← Back

Netbsd

netbsd

172 CVEs • 5 products

Products (5)

Click to collapse
Toggle
Netbsd
netbsd
Ftpd
ftpd
Tnftpd
tnftpd
Netbsd Current
netbsd_current
Umapfs
umapfs

CVEs (172)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Freebsd
Netbsd
2Freebsd
Netbsd
Apr 23, 2026
Nov 29, 2006
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
ld.so in FreeBSD, NetBSD, and possibly other BSD distributions does not remove certain harmful environment variables, which allows local users to gain privileges by passing certain environment variables to loading proces...Show more
ld.so in FreeBSD, NetBSD, and possibly other BSD distributions does not remove certain harmful environment variables, which allows local users to gain privileges by passing certain environment variables to loading processes. NOTE: this issue has been disputed by a third party, stating that it is the responsibility of the application to properly sanitize the environmentShow less
1Netbsd
1Netbsd
Apr 23, 2026
Nov 21, 2006
N/A· v4
N/A· v3
7.2 HIGH· v2
The NetBSD-current kernel before 20061028 does not properly perform bounds checking of an unspecified userspace parameter in the ptrace system call during a PT_DUMPCORE request, which allows local users to have an unknow...Show more
The NetBSD-current kernel before 20061028 does not properly perform bounds checking of an unspecified userspace parameter in the ptrace system call during a PT_DUMPCORE request, which allows local users to have an unknown impact.Show less
5Dragonflybsd
FreebsdMidnightbsd+2 more
5Dragonflybsd
FreebsdMidnightbsd+2 more
Apr 23, 2026
Nov 21, 2006
N/A· v4
N/A· v3
2.1 LOW· v2
Integer signedness error in the fw_ioctl (FW_IOCTL) function in the FireWire (IEEE-1394) drivers (dev/firewire/fwdev.c) in various BSD kernels, including DragonFlyBSD, FreeBSD 5.5, MidnightBSD 0.1-CURRENT before 20061115...Show more
Integer signedness error in the fw_ioctl (FW_IOCTL) function in the FireWire (IEEE-1394) drivers (dev/firewire/fwdev.c) in various BSD kernels, including DragonFlyBSD, FreeBSD 5.5, MidnightBSD 0.1-CURRENT before 20061115, NetBSD-current before 20061116, NetBSD-4 before 20061203, and TrustedBSD, allows local users to read arbitrary memory contents via certain negative values of crom_buf->len in an FW_GCROM command. NOTE: this issue has been labeled as an integer overflow, but it is more like an integer signedness error.Show less
2Netbsd
Openbsd
2Netbsd
Openbsd
Apr 23, 2026
Oct 10, 2006
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Integer overflow in the systrace_preprepl function (STRIOCREPLACE) in systrace in OpenBSD 3.9 and NetBSD 3 allows local users to cause a denial of service (crash), gain privileges, or read arbitrary kernel memory via lar...Show more
Integer overflow in the systrace_preprepl function (STRIOCREPLACE) in systrace in OpenBSD 3.9 and NetBSD 3 allows local users to cause a denial of service (crash), gain privileges, or read arbitrary kernel memory via large numeric arguments to the systrace ioctl.Show less
3Netbsd
SunX.org
4Netbsd
SolarisSunos+1 more
Apr 23, 2026
Oct 10, 2006
N/A· v4
N/A· v3
2.6 LOW· v2
The Xsession script, as used by X Display Manager (xdm) in NetBSD before 20060212, X.Org before 20060317, and Solaris 8 through 10 before 20061006, allows local users to overwrite arbitrary files, or read another user's...Show more
The Xsession script, as used by X Display Manager (xdm) in NetBSD before 20060212, X.Org before 20060317, and Solaris 8 through 10 before 20061006, allows local users to overwrite arbitrary files, or read another user's Xsession errors file, via a symlink attack on a /tmp/xses-$USER file.Show less
2Netbsd
Sun
3Netbsd
SolarisSunos
Apr 23, 2026
Oct 10, 2006
N/A· v4
N/A· v3
1.2 LOW· v2
Race condition in the Xsession script, as used by X Display Manager (xdm) in NetBSD before 20060212, X.Org before 20060225, and Solaris 8 through 10 before 20061006, causes a user's Xsession errors file to have weak perm...Show more
Race condition in the Xsession script, as used by X Display Manager (xdm) in NetBSD before 20060212, X.Org before 20060225, and Solaris 8 through 10 before 20061006, causes a user's Xsession errors file to have weak permissions before a chmod is performed, which allows local users to read Xsession errors files of other users.Show less
3Freebsd
NetbsdOpenbsd
3Freebsd
NetbsdOpenbsd
Apr 16, 2026
Aug 24, 2006
N/A· v4
N/A· v3
10.0 HIGH· v2
Buffer overflow in the sppp driver in FreeBSD 4.11 through 6.1, NetBSD 2.0 through 4.0 beta before 20060823, and OpenBSD 3.8 and 3.9 before 20060902 allows remote attackers to cause a denial of service (panic), obtain se...Show more
Buffer overflow in the sppp driver in FreeBSD 4.11 through 6.1, NetBSD 2.0 through 4.0 beta before 20060823, and OpenBSD 3.8 and 3.9 before 20060902 allows remote attackers to cause a denial of service (panic), obtain sensitive information, and possibly execute arbitrary code via crafted Link Control Protocol (LCP) packets with an option length that exceeds the overall length, which triggers the overflow in (1) pppoe and (2) ippp. NOTE: this issue was originally incorrectly reported for the ppp driver.Show less
1Netbsd
1Netbsd
Apr 16, 2026
Jun 23, 2006
N/A· v4
N/A· v3
4.9 MEDIUM· v2
The ip6_savecontrol function in NetBSD 2.0 through 3.0, under certain configurations, does not check to see if IPv4-mapped sockets are being used before processing IPv6 socket options, which allows local users to cause a...Show more
The ip6_savecontrol function in NetBSD 2.0 through 3.0, under certain configurations, does not check to see if IPv4-mapped sockets are being used before processing IPv6 socket options, which allows local users to cause a denial of service (crash) by creating an IPv4-mapped IPv6 socket with the SO_TIMESTAMP socket option set, then sending an IPv4 packet through the socket.Show less
1Netbsd
1Netbsd
Apr 16, 2026
May 5, 2006
N/A· v4
N/A· v3
2.1 LOW· v2
The audio_write function in NetBSD 3.0 allows local users to cause a denial of service (kernel crash) by using the audiosetinfo ioctl to change the sample rate of an audio device.
1Netbsd
1Netbsd
Apr 16, 2026
Apr 19, 2006
N/A· v4
N/A· v3
2.6 LOW· v2
Intel RNG Driver in NetBSD 1.6 through 3.0 may incorrectly detect the presence of the pchb interface, which will cause it to always generate the same random number, which allows remote attackers to more easily crack encr...Show more
Intel RNG Driver in NetBSD 1.6 through 3.0 may incorrectly detect the presence of the pchb interface, which will cause it to always generate the same random number, which allows remote attackers to more easily crack encryption keys generated from the interface.Show less
1Netbsd
1Netbsd
Apr 16, 2026
Apr 18, 2006
N/A· v4
N/A· v3
2.1 LOW· v2
NetBSD 1.6, 2.0, 2.1 and 3.0 allows local users to cause a denial of service (memory exhaustion) by using the sysctl system call to lock a large buffer into physical memory.
1Netbsd
1Netbsd
Apr 16, 2026
Apr 18, 2006
N/A· v4
N/A· v3
4.9 MEDIUM· v2
The kernel in NetBSD-current before September 28, 2005 allows local users to cause a denial of service (system crash) by using the SIOCGIFALIAS ioctl to gather information on a non-existent alias of a network interface,...Show more
The kernel in NetBSD-current before September 28, 2005 allows local users to cause a denial of service (system crash) by using the SIOCGIFALIAS ioctl to gather information on a non-existent alias of a network interface, which causes a NULL pointer dereference.Show less
1Netbsd
1Netbsd
Apr 16, 2026
Apr 3, 2006
N/A· v4
N/A· v3
4.9 MEDIUM· v2
The elf_load_file function in NetBSD 2.0 through 3.0 allows local users to cause a denial of service (kernel crash) via an ELF interpreter that does not have a PT_LOAD section in its header, which triggers a null derefer...Show more
The elf_load_file function in NetBSD 2.0 through 3.0 allows local users to cause a denial of service (kernel crash) via an ELF interpreter that does not have a PT_LOAD section in its header, which triggers a null dereference.Show less
1Netbsd
1Netbsd
Apr 16, 2026
Apr 3, 2006
N/A· v4
N/A· v3
2.1 LOW· v2
The bridge ioctl (if_bridge code) in NetBSD 1.6 through 3.0 does not clear sensitive memory before copying ioctl results to the requesting process, which allows local users to obtain portions of kernel memory.
1Netbsd
1Netbsd
Apr 16, 2026
Apr 3, 2006
N/A· v4
N/A· v3
2.1 LOW· v2
NetBSD 1.6 up to 3.0, when a user has "set record" in .mailrc with the default umask set, creates the record file with 0644 permissions, which allows local users to read the record file.
2Freebsd
Netbsd
2Freebsd
Netbsd
Apr 16, 2026
Mar 23, 2006
N/A· v4
N/A· v3
7.5 HIGH· v2
A "programming error" in fast_ipsec in FreeBSD 4.8-RELEASE through 6.1-STABLE and NetBSD 2 through 3 does not properly update the sequence number associated with a Security Association, which allows packets to pass seque...Show more
A "programming error" in fast_ipsec in FreeBSD 4.8-RELEASE through 6.1-STABLE and NetBSD 2 through 3 does not properly update the sequence number associated with a Security Association, which allows packets to pass sequence number checks and allows remote attackers to capture IPSec packets and conduct replay attacks.Show less
1Netbsd
1Netbsd
Apr 16, 2026
Jan 9, 2006
N/A· v4
N/A· v3
4.6 MEDIUM· v2
The kernfs_xread function in kernfs in NetBSD 1.6 through 2.1, and OpenBSD 3.8, does not properly validate file offsets against negative 32-bit values that occur as a result of truncation, which allows local users to rea...Show more
The kernfs_xread function in kernfs in NetBSD 1.6 through 2.1, and OpenBSD 3.8, does not properly validate file offsets against negative 32-bit values that occur as a result of truncation, which allows local users to read arbitrary kernel memory and gain privileges via the lseek system call.Show less
1Netbsd
1Netbsd
Apr 16, 2026
Dec 31, 2005
N/A· v4
N/A· v3
2.1 LOW· v2
kernfs_xread in kernfs_vnops.c in NetBSD before 20050831 does not check for a negative offset when reading the message buffer, which allows local users to read arbitrary kernel memory.
1Netbsd
1Netbsd
Apr 16, 2026
Dec 31, 2005
N/A· v4
N/A· v3
4.9 MEDIUM· v2
NetBSD 2.0 before 2.0.4, 2.1 before 2.1.1, and 3, when the kernel is compiled with "options DIAGNOSTIC," allows local users to cause a denial of service (kernel assertion panic) via a negative linger time in the SO_LINGE...Show more
NetBSD 2.0 before 2.0.4, 2.1 before 2.1.1, and 3, when the kernel is compiled with "options DIAGNOSTIC," allows local users to cause a denial of service (kernel assertion panic) via a negative linger time in the SO_LINGER socket option.Show less
1Netbsd
1Netbsd
Apr 16, 2026
Dec 31, 2005
N/A· v4
N/A· v3
3.6 LOW· v2
verifiedexecioctl in verified_exec.c in NetBSD 2.0.2 calls NDINIT with UIO_USERSPACE rather than UID_SYSSPACE, which removes the functionality of the verified exec kernel subsystem and might allow local users to execute...Show more
verifiedexecioctl in verified_exec.c in NetBSD 2.0.2 calls NDINIT with UIO_USERSPACE rather than UID_SYSSPACE, which removes the functionality of the verified exec kernel subsystem and might allow local users to execute Trojan horse programs.Show less