OpenBSD
by OpenBSD
Source repositories
CVEs (208)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2000-0962 | 0.00 | — | 0.02 | Dec 19, 2000 | The IPSEC implementation in OpenBSD 2.7 does not properly handle empty AH/ESP packets, which allows remote attackers to cause a denial of service. | |||
| CVE-2000-0995 | 0.00 | — | 0.01 | Dec 19, 2000 | Format string vulnerability in OpenBSD yp_passwd program (and possibly other BSD-based operating systems) allows attackers to gain root privileges a malformed name. | |||
| CVE-2000-0996 | 0.00 | — | 0.01 | Dec 19, 2000 | Format string vulnerability in OpenBSD su program (and possibly other BSD-based operating systems) allows local attackers to gain root privileges via a malformed shell. | |||
| CVE-2000-0997 | 0.00 | — | 0.01 | Dec 19, 2000 | Format string vulnerabilities in eeprom program in OpenBSD, NetBSD, and possibly other operating systems allows local attackers to gain root privileges. | |||
| CVE-2000-1010 | 0.00 | — | 0.05 | Dec 11, 2000 | Format string vulnerability in talkd in OpenBSD and possibly other BSD-based OSes allows remote attackers to execute arbitrary commands via a user name that contains format characters. | |||
| CVE-2000-1004 | 0.00 | — | 0.00 | Dec 11, 2000 | Format string vulnerability in OpenBSD photurisd allows local users to execute arbitrary commands via a configuration file directory name that contains formatting characters. | |||
| CVE-2000-0750 | 0.00 | — | 0.02 | Oct 20, 2000 | Buffer overflow in mopd (Maintenance Operations Protocol loader daemon) allows remote attackers to execute arbitrary commands via a long file name. | |||
| CVE-2000-0461 | 0.00 | — | 0.00 | May 29, 2000 | The undocumented semconfig system call in BSD freezes the state of semaphores, which allows local users to cause a denial of service of the semaphore system by using the semconfig call. | |||
| CVE-2000-0092 | 0.00 | — | 0.00 | Jan 19, 2000 | The BSD make program allows local users to modify files via a symlink attack when the -j option is being used. | |||
| CVE-1999-0001 | 0.00 | — | 0.03 | Dec 30, 1999 | ip_input.c in BSD-derived TCP/IP implementations allows remote attackers to cause a denial of service (crash or hang) via crafted packets. | |||
| CVE-1999-0724 | 0.00 | — | 0.00 | Aug 12, 1999 | Buffer overflow in OpenBSD procfs and fdescfs file systems via uio_offset in the readdir() function. | |||
| CVE-1999-0727 | 0.00 | — | 0.01 | Aug 6, 1999 | A kernel leak in the OpenBSD kernel allows IPsec packets to be sent unencrypted. | |||
| CVE-1999-0703 | 0.00 | — | 0.00 | Aug 3, 1999 | OpenBSD, BSDI, and other Unix operating systems allow users to set chflags and fchflags on character and block devices. | |||
| CVE-1999-0481 | 0.00 | — | 0.01 | Mar 22, 1999 | Denial of service in "poll" in OpenBSD. | |||
| CVE-1999-0482 | 0.00 | — | 0.01 | Mar 21, 1999 | OpenBSD kernel crash through TSS handling, as caused by the crashme program. | |||
| CVE-1999-0483 | 0.00 | — | 0.00 | Feb 25, 1999 | OpenBSD crash using nlink value in FFS and EXT2FS filesystems. | |||
| CVE-1999-0484 | 0.00 | — | 0.00 | Feb 23, 1999 | Buffer overflow in OpenBSD ping. | |||
| CVE-1999-0485 | 0.00 | — | 0.01 | Feb 19, 1999 | Remote attackers can cause a system crash through ipintr() in ipq in OpenBSD. | |||
| CVE-1999-0396 | 0.00 | — | 0.01 | Feb 17, 1999 | A race condition between the select() and accept() calls in NetBSD TCP servers allows remote attackers to cause a denial of service. | |||
| CVE-1999-0798 | 0.00 | — | 0.02 | Dec 4, 1998 | Buffer overflow in bootpd on OpenBSD, FreeBSD, and Linux systems via a malformed header type. |
- CVE-2000-0962Dec 19, 2000risk 0.00cvss —epss 0.02
The IPSEC implementation in OpenBSD 2.7 does not properly handle empty AH/ESP packets, which allows remote attackers to cause a denial of service.
- CVE-2000-0995Dec 19, 2000risk 0.00cvss —epss 0.01
Format string vulnerability in OpenBSD yp_passwd program (and possibly other BSD-based operating systems) allows attackers to gain root privileges a malformed name.
- CVE-2000-0996Dec 19, 2000risk 0.00cvss —epss 0.01
Format string vulnerability in OpenBSD su program (and possibly other BSD-based operating systems) allows local attackers to gain root privileges via a malformed shell.
- CVE-2000-0997Dec 19, 2000risk 0.00cvss —epss 0.01
Format string vulnerabilities in eeprom program in OpenBSD, NetBSD, and possibly other operating systems allows local attackers to gain root privileges.
- CVE-2000-1010Dec 11, 2000risk 0.00cvss —epss 0.05
Format string vulnerability in talkd in OpenBSD and possibly other BSD-based OSes allows remote attackers to execute arbitrary commands via a user name that contains format characters.
- CVE-2000-1004Dec 11, 2000risk 0.00cvss —epss 0.00
Format string vulnerability in OpenBSD photurisd allows local users to execute arbitrary commands via a configuration file directory name that contains formatting characters.
- CVE-2000-0750Oct 20, 2000risk 0.00cvss —epss 0.02
Buffer overflow in mopd (Maintenance Operations Protocol loader daemon) allows remote attackers to execute arbitrary commands via a long file name.
- CVE-2000-0461May 29, 2000risk 0.00cvss —epss 0.00
The undocumented semconfig system call in BSD freezes the state of semaphores, which allows local users to cause a denial of service of the semaphore system by using the semconfig call.
- CVE-2000-0092Jan 19, 2000risk 0.00cvss —epss 0.00
The BSD make program allows local users to modify files via a symlink attack when the -j option is being used.
- CVE-1999-0001Dec 30, 1999risk 0.00cvss —epss 0.03
ip_input.c in BSD-derived TCP/IP implementations allows remote attackers to cause a denial of service (crash or hang) via crafted packets.
- CVE-1999-0724Aug 12, 1999risk 0.00cvss —epss 0.00
Buffer overflow in OpenBSD procfs and fdescfs file systems via uio_offset in the readdir() function.
- CVE-1999-0727Aug 6, 1999risk 0.00cvss —epss 0.01
A kernel leak in the OpenBSD kernel allows IPsec packets to be sent unencrypted.
- CVE-1999-0703Aug 3, 1999risk 0.00cvss —epss 0.00
OpenBSD, BSDI, and other Unix operating systems allow users to set chflags and fchflags on character and block devices.
- CVE-1999-0481Mar 22, 1999risk 0.00cvss —epss 0.01
Denial of service in "poll" in OpenBSD.
- CVE-1999-0482Mar 21, 1999risk 0.00cvss —epss 0.01
OpenBSD kernel crash through TSS handling, as caused by the crashme program.
- CVE-1999-0483Feb 25, 1999risk 0.00cvss —epss 0.00
OpenBSD crash using nlink value in FFS and EXT2FS filesystems.
- CVE-1999-0484Feb 23, 1999risk 0.00cvss —epss 0.00
Buffer overflow in OpenBSD ping.
- CVE-1999-0485Feb 19, 1999risk 0.00cvss —epss 0.01
Remote attackers can cause a system crash through ipintr() in ipq in OpenBSD.
- CVE-1999-0396Feb 17, 1999risk 0.00cvss —epss 0.01
A race condition between the select() and accept() calls in NetBSD TCP servers allows remote attackers to cause a denial of service.
- CVE-1999-0798Dec 4, 1998risk 0.00cvss —epss 0.02
Buffer overflow in bootpd on OpenBSD, FreeBSD, and Linux systems via a malformed header type.
Page 10 of 11