004-0220

isakmpd in OpenBSD 3.4 and earlier allows remote attackers to cause a denial of service via an ISAKMP packet with a malformed Cert Request payload, w…

Fix: after 3.4
Fix from $1,950 2004-05-04
OpenBSD MEDIUM 5.0
CVE-2004-0218

isakmpd in OpenBSD 3.4 and earlier allows remote attackers to cause a denial of service (infinite loop) via an ISAKMP packet with a zero-length paylo…

Fix: after 3.4
Fix from $1,600 2004-05-04
OpenBSD MEDIUM 5.0
CVE-2004-0219

isakmpd in OpenBSD 3.4 and earlier allows remote attackers to cause a denial of service (crash) via an ISAKMP packet with a malformed IPSEC SA payloa…

Fix: after 3.4
Fix from $1,600 2004-05-04
OpenBSD MEDIUM 5.0
CVE-2004-0221

isakmpd in OpenBSD 3.4 and earlier allows remote attackers to cause a denial of service (crash) via an ISAKMP packet with a delete payload containing…

Fix: after 3.4
Fix from $1,600 2004-05-04
OpenBSD MEDIUM 5.0
CVE-2004-0222

Multiple memory leaks in isakmpd in OpenBSD 3.4 and earlier allow remote attackers to cause a denial of service (memory exhaustion) via certain ISAKM…

Fix: after 3.4
Fix from $1,600 2004-05-04
Openssh HIGH 7.6
CVE-2003-1562EPSS 6%

sshd in OpenSSH 3.6.1p2 and earlier, when PermitRootLogin is disabled and using PAM keyboard-interactive authentication, does not insert a delay afte…

Mitigation only
Fix from $1,950 2003-12-31
Openssh HIGH 10.0
CVE-2003-0786

The SSH1 PAM challenge response authentication in OpenSSH 3.7.1 and 3.7.1p1, when Privilege Separation is disabled, does not check the result of the …

Mitigation only
Fix from $1,950 2003-11-17
Openssh HIGH 7.5
CVE-2003-0787

The PAM conversation function in OpenSSH 3.7.1 and 3.7.1p1 interprets an array of structures as an array of pointers, which allows attackers to modif…

Mitigation only
Fix from $1,950 2003-11-17
Openssh HIGH 7.5
CVE-2003-0682EPSS 9%

"Memory bugs" in OpenSSH 3.7.1 and earlier, with unknown impact, a different set of vulnerabilities than CVE-2003-0693 and CVE-2003-0695.

Fix: after 3.7.1
Fix from $1,950 2003-10-06
Openssh HIGH 7.5
CVE-2003-0695

Multiple "buffer management errors" in OpenSSH before 3.7.1 may allow attackers to cause a denial of service or execute arbitrary code using (1) buff…

Fix: after 3.7.1
Fix from $1,950 2003-10-06
Openssh HIGH 10.0
CVE-2003-0693EPSS 11%

A "buffer management error" in buffer_append_space of buffer.c for OpenSSH before 3.7 may allow remote attackers to execute arbitrary code by causing…

Fix: after 3.7
Fix from $1,950 2003-09-22
Openssh HIGH 7.5
CVE-2003-0386EPSS 6%

OpenSSH 3.6.1 and earlier, when restricting host access by numeric IP addresses and with VerifyReverseMapping disabled, allows remote attackers to by…

Patch available
Fix from $1,950 2003-07-02
Openssh MEDIUM 5.0
CVE-2003-0190EPSS 77%

OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user does not exist, which allows r…

Fix: 3.2.7 / 3.6.1+
Fix from $1,600 2003-05-12
OpenBSD HIGH 7.2
CVE-2002-1420

Integer signedness error in select() on OpenBSD 3.1 and earlier allows local users to overwrite arbitrary kernel memory via a negative value for the …

Patch available
Fix from $1,950 2003-04-11
OpenBSD MEDIUM 6.8
CVE-2002-2180

The setitimer(2) system call in OpenBSD 2.0 through 3.1 does not properly check certain arguments, which allows local users to write to kernel memory…

Patch available
Fix from $1,600 2002-12-31
Openssh HIGH 7.5
CVE-2002-0765

sshd in OpenSSH 3.2.2, when using YP with netgroups and under certain conditions, may allow users to successfully authenticate and log in with anothe…

Patch available
Fix from $1,950 2002-08-12
OpenBSD HIGH 7.2
CVE-2002-0766

OpenBSD 2.9 through 3.1 allows local users to cause a denial of service (resource exhaustion) and gain root privileges by filling the kernel's file d…

Patch available
Fix from $1,950 2002-08-12
OpenBSD MEDIUM 5.0
CVE-2002-0514

PF in OpenBSD 3.0 with the return-rst rule sets the TTL to 128 in the RST packet, which allows remote attackers to determine if a port is being filte…

No fix yet
Fix from $1,600 2002-08-12
Openssh HIGH 10.0
CVE-2002-0640EPSS 27%

Buffer overflow in sshd in OpenSSH 2.3.1 through 3.3 may allow remote attackers to execute arbitrary code via a large number of responses during chal…

Mitigation only
Fix from $1,950 2002-07-03
Openssh CRITICAL 9.8
CVE-2002-0639EPSS 18%

Integer overflow in sshd in OpenSSH 2.9.9 through 3.3 allows remote attackers to execute arbitrary code during challenge response authentication (Cha…

Fix: after 3.3
Fix from $2,300 2002-07-03
OpenBSD HIGH 7.5
CVE-2002-0557

Vulnerability in OpenBSD 3.0, when using YP with netgroups in the password database, causes (1) rexec or (2) rsh to run another user's shell, or (3) …

Patch available
Fix from $1,950 2002-07-03
OpenBSD HIGH 7.2
CVE-2002-0542

mail in OpenBSD 2.9 and 3.0 processes a tilde (~) escape character in a message even when it is not in interactive mode, which could allow local user…

Patch available
Fix from $1,950 2002-07-03
Openssh HIGH 7.5
CVE-2002-0575

Buffer overflow in OpenSSH before 2.9.9, and 3.x before 3.2.1, with Kerberos/AFS support and KerberosTgtPassing or AFSTokenPassing enabled, allows re…

Patch available
Fix from $1,950 2002-06-18
Openssh HIGH 7.5
CVE-2001-1507

OpenSSH before 3.0.1 with Kerberos V enabled does not properly authenticate users, which could allow remote attackers to login unchallenged.

Patch available
Fix from $1,950 2001-12-31
Openssh MEDIUM 6.8
CVE-2001-1585

SSH protocol 2 (aka SSH-2) public key authentication in the development snapshot of OpenSSH 2.3.1, available from 2001-01-18 through 2001-02-08, does…

Patch available
Fix from $1,600 2001-12-31