Search: "openbsd"

165 CVEs found

CVE-2002-2188
4.9 MEDIUM

OpenBSD before 3.2 allows local users to cause a denial of service (kernel crash) via a call to getrlimit(2) with invalid arguments, possibly due to an integer signedness error.

Published: 2002-12-31
Products: 2
Vendors:
openbsd
CVE-2002-2222
5.1 MEDIUM

isakmpd/message.c in isakmpd in FreeBSD before isakmpd-20020403_1, and in OpenBSD 3.1, allows remote attackers to cause a denial of service (crash) by sending Internet Key Exchange (IKE) payloads out ...

Published: 2002-12-31
Products: 2
Vendors:
freebsd openbsd

syslogd on OpenBSD 2.9 through 3.2 does not change the source IP address of syslog packets when the machine's IP addressed is changed without rebooting, e.g. via ifconfig, which can cause incorrect in...

Published: 2002-12-31
Products: 4
Vendors:
openbsd

Buffer overflow in the lprm command in the lprold lpr package on SuSE 7.1 through 7.3, OpenBSD 3.2 and earlier, and possibly other operating systems, allows local users to gain root privileges via lon...

Published: 2003-03-31
Products: 22
Vendors:
bsd lprold freebsd openbsd

Integer signedness error in select() on OpenBSD 3.1 and earlier allows local users to overwrite arbitrary kernel memory via a negative value for the size parameter, which satisfies the boundary check ...

Published: 2003-04-11
Products: 2
Vendors:
openbsd
CVE-2003-0955
4.6 MEDIUM

OpenBSD kernel 3.3 and 3.4 allows local users to cause a denial of service (kernel panic) and possibly execute arbitrary code in 3.4 via a program with an invalid header that is not properly handled b...

Published: 2003-12-15
Products: 2
Vendors:
openbsd

chpass in OpenBSD 2.0 through 3.2 allows local users to read portions of arbitrary files via a hard link attack on a temporary file used to store user database information.

Published: 2003-12-31
Products: 13
Vendors:
openbsd
CVE-2003-1418
4.3 MEDIUM

Apache HTTP Server 1.3.22 through 1.3.27 on OpenBSD allows remote attackers to obtain sensitive information via (1) the ETag header, which reveals the inode number, or (2) multipart MIME boundary, whi...

Published: 2003-12-31
Products: 6
Vendors:
apache
CVE-2004-0114
4.6 MEDIUM

The shmat system call in the System V Shared Memory interface for FreeBSD 5.2 and earlier, NetBSD 1.3 and earlier, and OpenBSD 2.6 and earlier, does not properly decrement a shared memory segment's re...

Published: 2004-03-03
Products: 3
Vendors:
netbsd freebsd openbsd
CVE-2004-0218
5.0 MEDIUM

isakmpd in OpenBSD 3.4 and earlier allows remote attackers to cause a denial of service (infinite loop) via an ISAKMP packet with a zero-length payload, as demonstrated by the Striker ISAKMP Protocol ...

Published: 2004-05-04
Products: 1
Vendors:
openbsd
CVE-2004-0219
5.0 MEDIUM

isakmpd in OpenBSD 3.4 and earlier allows remote attackers to cause a denial of service (crash) via an ISAKMP packet with a malformed IPSEC SA payload, as demonstrated by the Striker ISAKMP Protocol T...

Published: 2004-05-04
Products: 1
Vendors:
openbsd
CVE-2004-0220
10.0 HIGH

isakmpd in OpenBSD 3.4 and earlier allows remote attackers to cause a denial of service via an ISAKMP packet with a malformed Cert Request payload, which causes an integer underflow that is used in a ...

Published: 2004-05-04
Products: 1
Vendors:
openbsd
CVE-2004-0221
5.0 MEDIUM

isakmpd in OpenBSD 3.4 and earlier allows remote attackers to cause a denial of service (crash) via an ISAKMP packet with a delete payload containing a large number of SPIs, which triggers an out-of-b...

Published: 2004-05-04
Products: 1
Vendors:
openbsd
CVE-2004-0222
5.0 MEDIUM

Multiple memory leaks in isakmpd in OpenBSD 3.4 and earlier allow remote attackers to cause a denial of service (memory exhaustion) via certain ISAKMP packets, as demonstrated by the Striker ISAKMP Pr...

Published: 2004-05-04
Products: 1
Vendors:
openbsd
CVE-2004-0482
4.6 MEDIUM

Multiple integer overflows in (1) procfs_cmdline.c, (2) procfs_fpregs.c, (3) procfs_linux.c, (4) procfs_regs.c, (5) procfs_status.c, and (6) procfs_subr.c in procfs for OpenBSD 3.5 and earlier allow l...

Published: 2004-07-07
Products: 2
Vendors:
openbsd
CVE-2004-0819
5.0 MEDIUM

The bridge functionality in OpenBSD 3.4 and 3.5, when running a gateway configured as a bridging firewall with the link2 option for IPSec enabled, allows remote attackers to cause a denial of service ...

Published: 2004-08-25
Products: 4
Vendors:
openbsd
CVE-2004-0257
5.0 MEDIUM

OpenBSD 3.4 and NetBSD 1.6 and 1.6.1 allow remote attackers to cause a denial of service (crash) by sending an IPv6 packet with a small MTU to a listening port and then issuing a TCP connect to that p...

Published: 2004-11-23
Products: 7
Vendors:
netbsd openbsd

PF in certain OpenBSD versions, when stateful filtering is enabled, does not limit packets for a session to the original interface, which allows remote attackers to bypass intended packet filters via ...

Published: 2004-12-31
Products: 5
Vendors:
openbsd

login_radius on OpenBSD 3.2, 3.5, and possibly other versions does not verify the shared secret in a response packet from a RADIUS server, which allows remote attackers to bypass authentication by spo...

Published: 2004-12-31
Products: 3
Vendors:
openbsd

Heap-based buffer overflow in isakmpd on OpenBSD 3.4 through 3.6 allows local users to cause a denial of service (panic) and corrupt memory via IPSEC credentials on a socket.

Published: 2004-12-31
Products: 3
Vendors:
openbsd