← Back

Netbsd

netbsd

172 CVEs • 5 products

Products (5)

Click to collapse
Toggle
Netbsd
netbsd
Ftpd
ftpd
Tnftpd
tnftpd
Netbsd Current
netbsd_current
Umapfs
umapfs

CVEs (172)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Freebsd
NetbsdOpenbsd
3Freebsd
NetbsdOpenbsd
Apr 16, 2026
Aug 17, 2001
N/A· v4
N/A· v3
6.2 MEDIUM· v2
fts routines in FreeBSD 4.3 and earlier, NetBSD before 1.5.2, and OpenBSD 2.9 and earlier can be forced to change (chdir) into a different directory than intended when the directory above the current directory is moved,...Show more
fts routines in FreeBSD 4.3 and earlier, NetBSD before 1.5.2, and OpenBSD 2.9 and earlier can be forced to change (chdir) into a different directory than intended when the directory above the current directory is moved, which could cause scripts to perform dangerous actions on the wrong directories.Show less
9Debian
FreebsdIbm+6 more
11Aix
Debian LinuxFreebsd+8 more
Apr 16, 2026
Aug 14, 2001
N/A· v4
N/A· v3
10.0 HIGH· v2
Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a set of options including AYT (Are You There), which is not properly handled by t...Show more
Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a set of options including AYT (Are You There), which is not properly handled by the telrcv function.Show less
1Netbsd
1Netbsd
Apr 16, 2026
Jul 24, 2001
N/A· v4
N/A· v3
2.1 LOW· v2
sendmsg function in NetBSD 1.3 through 1.5 allows local users to cause a denial of service (kernel trap or panic) via a msghdr structure with a large msg_controllen length.
7Freebsd
HpLinux+4 more
9Freebsd
Hp UxLinux Kernel+6 more
Apr 16, 2026
Jul 7, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Multiple TCP implementations could allow remote attackers to cause a denial of service (bandwidth and CPU exhaustion) by setting the maximum segment size (MSS) to a very small number and requesting large amounts of data,...Show more
Multiple TCP implementations could allow remote attackers to cause a denial of service (bandwidth and CPU exhaustion) by setting the maximum segment size (MSS) to a very small number and requesting large amounts of data, which generates more packets with less TCP-level data that amplify network traffic and consume more server CPU to process.Show less
5Freebsd
MitNetbsd+2 more
5Freebsd
IrixKerberos 5+2 more
Apr 16, 2026
Jun 18, 2001
N/A· v4
N/A· v3
10.0 HIGH· v2
Buffer overflows in BSD-based FTP servers allows remote attackers to execute arbitrary commands via a long pattern string containing a {} sequence, as seen in (1) g_opendir, (2) g_lstat, (3) g_stat, and (4) the glob0 buf...Show more
Buffer overflows in BSD-based FTP servers allows remote attackers to execute arbitrary commands via a long pattern string containing a {} sequence, as seen in (1) g_opendir, (2) g_lstat, (3) g_stat, and (4) the glob0 buffer as used in the glob functions glob2 and glob3.Show less
2Netbsd
Openbsd
2Netbsd
Openbsd
Apr 16, 2026
May 3, 2001
N/A· v4
N/A· v3
7.2 HIGH· v2
The i386_set_ldt system call in NetBSD 1.5 and earlier, and OpenBSD 2.8 and earlier, when the USER_LDT kernel option is enabled, does not validate a call gate target, which allows local users to gain root privileges by c...Show more
The i386_set_ldt system call in NetBSD 1.5 and earlier, and OpenBSD 2.8 and earlier, when the USER_LDT kernel option is enabled, does not validate a call gate target, which allows local users to gain root privileges by creating a segment call gate in the Local Descriptor Table (LDT) with a target that specifies an arbitrary kernel address.Show less
5Debian
DigitalNetbsd+2 more
5Debian Linux
LinuxNetbsd+2 more
Apr 16, 2026
Mar 12, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
traceroute in NetBSD 1.3.3 and Linux systems allows local unprivileged users to modify the source address of the packets, which could be used in spoofing attacks.
5Debian
DigitalNetbsd+2 more
5Debian Linux
LinuxNetbsd+2 more
Apr 16, 2026
Mar 12, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
traceroute in NetBSD 1.3.3 and Linux systems allows local users to flood other systems by providing traceroute with a large waittime (-w) option, which is not parsed properly and sets the time delay for sending packets t...Show more
traceroute in NetBSD 1.3.3 and Linux systems allows local users to flood other systems by providing traceroute with a large waittime (-w) option, which is not parsed properly and sets the time delay for sending packets to zero.Show less
2Kth
Netbsd
2Kth Kerberos
Netbsd
Apr 16, 2026
Feb 16, 2001
N/A· v4
N/A· v3
7.2 HIGH· v2
KTH Kerberos IV allows local users to change the configuration of a Kerberos server running at an elevated privilege by specifying an alternate directory using with the KRBCONFDIR environmental variable, which allows the...Show more
KTH Kerberos IV allows local users to change the configuration of a Kerberos server running at an elevated privilege by specifying an alternate directory using with the KRBCONFDIR environmental variable, which allows the user to gain additional privileges.Show less
3David Madore
NetbsdOpenbsd
3Ftpd Bsd
NetbsdOpenbsd
Apr 16, 2026
Feb 12, 2001
N/A· v4
N/A· v3
10.0 HIGH· v2
One-byte buffer overflow in replydirname function in BSD-based ftpd allows remote attackers to gain root privileges.
2Netbsd
Openbsd
2Netbsd
Openbsd
Apr 16, 2026
Dec 19, 2000
N/A· v4
N/A· v3
7.2 HIGH· v2
Format string vulnerabilities in eeprom program in OpenBSD, NetBSD, and possibly other operating systems allows local attackers to gain root privileges.
3Freebsd
NetbsdOpenbsd
3Freebsd
NetbsdOpenbsd
Apr 16, 2026
Dec 19, 2000
N/A· v4
N/A· v3
7.2 HIGH· v2
Format string vulnerability in pw_error function in BSD libutil library allows local users to gain root privileges via a malformed password in commands such as chpass or passwd.
3Netbsd
OpenbsdRedhat
3Linux
NetbsdOpenbsd
Apr 16, 2026
Oct 20, 2000
N/A· v4
N/A· v3
7.5 HIGH· v2
mopd (Maintenance Operations Protocol loader daemon) does not properly cleanse user-injected format strings, which allows remote attackers to execute arbitrary commands.
3Netbsd
OpenbsdRedhat
3Linux
NetbsdOpenbsd
Apr 16, 2026
Oct 20, 2000
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in mopd (Maintenance Operations Protocol loader daemon) allows remote attackers to execute arbitrary commands via a long file name.
2Freebsd
Netbsd
2Freebsd
Netbsd
Apr 16, 2026
May 29, 2000
N/A· v4
N/A· v3
2.1 LOW· v2
The undocumented semconfig system call in BSD freezes the state of semaphores, which allows local users to cause a denial of service of the semaphore system by using the semconfig call.
1Netbsd
1Netbsd
Apr 16, 2026
May 28, 2000
N/A· v4
N/A· v3
2.1 LOW· v2
ftpd in NetBSD 1.4.2 does not properly parse entries in /etc/ftpchroot and does not chroot the specified users, which allows those users to access other files outside of their home directory.
1Netbsd
1Netbsd
Apr 16, 2026
May 28, 2000
N/A· v4
N/A· v3
2.1 LOW· v2
NetBSD 1.4.2 and earlier allows local users to cause a denial of service by repeatedly running certain system calls in the kernel which do not yield the CPU, aka "cpu-hog".
2Freebsd
Netbsd
2Freebsd
Netbsd
Apr 16, 2026
May 1, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
NetBSD 1.4.2 and earlier allows remote attackers to cause a denial of service by sending a packet with an unaligned IP timestamp option.
1Netbsd
1Netbsd
Apr 16, 2026
Feb 16, 2000
N/A· v4
N/A· v3
7.2 HIGH· v2
procfs in BSD systems allows local users to gain root privileges by modifying the /proc/pid/mem interface via a modified file descriptor for stderr.
1Netbsd
1Netbsd
Apr 16, 2026
Feb 1, 2000
N/A· v4
N/A· v3
7.2 HIGH· v2
NetBSD ptrace call on VAX allows local users to gain privileges by modifying the PSL contents in the debugging process.