Skip to main content

Vendor archive

openbsd CVEs

Beta · best-effort

343 CVEs tagged to vendor openbsd42 Critical, 111 High, 161 Medium, 29 Low, 0 Unrated.

CVE-2004-0482

Published Jul 7, 2004

Multiple integer overflows in (1) procfs_cmdline.c, (2) procfs_fpregs.c, (3) procfs_linux.c, (4) procfs_regs.c, (5) procfs_status.c, and (6) procfs_subr.c in procfs for OpenBSD 3.…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0218

Published May 4, 2004

isakmpd in OpenBSD 3.4 and earlier allows remote attackers to cause a denial of service (infinite loop) via an ISAKMP packet with a zero-length payload, as demonstrated by the Str…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0219

Published May 4, 2004

isakmpd in OpenBSD 3.4 and earlier allows remote attackers to cause a denial of service (crash) via an ISAKMP packet with a malformed IPSEC SA payload, as demonstrated by the Stri…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0220

Published May 4, 2004

isakmpd in OpenBSD 3.4 and earlier allows remote attackers to cause a denial of service via an ISAKMP packet with a malformed Cert Request payload, which causes an integer underfl…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-0221

Published May 4, 2004

isakmpd in OpenBSD 3.4 and earlier allows remote attackers to cause a denial of service (crash) via an ISAKMP packet with a delete payload containing a large number of SPIs, which…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0222

Published May 4, 2004

Multiple memory leaks in isakmpd in OpenBSD 3.4 and earlier allow remote attackers to cause a denial of service (memory exhaustion) via certain ISAKMP packets, as demonstrated by…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0171

Published Mar 15, 2004

FreeBSD 5.1 and earlier, and Mac OS X before 10.3.4, allows remote attackers to cause a denial of service (resource exhaustion of memory buffers and system crash) via a large numb…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0083

Published Mar 3, 2004

Buffer overflow in ReadFontAlias from dirfile.c of XFree86 4.1.0 through 4.3.0 allows local users and remote attackers to execute arbitrary code via a font alias file (font.alias)…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-0084

Published Mar 3, 2004

Buffer overflow in the ReadFontAlias function in XFree86 4.1.0 to 4.3.0, when using the CopyISOLatin1Lowered function, allows local or remote authenticated users to execute arbitr…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-0106

Published Mar 3, 2004

Multiple unknown vulnerabilities in XFree86 4.1.0 to 4.3.0, related to improper handling of font files, a different set of vulnerabilities than CVE-2004-0083 and CVE-2004-0084.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2004-0114

Published Mar 3, 2004

The shmat system call in the System V Shared Memory interface for FreeBSD 5.2 and earlier, NetBSD 1.3 and earlier, and OpenBSD 2.6 and earlier, does not properly decrement a share…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1082

Published Feb 3, 2004

mod_digest_apple for Apache 1.3.31 and 1.3.32 on Mac OS X Server does not properly verify the nonce of a client response, which allows remote attackers to replay credentials.

CVSS 7.5 · High

CVE-2003-1366

Published Dec 31, 2003

chpass in OpenBSD 2.0 through 3.2 allows local users to read portions of arbitrary files via a hard link attack on a temporary file used to store user database information.

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2003-1562

Published Dec 31, 2003

sshd in OpenSSH 3.6.1p2 and earlier, when PermitRootLogin is disabled and using PAM keyboard-interactive authentication, does not insert a delay after a root login attempt with th…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0955

Published Dec 15, 2003

OpenBSD kernel 3.3 and 3.4 allows local users to cause a denial of service (kernel panic) and possibly execute arbitrary code in 3.4 via a program with an invalid header that is n…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0786

Published Nov 17, 2003

The SSH1 PAM challenge response authentication in OpenSSH 3.7.1 and 3.7.1p1, when Privilege Separation is disabled, does not check the result of the authentication attempt, which…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2003-0787

Published Nov 17, 2003

The PAM conversation function in OpenSSH 3.7.1 and 3.7.1p1 interprets an array of structures as an array of pointers, which allows attackers to modify the stack and possibly gain…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0681

Published Oct 6, 2003

A "potential buffer overflow in ruleset parsing" for Sendmail 8.12.9, when using the nonstandard rulesets (1) recipient (2), final, or (3) mailer-specific envelope recipients, has…

CVSS 7.5 · High

CVE-2003-0682

Published Oct 6, 2003

"Memory bugs" in OpenSSH 3.7.1 and earlier, with unknown impact, a different set of vulnerabilities than CVE-2003-0693 and CVE-2003-0695.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0695

Published Oct 6, 2003

Multiple "buffer management errors" in OpenSSH before 3.7.1 may allow attackers to cause a denial of service or execute arbitrary code using (1) buffer_init in buffer.c, (2) buffe…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0693

Published Sep 22, 2003

A "buffer management error" in buffer_append_space of buffer.c for OpenSSH before 3.7 may allow remote attackers to execute arbitrary code by causing an incorrect amount of memory…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 226-250 of 343 CVEsPage 10 of 14