← Back

Openbsd

openbsd

Vendor: Openbsd • 201 CVEs

CVEs (201)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Openbsd
1Openbsd
Apr 16, 2026
May 3, 2001
N/A· v4
N/A· v3
10.0 HIGH· v2
Buffer overflow in IPSEC authentication mechanism for OpenBSD 2.8 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a malformed Authentication header (AH) IPv4 o...Show more
Buffer overflow in IPSEC authentication mechanism for OpenBSD 2.8 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a malformed Authentication header (AH) IPv4 option.Show less
2Netbsd
Openbsd
2Netbsd
Openbsd
Apr 16, 2026
May 3, 2001
N/A· v4
N/A· v3
7.2 HIGH· v2
The i386_set_ldt system call in NetBSD 1.5 and earlier, and OpenBSD 2.8 and earlier, when the USER_LDT kernel option is enabled, does not validate a call gate target, which allows local users to gain root privileges by c...Show more
The i386_set_ldt system call in NetBSD 1.5 and earlier, and OpenBSD 2.8 and earlier, when the USER_LDT kernel option is enabled, does not validate a call gate target, which allows local users to gain root privileges by creating a segment call gate in the Local Descriptor Table (LDT) with a target that specifies an arbitrary kernel address.Show less
1Openbsd
1Openbsd
Apr 16, 2026
Mar 12, 2001
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Vulnerability in OpenBSD 2.6 allows a local user to change interface media configurations.
1Openbsd
1Openbsd
Apr 16, 2026
Mar 12, 2001
N/A· v4
N/A· v3
7.2 HIGH· v2
cron in OpenBSD 2.5 allows local users to gain root privileges via an argv[] that is not NULL terminated, which is passed to cron's fake popen function.
1Openbsd
1Openbsd
Apr 16, 2026
Mar 12, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
IP fragment assembly in OpenBSD 2.4 allows a remote attacker to cause a denial of service by sending a large number of fragmented packets.
1Openbsd
1Openbsd
Apr 16, 2026
Mar 12, 2001
N/A· v4
N/A· v3
2.1 LOW· v2
The i386 trace-trap handling in OpenBSD 2.4 with DDB enabled allows a local user to cause a denial of service.
3David Madore
NetbsdOpenbsd
3Ftpd Bsd
NetbsdOpenbsd
Apr 16, 2026
Feb 12, 2001
N/A· v4
N/A· v3
10.0 HIGH· v2
One-byte buffer overflow in replydirname function in BSD-based ftpd allows remote attackers to gain root privileges.
2Netbsd
Openbsd
2Netbsd
Openbsd
Apr 16, 2026
Dec 19, 2000
N/A· v4
N/A· v3
7.2 HIGH· v2
Format string vulnerabilities in eeprom program in OpenBSD, NetBSD, and possibly other operating systems allows local attackers to gain root privileges.
1Openbsd
1Openbsd
Apr 16, 2026
Dec 19, 2000
N/A· v4
N/A· v3
7.2 HIGH· v2
Format string vulnerability in OpenBSD su program (and possibly other BSD-based operating systems) allows local attackers to gain root privileges via a malformed shell.
1Openbsd
1Openbsd
Apr 16, 2026
Dec 19, 2000
N/A· v4
N/A· v3
7.2 HIGH· v2
Format string vulnerability in OpenBSD yp_passwd program (and possibly other BSD-based operating systems) allows attackers to gain root privileges a malformed name.
1Openbsd
1Openbsd
Apr 16, 2026
Dec 19, 2000
N/A· v4
N/A· v3
7.2 HIGH· v2
Format string vulnerability in OpenBSD fstat program (and possibly other BSD-based operating systems) allows local users to gain root privileges via the PWD environmental variable.
3Freebsd
NetbsdOpenbsd
3Freebsd
NetbsdOpenbsd
Apr 16, 2026
Dec 19, 2000
N/A· v4
N/A· v3
7.2 HIGH· v2
Format string vulnerability in pw_error function in BSD libutil library allows local users to gain root privileges via a malformed password in commands such as chpass or passwd.
1Openbsd
1Openbsd
Apr 16, 2026
Dec 19, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The IPSEC implementation in OpenBSD 2.7 does not properly handle empty AH/ESP packets, which allows remote attackers to cause a denial of service.
1Openbsd
1Openbsd
Apr 16, 2026
Dec 19, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
OpenBSD 2.6 and earlier allows remote attackers to cause a denial of service by flooding the server with ARP requests.
2Openbsd
Redhat
2Linux
Openbsd
Apr 16, 2026
Dec 11, 2000
N/A· v4
N/A· v3
10.0 HIGH· v2
Format string vulnerability in talkd in OpenBSD and possibly other BSD-based OSes allows remote attackers to execute arbitrary commands via a user name that contains format characters.
1Openbsd
1Openbsd
Apr 16, 2026
Dec 11, 2000
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Format string vulnerability in OpenBSD photurisd allows local users to execute arbitrary commands via a configuration file directory name that contains formatting characters.
3Netbsd
OpenbsdRedhat
3Linux
NetbsdOpenbsd
Apr 16, 2026
Oct 20, 2000
N/A· v4
N/A· v3
7.5 HIGH· v2
mopd (Maintenance Operations Protocol loader daemon) does not properly cleanse user-injected format strings, which allows remote attackers to execute arbitrary commands.
3Netbsd
OpenbsdRedhat
3Linux
NetbsdOpenbsd
Apr 16, 2026
Oct 20, 2000
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in mopd (Maintenance Operations Protocol loader daemon) allows remote attackers to execute arbitrary commands via a long file name.
3Freebsd
NetbsdOpenbsd
3Freebsd
NetbsdOpenbsd
Apr 16, 2026
Jan 19, 2000
N/A· v4
N/A· v3
6.2 MEDIUM· v2
The BSD make program allows local users to modify files via a symlink attack when the -j option is being used.
3Bsdi
FreebsdOpenbsd
3Bsd Os
FreebsdOpenbsd
Apr 16, 2026
Dec 30, 1999
N/A· v4
N/A· v3
5.0 MEDIUM· v2
ip_input.c in BSD-derived TCP/IP implementations allows remote attackers to cause a denial of service (crash or hang) via crafted packets.