Vulnerability index

Browse CVEs

176 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

OpenBSD MEDIUM 5.5
CVE-2001-1559

The uipc system calls (uipc_syscalls.c) in OpenBSD 2.9 and 3.0 provide user mode return instead of versus rval kernel mode values to the fdrelease fu…

No fix yet
Fix from $1,600 2001-12-31
Openssh HIGH 7.5
CVE-2001-0816

OpenSSH before 2.9.9, when running sftp using sftp-server and using restricted keypairs, allows remote authenticated users to bypass authorized_keys2…

Fix: after 2.9.9
Fix from $1,950 2001-12-06
Openssh HIGH 7.5
CVE-2001-1380

OpenSSH before 2.9.9, while using keypairs and multiple keys of different types in the ~/.ssh/authorized_keys2 file, may not properly handle the "fro…

Fix: after 2.9.9
Fix from $1,950 2001-10-18
Openssh MEDIUM 5.0
CVE-2001-1382EPSS 8%

The "echo simulation" traffic analysis countermeasure in OpenSSH before 2.9.9p2 sends an additional echo packet after the password and carriage retur…

Fix: after 2.9.9p2
Fix from $1,600 2001-09-27
Openssh HIGH 7.5
CVE-2001-0572EPSS 7%

The SSH protocols 1 and 2 (aka SSH-2) as implemented in OpenSSH and other packages have various weaknesses which can allow a remote attacker to obtai…

Patch available
Fix from $1,950 2001-08-22
Openssh HIGH 7.2
CVE-2001-0529

OpenSSH version 2.9 and earlier, with X forwarding enabled, allows a local attacker to delete any file named 'cookies' via a symlink attack.

Fix: after 2.9
Fix from $1,950 2001-08-14
Openssh HIGH 7.5
CVE-2001-1459

OpenSSH 2.9 and earlier does not initiate a Pluggable Authentication Module (PAM) session if commands are executed with no pty, which allows local us…

Mitigation only
Fix from $1,950 2001-06-19
OpenBSD HIGH 10.0
CVE-2001-0284

Buffer overflow in IPSEC authentication mechanism for OpenBSD 2.8 and earlier allows remote attackers to cause a denial of service and possibly execu…

Fix: after 2.8
Fix from $1,950 2001-05-03
Openssh HIGH 10.0
CVE-2001-0144EPSS 32%

CORE SDI SSH1 CRC-32 compensation attack detector allows remote attackers to execute arbitrary commands on an SSH server or client via an integer ove…

Patch available
Fix from $1,950 2001-03-12
OpenBSD HIGH 7.2
CVE-2000-0312

cron in OpenBSD 2.5 allows local users to gain root privileges via an argv[] that is not NULL terminated, which is passed to cron's fake popen functi…

Patch available
Fix from $1,950 2001-03-12
OpenBSD MEDIUM 5.0
CVE-2000-0310

IP fragment assembly in OpenBSD 2.4 allows a remote attacker to cause a denial of service by sending a large number of fragmented packets.

Mitigation only
Fix from $1,600 2001-03-12
Openssh HIGH 7.5
CVE-2000-1169

OpenSSH SSH client before 2.3.0 does not properly disable X11 or agent forwarding, which could allow a malicious SSH server to gain access to the X11…

Patch available
Fix from $1,950 2001-01-09
OpenBSD HIGH 7.2
CVE-2000-0994

Format string vulnerability in OpenBSD fstat program (and possibly other BSD-based operating systems) allows local users to gain root privileges via …

Patch available
Fix from $1,950 2000-12-19
OpenBSD HIGH 7.2
CVE-2000-0995

Format string vulnerability in OpenBSD yp_passwd program (and possibly other BSD-based operating systems) allows attackers to gain root privileges a …

Patch available
Fix from $1,950 2000-12-19
OpenBSD HIGH 7.2
CVE-2000-0996

Format string vulnerability in OpenBSD su program (and possibly other BSD-based operating systems) allows local attackers to gain root privileges via…

Patch available
Fix from $1,950 2000-12-19
OpenBSD MEDIUM 5.0
CVE-2000-0914

OpenBSD 2.6 and earlier allows remote attackers to cause a denial of service by flooding the server with ARP requests.

Patch available
Fix from $1,600 2000-12-19
OpenBSD MEDIUM 5.0
CVE-2000-0962

The IPSEC implementation in OpenBSD 2.7 does not properly handle empty AH/ESP packets, which allows remote attackers to cause a denial of service.

Patch available
Fix from $1,600 2000-12-19
Openssh MEDIUM 5.0
CVE-2000-0992EPSS 6%

Directory traversal vulnerability in scp in sshd 1.2.xx allows a remote malicious scp server to overwrite arbitrary files via a .. (dot dot) attack.

Patch available
Fix from $1,600 2000-12-19
Openssh HIGH 10.0
CVE-2000-0999EPSS 12%

Format string vulnerabilities in OpenBSD ssh program (and possibly other BSD-based operating systems) allow attackers to gain root privileges.

Patch available
Fix from $1,950 2000-12-11
Ftpd MEDIUM 5.0
CVE-2000-0574EPSS 59%

FTP servers such as OpenBSD ftpd, NetBSD ftpd, ProFTPd and Opieftpd do not properly cleanse untrusted format strings that are used in the setproctitl…

Patch available
Fix from $1,600 2000-07-07
Openssh HIGH 10.0
CVE-2000-0525

OpenSSH does not properly drop privileges when the UseLogin option is enabled, which allows local users to execute arbitrary commands by providing th…

Mitigation only
Fix from $1,950 2000-06-08
Openssh MEDIUM 5.1
CVE-2000-0217

The default configuration of SSH allows X forwarding, which could allow a remote attacker to control a client's X sessions via a malicious xauth prog…

Mitigation only
Fix from $1,600 2000-02-24
OpenBSD MEDIUM 5.0
CVE-1999-0727

A kernel leak in the OpenBSD kernel allows IPsec packets to be sent unencrypted.

No fix yet
Fix from $1,600 1999-08-06
OpenBSD MEDIUM 5.0
CVE-1999-0481

Denial of service in "poll" in OpenBSD.

No fix yet
Fix from $1,600 1999-03-22
OpenBSD MEDIUM 5.0
CVE-1999-0482

OpenBSD kernel crash through TSS handling, as caused by the crashme program.

Mitigation only
Fix from $1,600 1999-03-21
OpenBSD HIGH 7.2
CVE-1999-0062

The chpass command in OpenBSD allows a local user to gain root access through file descriptor leakage.

Mitigation only
Fix from $1,950 1998-08-03