Vulnerability index

Browse CVEs

176 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.5 CVE-2001-1559 The uipc system calls (uipc_syscalls.c) in OpenBSD 2.9 and 3.0 provide user mode return instead of versus rval kernel mode values to the fdrelease fu… OpenBSD No fix yet Fix from $1,6002001-12-31 HIGH 7.5 CVE-2001-0816 OpenSSH before 2.9.9, when running sftp using sftp-server and using restricted keypairs, allows remote authenticated users to bypass authorized_keys2… Openssh after 2.9.9 Fix from $1,9502001-12-06 HIGH 7.5 CVE-2001-1380 OpenSSH before 2.9.9, while using keypairs and multiple keys of different types in the ~/.ssh/authorized_keys2 file, may not properly handle the "fro… Openssh after 2.9.9 Fix from $1,9502001-10-18 MEDIUM 5.0 CVE-2001-1382EPSS 8% The "echo simulation" traffic analysis countermeasure in OpenSSH before 2.9.9p2 sends an additional echo packet after the password and carriage retur… Openssh after 2.9.9p2 Fix from $1,6002001-09-27 HIGH 7.5 CVE-2001-0572EPSS 7% The SSH protocols 1 and 2 (aka SSH-2) as implemented in OpenSSH and other packages have various weaknesses which can allow a remote attacker to obtai… Openssh Patch available Fix from $1,9502001-08-22 HIGH 7.2 CVE-2001-0529 OpenSSH version 2.9 and earlier, with X forwarding enabled, allows a local attacker to delete any file named 'cookies' via a symlink attack. Openssh after 2.9 Fix from $1,9502001-08-14 HIGH 7.5 CVE-2001-1459 OpenSSH 2.9 and earlier does not initiate a Pluggable Authentication Module (PAM) session if commands are executed with no pty, which allows local us… Openssh Mitigation only Fix from $1,9502001-06-19 HIGH 10.0 CVE-2001-0284 Buffer overflow in IPSEC authentication mechanism for OpenBSD 2.8 and earlier allows remote attackers to cause a denial of service and possibly execu… OpenBSD after 2.8 Fix from $1,9502001-05-03 HIGH 10.0 CVE-2001-0144EPSS 32% CORE SDI SSH1 CRC-32 compensation attack detector allows remote attackers to execute arbitrary commands on an SSH server or client via an integer ove… Openssh Patch available Fix from $1,9502001-03-12 HIGH 7.2 CVE-2000-0312 cron in OpenBSD 2.5 allows local users to gain root privileges via an argv[] that is not NULL terminated, which is passed to cron's fake popen functi… OpenBSD Patch available Fix from $1,9502001-03-12 MEDIUM 5.0 CVE-2000-0310 IP fragment assembly in OpenBSD 2.4 allows a remote attacker to cause a denial of service by sending a large number of fragmented packets. OpenBSD Mitigation only Fix from $1,6002001-03-12 HIGH 7.5 CVE-2000-1169 OpenSSH SSH client before 2.3.0 does not properly disable X11 or agent forwarding, which could allow a malicious SSH server to gain access to the X11… Openssh Patch available Fix from $1,9502001-01-09 HIGH 7.2 CVE-2000-0994 Format string vulnerability in OpenBSD fstat program (and possibly other BSD-based operating systems) allows local users to gain root privileges via … OpenBSD Patch available Fix from $1,9502000-12-19 HIGH 7.2 CVE-2000-0995 Format string vulnerability in OpenBSD yp_passwd program (and possibly other BSD-based operating systems) allows attackers to gain root privileges a … OpenBSD Patch available Fix from $1,9502000-12-19 HIGH 7.2 CVE-2000-0996 Format string vulnerability in OpenBSD su program (and possibly other BSD-based operating systems) allows local attackers to gain root privileges via… OpenBSD Patch available Fix from $1,9502000-12-19 MEDIUM 5.0 CVE-2000-0914 OpenBSD 2.6 and earlier allows remote attackers to cause a denial of service by flooding the server with ARP requests. OpenBSD Patch available Fix from $1,6002000-12-19 MEDIUM 5.0 CVE-2000-0962 The IPSEC implementation in OpenBSD 2.7 does not properly handle empty AH/ESP packets, which allows remote attackers to cause a denial of service. OpenBSD Patch available Fix from $1,6002000-12-19 MEDIUM 5.0 CVE-2000-0992EPSS 6% Directory traversal vulnerability in scp in sshd 1.2.xx allows a remote malicious scp server to overwrite arbitrary files via a .. (dot dot) attack. Openssh Patch available Fix from $1,6002000-12-19 HIGH 10.0 CVE-2000-0999EPSS 12% Format string vulnerabilities in OpenBSD ssh program (and possibly other BSD-based operating systems) allow attackers to gain root privileges. Openssh Patch available Fix from $1,9502000-12-11 MEDIUM 5.0 CVE-2000-0574EPSS 59% FTP servers such as OpenBSD ftpd, NetBSD ftpd, ProFTPd and Opieftpd do not properly cleanse untrusted format strings that are used in the setproctitl… Ftpd Patch available Fix from $1,6002000-07-07 HIGH 10.0 CVE-2000-0525 OpenSSH does not properly drop privileges when the UseLogin option is enabled, which allows local users to execute arbitrary commands by providing th… Openssh Mitigation only Fix from $1,9502000-06-08 MEDIUM 5.1 CVE-2000-0217 The default configuration of SSH allows X forwarding, which could allow a remote attacker to control a client's X sessions via a malicious xauth prog… Openssh Mitigation only Fix from $1,6002000-02-24 MEDIUM 5.0 CVE-1999-0727 A kernel leak in the OpenBSD kernel allows IPsec packets to be sent unencrypted. OpenBSD No fix yet Fix from $1,6001999-08-06 MEDIUM 5.0 CVE-1999-0481 Denial of service in "poll" in OpenBSD. OpenBSD No fix yet Fix from $1,6001999-03-22 MEDIUM 5.0 CVE-1999-0482 OpenBSD kernel crash through TSS handling, as caused by the crashme program. OpenBSD Mitigation only Fix from $1,6001999-03-21 HIGH 7.2 CVE-1999-0062 The chpass command in OpenBSD allows a local user to gain root access through file descriptor leakage. OpenBSD Mitigation only Fix from $1,9501998-08-03