Vendor CVEs
OpenBSD
All CVEs
364 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2002-2280 | 0.00 | — | 0.00 | Dec 31, 2002 | syslogd on OpenBSD 2.9 through 3.2 does not change the source IP address of syslog packets when the machine's IP addressed is changed without rebooting, e.g. via ifconfig, which can cause incorrect information to be sent to the syslog server. | |||
| CVE-2002-2180 | 0.00 | — | 0.01 | Dec 31, 2002 | The setitimer(2) system call in OpenBSD 2.0 through 3.1 does not properly check certain arguments, which allows local users to write to kernel memory and possibly gain root privileges, possibly via an integer signedness error. | |||
| CVE-2002-1345 | 0.00 | — | 0.03 | Dec 23, 2002 | Directory traversal vulnerabilities in multiple FTP clients on UNIX systems allow remote malicious FTP servers to create or overwrite files as the client user via filenames containing /absolute/path or .. (dot dot) sequences. | |||
| CVE-2002-0514 | 0.00 | — | 0.02 | Aug 12, 2002 | PF in OpenBSD 3.0 with the return-rst rule sets the TTL to 128 in the RST packet, which allows remote attackers to determine if a port is being filtered because the TTL is different than the default TTL. | |||
| CVE-2002-0766 | 0.00 | — | 0.01 | Aug 12, 2002 | OpenBSD 2.9 through 3.1 allows local users to cause a denial of service (resource exhaustion) and gain root privileges by filling the kernel's file descriptor table and closing file descriptors 0, 1, or 2 before executing a privileged process, which is not properly handled when… | |||
| CVE-2000-1208 | 0.00 | — | 0.00 | Aug 12, 2002 | Format string vulnerability in startprinting() function of printjob.c in BSD-based lpr lpd package may allow local users to gain privileges via an improper syslog call that uses format strings from the checkremote() call. | |||
| CVE-2002-0765 | 0.00 | — | 0.01 | Aug 12, 2002 | sshd in OpenSSH 3.2.2, when using YP with netgroups and under certain conditions, may allow users to successfully authenticate and log in with another user's password. | |||
| CVE-2002-0414 | 0.00 | — | 0.01 | Aug 12, 2002 | KAME-derived implementations of IPsec on NetBSD 1.5.2, FreeBSD 4.5, and other operating systems, does not properly consult the Security Policy Database (SPD), which could cause a Security Gateway (SG) that does not use Encapsulating Security Payload (ESP) to forward forged IPv4… | |||
| CVE-2002-0701 | 0.00 | — | 0.00 | Jul 23, 2002 | ktrace in BSD-based operating systems allows the owner of a process with special privileges to trace the process after its privileges have been lowered, which may allow the owner to obtain sensitive information that the process obtained while it was running with the extra… | |||
| CVE-2002-0557 | 0.00 | — | 0.01 | Jul 3, 2002 | Vulnerability in OpenBSD 3.0, when using YP with netgroups in the password database, causes (1) rexec or (2) rsh to run another user's shell, or (3) atrun to change to a different user's directory, possibly due to memory allocation failures or an incorrect call to… | |||
| CVE-2002-0640 | 0.00 | — | 0.27 | Jul 3, 2002 | Buffer overflow in sshd in OpenSSH 2.3.1 through 3.3 may allow remote attackers to execute arbitrary code via a large number of responses during challenge response authentication when OpenBSD is using PAM modules with interactive keyboard authentication… | |||
| CVE-2002-0381 | 0.00 | — | 0.02 | Jun 25, 2002 | The TCP implementation in various BSD operating systems (tcp_input.c) does not properly block connections to broadcast addresses, which could allow remote attackers to bypass intended filters via packets with a unicast link layer address and an IP broadcast address. | |||
| CVE-2001-1507 | 0.00 | — | 0.02 | Dec 31, 2001 | OpenSSH before 3.0.1 with Kerberos V enabled does not properly authenticate users, which could allow remote attackers to login unchallenged. | |||
| CVE-2001-1585 | 0.00 | — | 0.02 | Dec 31, 2001 | SSH protocol 2 (aka SSH-2) public key authentication in the development snapshot of OpenSSH 2.3.1, available from 2001-01-18 through 2001-02-08, does not perform a challenge-response step to ensure that the client has the proper private key, which allows remote attackers to… | |||
| CVE-2001-0872 | 0.00 | — | 0.01 | Dec 21, 2001 | OpenSSH 3.0.1 and earlier with UseLogin enabled does not properly cleanse critical environment variables such as LD_PRELOAD, which allows local users to gain root privileges. | |||
| CVE-2001-0816 | 0.00 | — | 0.02 | Dec 6, 2001 | OpenSSH before 2.9.9, when running sftp using sftp-server and using restricted keypairs, allows remote authenticated users to bypass authorized_keys2 command= restrictions using sftp commands. | |||
| CVE-2001-1415 | 0.00 | — | 0.00 | Nov 13, 2001 | vi.recover in OpenBSD before 3.1 allows local users to remove arbitrary zero-byte files such as device nodes. | |||
| CVE-2001-1380 | 0.00 | — | 0.03 | Oct 18, 2001 | OpenSSH before 2.9.9, while using keypairs and multiple keys of different types in the ~/.ssh/authorized_keys2 file, may not properly handle the "from" option associated with a key, which could allow remote attackers to login from unauthorized IP addresses. | |||
| CVE-2001-1145 | 0.00 | — | 0.00 | Aug 17, 2001 | fts routines in FreeBSD 4.3 and earlier, NetBSD before 1.5.2, and OpenBSD 2.9 and earlier can be forced to change (chdir) into a different directory than intended when the directory above the current directory is moved, which could cause scripts to perform dangerous actions on… | |||
| CVE-2001-0529 | 0.00 | — | 0.01 | Aug 14, 2001 | OpenSSH version 2.9 and earlier, with X forwarding enabled, allows a local attacker to delete any file named 'cookies' via a symlink attack. | |||
| CVE-2001-1244 | 0.00 | — | 0.21 | Jul 7, 2001 | Multiple TCP implementations could allow remote attackers to cause a denial of service (bandwidth and CPU exhaustion) by setting the maximum segment size (MSS) to a very small number and requesting large amounts of data, which generates more packets with less TCP-level data that… | |||
| CVE-2001-0361 | 0.00 | — | 0.03 | Jun 27, 2001 | Implementations of SSH version 1.5, including (1) OpenSSH up to version 2.3.0, (2) AppGate, and (3) ssh-1 up to version 1.2.31, in certain configurations, allow a remote attacker to decrypt and/or alter traffic via a "Bleichenbacher attack" on PKCS#1 version 1.5. | |||
| CVE-2001-0378 | 0.00 | — | 0.00 | Jun 27, 2001 | readline prior to 4.1, in OpenBSD 2.8 and earlier, creates history files with insecure permissions, which allows a local attacker to recover potentially sensitive information via readline history files. | |||
| CVE-2001-1459 | 0.00 | — | 0.02 | Jun 19, 2001 | OpenSSH 2.9 and earlier does not initiate a Pluggable Authentication Module (PAM) session if commands are executed with no pty, which allows local users to bypass resource limits (rlimits) set in pam.d. | |||
| CVE-2001-1047 | 0.00 | — | 0.00 | Jun 2, 2001 | Race condition in OpenBSD VFS allows local users to cause a denial of service (kernel panic) by (1) creating a pipe in one thread and causing another thread to set one of the file descriptors to NULL via a close, or (2) calling dup2 on a file descriptor in one process, then… | |||
| CVE-2001-0268 | 0.00 | — | 0.01 | May 3, 2001 | The i386_set_ldt system call in NetBSD 1.5 and earlier, and OpenBSD 2.8 and earlier, when the USER_LDT kernel option is enabled, does not validate a call gate target, which allows local users to gain root privileges by creating a segment call gate in the Local Descriptor Table… | |||
| CVE-2001-0284 | 0.00 | — | 0.03 | May 3, 2001 | Buffer overflow in IPSEC authentication mechanism for OpenBSD 2.8 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a malformed Authentication header (AH) IPv4 option. | |||
| CVE-2000-0310 | 0.00 | — | 0.01 | Mar 12, 2001 | IP fragment assembly in OpenBSD 2.4 allows a remote attacker to cause a denial of service by sending a large number of fragmented packets. | |||
| CVE-2000-0313 | 0.00 | — | 0.00 | Mar 12, 2001 | Vulnerability in OpenBSD 2.6 allows a local user to change interface media configurations. | |||
| CVE-2000-0309 | 0.00 | — | 0.00 | Mar 12, 2001 | The i386 trace-trap handling in OpenBSD 2.4 with DDB enabled allows a local user to cause a denial of service. | |||
| CVE-2000-0312 | 0.00 | — | 0.01 | Mar 12, 2001 | cron in OpenBSD 2.5 allows local users to gain root privileges via an argv[] that is not NULL terminated, which is passed to cron's fake popen function. | |||
| CVE-2000-1169 | 0.00 | — | 0.02 | Jan 9, 2001 | OpenSSH SSH client before 2.3.0 does not properly disable X11 or agent forwarding, which could allow a malicious SSH server to gain access to the X11 display and sniff X11 events, or gain access to the ssh-agent. | |||
| CVE-2000-0962 | 0.00 | — | 0.02 | Dec 19, 2000 | The IPSEC implementation in OpenBSD 2.7 does not properly handle empty AH/ESP packets, which allows remote attackers to cause a denial of service. | |||
| CVE-2000-0996 | 0.00 | — | 0.01 | Dec 19, 2000 | Format string vulnerability in OpenBSD su program (and possibly other BSD-based operating systems) allows local attackers to gain root privileges via a malformed shell. | |||
| CVE-2000-0997 | 0.00 | — | 0.01 | Dec 19, 2000 | Format string vulnerabilities in eeprom program in OpenBSD, NetBSD, and possibly other operating systems allows local attackers to gain root privileges. | |||
| CVE-2000-0995 | 0.00 | — | 0.01 | Dec 19, 2000 | Format string vulnerability in OpenBSD yp_passwd program (and possibly other BSD-based operating systems) allows attackers to gain root privileges a malformed name. | |||
| CVE-2000-1004 | 0.00 | — | 0.00 | Dec 11, 2000 | Format string vulnerability in OpenBSD photurisd allows local users to execute arbitrary commands via a configuration file directory name that contains formatting characters. | |||
| CVE-2000-1010 | 0.00 | — | 0.05 | Dec 11, 2000 | Format string vulnerability in talkd in OpenBSD and possibly other BSD-based OSes allows remote attackers to execute arbitrary commands via a user name that contains format characters. | |||
| CVE-2000-0750 | 0.00 | — | 0.02 | Oct 20, 2000 | Buffer overflow in mopd (Maintenance Operations Protocol loader daemon) allows remote attackers to execute arbitrary commands via a long file name. | |||
| CVE-2000-0525 | 0.00 | — | 0.03 | Jun 8, 2000 | OpenSSH does not properly drop privileges when the UseLogin option is enabled, which allows local users to execute arbitrary commands by providing the command to the ssh daemon. | |||
| CVE-2000-0461 | 0.00 | — | 0.00 | May 29, 2000 | The undocumented semconfig system call in BSD freezes the state of semaphores, which allows local users to cause a denial of service of the semaphore system by using the semconfig call. | |||
| CVE-2000-0217 | 0.00 | — | 0.01 | Feb 24, 2000 | The default configuration of SSH allows X forwarding, which could allow a remote attacker to control a client's X sessions via a malicious xauth program. | |||
| CVE-2000-0143 | 0.00 | — | 0.00 | Feb 11, 2000 | The SSH protocol server sshd allows local users without shell access to redirect a TCP connection through a service that uses the standard system password database for authentication, such as POP or FTP. | |||
| CVE-2000-0092 | 0.00 | — | 0.00 | Jan 19, 2000 | The BSD make program allows local users to modify files via a symlink attack when the -j option is being used. | |||
| CVE-1999-0001 | 0.00 | — | 0.03 | Dec 30, 1999 | ip_input.c in BSD-derived TCP/IP implementations allows remote attackers to cause a denial of service (crash or hang) via crafted packets. | |||
| CVE-1999-1010 | 0.00 | — | 0.01 | Dec 14, 1999 | An SSH 1.2.27 server allows a client to use the "none" cipher, even if it is not allowed by the server policy. | |||
| CVE-1999-0724 | 0.00 | — | 0.00 | Aug 12, 1999 | Buffer overflow in OpenBSD procfs and fdescfs file systems via uio_offset in the readdir() function. | |||
| CVE-1999-0727 | 0.00 | — | 0.01 | Aug 6, 1999 | A kernel leak in the OpenBSD kernel allows IPsec packets to be sent unencrypted. | |||
| CVE-1999-0703 | 0.00 | — | 0.00 | Aug 3, 1999 | OpenBSD, BSDI, and other Unix operating systems allow users to set chflags and fchflags on character and block devices. | |||
| CVE-1999-0481 | 0.00 | — | 0.01 | Mar 22, 1999 | Denial of service in "poll" in OpenBSD. |
- CVE-2002-2280Dec 31, 2002risk 0.00cvss —epss 0.00
syslogd on OpenBSD 2.9 through 3.2 does not change the source IP address of syslog packets when the machine's IP addressed is changed without rebooting, e.g. via ifconfig, which can cause incorrect information to be sent to the syslog server.
- CVE-2002-2180Dec 31, 2002risk 0.00cvss —epss 0.01
The setitimer(2) system call in OpenBSD 2.0 through 3.1 does not properly check certain arguments, which allows local users to write to kernel memory and possibly gain root privileges, possibly via an integer signedness error.
- CVE-2002-1345Dec 23, 2002risk 0.00cvss —epss 0.03
Directory traversal vulnerabilities in multiple FTP clients on UNIX systems allow remote malicious FTP servers to create or overwrite files as the client user via filenames containing /absolute/path or .. (dot dot) sequences.
- CVE-2002-0514Aug 12, 2002risk 0.00cvss —epss 0.02
PF in OpenBSD 3.0 with the return-rst rule sets the TTL to 128 in the RST packet, which allows remote attackers to determine if a port is being filtered because the TTL is different than the default TTL.
- CVE-2002-0766Aug 12, 2002risk 0.00cvss —epss 0.01
OpenBSD 2.9 through 3.1 allows local users to cause a denial of service (resource exhaustion) and gain root privileges by filling the kernel's file descriptor table and closing file descriptors 0, 1, or 2 before executing a privileged process, which is not properly handled when…
- CVE-2000-1208Aug 12, 2002risk 0.00cvss —epss 0.00
Format string vulnerability in startprinting() function of printjob.c in BSD-based lpr lpd package may allow local users to gain privileges via an improper syslog call that uses format strings from the checkremote() call.
- CVE-2002-0765Aug 12, 2002risk 0.00cvss —epss 0.01
sshd in OpenSSH 3.2.2, when using YP with netgroups and under certain conditions, may allow users to successfully authenticate and log in with another user's password.
- CVE-2002-0414Aug 12, 2002risk 0.00cvss —epss 0.01
KAME-derived implementations of IPsec on NetBSD 1.5.2, FreeBSD 4.5, and other operating systems, does not properly consult the Security Policy Database (SPD), which could cause a Security Gateway (SG) that does not use Encapsulating Security Payload (ESP) to forward forged IPv4…
- CVE-2002-0701Jul 23, 2002risk 0.00cvss —epss 0.00
ktrace in BSD-based operating systems allows the owner of a process with special privileges to trace the process after its privileges have been lowered, which may allow the owner to obtain sensitive information that the process obtained while it was running with the extra…
- CVE-2002-0557Jul 3, 2002risk 0.00cvss —epss 0.01
Vulnerability in OpenBSD 3.0, when using YP with netgroups in the password database, causes (1) rexec or (2) rsh to run another user's shell, or (3) atrun to change to a different user's directory, possibly due to memory allocation failures or an incorrect call to…
- CVE-2002-0640Jul 3, 2002risk 0.00cvss —epss 0.27
Buffer overflow in sshd in OpenSSH 2.3.1 through 3.3 may allow remote attackers to execute arbitrary code via a large number of responses during challenge response authentication when OpenBSD is using PAM modules with interactive keyboard authentication…
- CVE-2002-0381Jun 25, 2002risk 0.00cvss —epss 0.02
The TCP implementation in various BSD operating systems (tcp_input.c) does not properly block connections to broadcast addresses, which could allow remote attackers to bypass intended filters via packets with a unicast link layer address and an IP broadcast address.
- CVE-2001-1507Dec 31, 2001risk 0.00cvss —epss 0.02
OpenSSH before 3.0.1 with Kerberos V enabled does not properly authenticate users, which could allow remote attackers to login unchallenged.
- CVE-2001-1585Dec 31, 2001risk 0.00cvss —epss 0.02
SSH protocol 2 (aka SSH-2) public key authentication in the development snapshot of OpenSSH 2.3.1, available from 2001-01-18 through 2001-02-08, does not perform a challenge-response step to ensure that the client has the proper private key, which allows remote attackers to…
- CVE-2001-0872Dec 21, 2001risk 0.00cvss —epss 0.01
OpenSSH 3.0.1 and earlier with UseLogin enabled does not properly cleanse critical environment variables such as LD_PRELOAD, which allows local users to gain root privileges.
- CVE-2001-0816Dec 6, 2001risk 0.00cvss —epss 0.02
OpenSSH before 2.9.9, when running sftp using sftp-server and using restricted keypairs, allows remote authenticated users to bypass authorized_keys2 command= restrictions using sftp commands.
- CVE-2001-1415Nov 13, 2001risk 0.00cvss —epss 0.00
vi.recover in OpenBSD before 3.1 allows local users to remove arbitrary zero-byte files such as device nodes.
- CVE-2001-1380Oct 18, 2001risk 0.00cvss —epss 0.03
OpenSSH before 2.9.9, while using keypairs and multiple keys of different types in the ~/.ssh/authorized_keys2 file, may not properly handle the "from" option associated with a key, which could allow remote attackers to login from unauthorized IP addresses.
- CVE-2001-1145Aug 17, 2001risk 0.00cvss —epss 0.00
fts routines in FreeBSD 4.3 and earlier, NetBSD before 1.5.2, and OpenBSD 2.9 and earlier can be forced to change (chdir) into a different directory than intended when the directory above the current directory is moved, which could cause scripts to perform dangerous actions on…
- CVE-2001-0529Aug 14, 2001risk 0.00cvss —epss 0.01
OpenSSH version 2.9 and earlier, with X forwarding enabled, allows a local attacker to delete any file named 'cookies' via a symlink attack.
- CVE-2001-1244Jul 7, 2001risk 0.00cvss —epss 0.21
Multiple TCP implementations could allow remote attackers to cause a denial of service (bandwidth and CPU exhaustion) by setting the maximum segment size (MSS) to a very small number and requesting large amounts of data, which generates more packets with less TCP-level data that…
- CVE-2001-0361Jun 27, 2001risk 0.00cvss —epss 0.03
Implementations of SSH version 1.5, including (1) OpenSSH up to version 2.3.0, (2) AppGate, and (3) ssh-1 up to version 1.2.31, in certain configurations, allow a remote attacker to decrypt and/or alter traffic via a "Bleichenbacher attack" on PKCS#1 version 1.5.
- CVE-2001-0378Jun 27, 2001risk 0.00cvss —epss 0.00
readline prior to 4.1, in OpenBSD 2.8 and earlier, creates history files with insecure permissions, which allows a local attacker to recover potentially sensitive information via readline history files.
- CVE-2001-1459Jun 19, 2001risk 0.00cvss —epss 0.02
OpenSSH 2.9 and earlier does not initiate a Pluggable Authentication Module (PAM) session if commands are executed with no pty, which allows local users to bypass resource limits (rlimits) set in pam.d.
- CVE-2001-1047Jun 2, 2001risk 0.00cvss —epss 0.00
Race condition in OpenBSD VFS allows local users to cause a denial of service (kernel panic) by (1) creating a pipe in one thread and causing another thread to set one of the file descriptors to NULL via a close, or (2) calling dup2 on a file descriptor in one process, then…
- CVE-2001-0268May 3, 2001risk 0.00cvss —epss 0.01
The i386_set_ldt system call in NetBSD 1.5 and earlier, and OpenBSD 2.8 and earlier, when the USER_LDT kernel option is enabled, does not validate a call gate target, which allows local users to gain root privileges by creating a segment call gate in the Local Descriptor Table…
- CVE-2001-0284May 3, 2001risk 0.00cvss —epss 0.03
Buffer overflow in IPSEC authentication mechanism for OpenBSD 2.8 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a malformed Authentication header (AH) IPv4 option.
- CVE-2000-0310Mar 12, 2001risk 0.00cvss —epss 0.01
IP fragment assembly in OpenBSD 2.4 allows a remote attacker to cause a denial of service by sending a large number of fragmented packets.
- CVE-2000-0313Mar 12, 2001risk 0.00cvss —epss 0.00
Vulnerability in OpenBSD 2.6 allows a local user to change interface media configurations.
- CVE-2000-0309Mar 12, 2001risk 0.00cvss —epss 0.00
The i386 trace-trap handling in OpenBSD 2.4 with DDB enabled allows a local user to cause a denial of service.
- CVE-2000-0312Mar 12, 2001risk 0.00cvss —epss 0.01
cron in OpenBSD 2.5 allows local users to gain root privileges via an argv[] that is not NULL terminated, which is passed to cron's fake popen function.
- CVE-2000-1169Jan 9, 2001risk 0.00cvss —epss 0.02
OpenSSH SSH client before 2.3.0 does not properly disable X11 or agent forwarding, which could allow a malicious SSH server to gain access to the X11 display and sniff X11 events, or gain access to the ssh-agent.
- CVE-2000-0962Dec 19, 2000risk 0.00cvss —epss 0.02
The IPSEC implementation in OpenBSD 2.7 does not properly handle empty AH/ESP packets, which allows remote attackers to cause a denial of service.
- CVE-2000-0996Dec 19, 2000risk 0.00cvss —epss 0.01
Format string vulnerability in OpenBSD su program (and possibly other BSD-based operating systems) allows local attackers to gain root privileges via a malformed shell.
- CVE-2000-0997Dec 19, 2000risk 0.00cvss —epss 0.01
Format string vulnerabilities in eeprom program in OpenBSD, NetBSD, and possibly other operating systems allows local attackers to gain root privileges.
- CVE-2000-0995Dec 19, 2000risk 0.00cvss —epss 0.01
Format string vulnerability in OpenBSD yp_passwd program (and possibly other BSD-based operating systems) allows attackers to gain root privileges a malformed name.
- CVE-2000-1004Dec 11, 2000risk 0.00cvss —epss 0.00
Format string vulnerability in OpenBSD photurisd allows local users to execute arbitrary commands via a configuration file directory name that contains formatting characters.
- CVE-2000-1010Dec 11, 2000risk 0.00cvss —epss 0.05
Format string vulnerability in talkd in OpenBSD and possibly other BSD-based OSes allows remote attackers to execute arbitrary commands via a user name that contains format characters.
- CVE-2000-0750Oct 20, 2000risk 0.00cvss —epss 0.02
Buffer overflow in mopd (Maintenance Operations Protocol loader daemon) allows remote attackers to execute arbitrary commands via a long file name.
- CVE-2000-0525Jun 8, 2000risk 0.00cvss —epss 0.03
OpenSSH does not properly drop privileges when the UseLogin option is enabled, which allows local users to execute arbitrary commands by providing the command to the ssh daemon.
- CVE-2000-0461May 29, 2000risk 0.00cvss —epss 0.00
The undocumented semconfig system call in BSD freezes the state of semaphores, which allows local users to cause a denial of service of the semaphore system by using the semconfig call.
- CVE-2000-0217Feb 24, 2000risk 0.00cvss —epss 0.01
The default configuration of SSH allows X forwarding, which could allow a remote attacker to control a client's X sessions via a malicious xauth program.
- CVE-2000-0143Feb 11, 2000risk 0.00cvss —epss 0.00
The SSH protocol server sshd allows local users without shell access to redirect a TCP connection through a service that uses the standard system password database for authentication, such as POP or FTP.
- CVE-2000-0092Jan 19, 2000risk 0.00cvss —epss 0.00
The BSD make program allows local users to modify files via a symlink attack when the -j option is being used.
- CVE-1999-0001Dec 30, 1999risk 0.00cvss —epss 0.03
ip_input.c in BSD-derived TCP/IP implementations allows remote attackers to cause a denial of service (crash or hang) via crafted packets.
- CVE-1999-1010Dec 14, 1999risk 0.00cvss —epss 0.01
An SSH 1.2.27 server allows a client to use the "none" cipher, even if it is not allowed by the server policy.
- CVE-1999-0724Aug 12, 1999risk 0.00cvss —epss 0.00
Buffer overflow in OpenBSD procfs and fdescfs file systems via uio_offset in the readdir() function.
- CVE-1999-0727Aug 6, 1999risk 0.00cvss —epss 0.01
A kernel leak in the OpenBSD kernel allows IPsec packets to be sent unencrypted.
- CVE-1999-0703Aug 3, 1999risk 0.00cvss —epss 0.00
OpenBSD, BSDI, and other Unix operating systems allow users to set chflags and fchflags on character and block devices.
- CVE-1999-0481Mar 22, 1999risk 0.00cvss —epss 0.01
Denial of service in "poll" in OpenBSD.
Page 7 of 8