Openbsd
openbsd
347 CVEs • 7 products
Products (7)
Click to collapseToggle
Products (7)
Click to collapse
CVEs (347)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Multiple "buffer management errors" in OpenSSH before 3.7.1 may allow attackers to cause a denial of service or execute arbitrary code using (1) buffer_init in buffer.c, (2) buffer_free in buffer.c, or (3) a separate fun...Show more |
"Memory bugs" in OpenSSH 3.7.1 and earlier, with unknown impact, a different set of vulnerabilities than CVE-2003-0693 and CVE-2003-0695. |
8Apple GentooHp+5 more14Advanced Message Server AixHp Ux+11 moreApr 16, 2026 Oct 6, 2003 N/A· v4 N/A· v3 7.5 HIGH· v2 A "potential buffer overflow in ruleset parsing" for Sendmail 8.12.9, when using the nonstandard rulesets (1) recipient (2), final, or (3) mailer-specific envelope recipients, has unknown consequences. |
A "buffer management error" in buffer_append_space of buffer.c for OpenSSH before 3.7 may allow remote attackers to execute arbitrary code by causing an incorrect amount of memory to be freed and corrupting the heap, a d...Show more |
7Apple FreebsdNetbsd+4 more8Freebsd Mac Os XMac Os X Server+5 moreApr 16, 2026 Aug 27, 2003 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code, as demonstrated in wu-ftpd 2.5.0 through 2.6.2 via commands that cause pathname...Show more |
OpenSSH 3.6.1 and earlier, when restricting host access by numeric IP addresses and with VerifyReverseMapping disabled, allows remote attackers to bypass "from=" and "user@host" address restrictions by connecting to a ho...Show more |
3Openbsd OpenpkgSiemens4Openpkg OpensshScalance X204rna Ecc Firmware+1 moreApr 16, 2026 May 12, 2003 N/A· v4 N/A· v3 5.0 MEDIUM· v2 OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user does not exist, which allows remote attackers to determine valid usernames via a timing attack. |
Integer signedness error in select() on OpenBSD 3.1 and earlier allows local users to overwrite arbitrary kernel memory via a negative value for the size parameter, which satisfies the boundary check as a signed integer,...Show more |
4Bsd FreebsdLprold+1 more4Freebsd LprLprold+1 moreApr 16, 2026 Mar 31, 2003 N/A· v4 N/A· v3 7.2 HIGH· v2 Buffer overflow in the lprm command in the lprold lpr package on SuSE 7.1 through 7.3, OpenBSD 3.2 and earlier, and possibly other operating systems, allows local users to gain root privileges via long command line argum...Show more |
10Cray FreebsdGnu+7 more13Aix FreebsdGlibc+10 moreApr 16, 2026 Mar 25, 2003 N/A· v4 N/A· v3 7.5 HIGH· v2 Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers...Show more |
3Freebsd OpenbsdOpenssl3Freebsd OpenbsdOpensslApr 16, 2026 Mar 3, 2003 N/A· v4 N/A· v3 5.0 MEDIUM· v2 ssl3_get_record in s3_pkt.c for OpenSSL before 0.9.7a and 0.9.6 before 0.9.6i does not perform a MAC computation if an incorrect block cipher padding is used, which causes an information leak (timing discrepancy) that ma...Show more |
syslogd on OpenBSD 2.9 through 3.2 does not change the source IP address of syslog packets when the machine's IP addressed is changed without rebooting, e.g. via ifconfig, which can cause incorrect information to be sent...Show more |
2Freebsd Openbsd2Openbsd Ports CollectionApr 16, 2026 Dec 31, 2002 N/A· v4 N/A· v3 5.1 MEDIUM· v2 isakmpd/message.c in isakmpd in FreeBSD before isakmpd-20020403_1, and in OpenBSD 3.1, allows remote attackers to cause a denial of service (crash) by sending Internet Key Exchange (IKE) payloads out of sequence. |
OpenBSD before 3.2 allows local users to cause a denial of service (kernel crash) via a call to getrlimit(2) with invalid arguments, possibly due to an integer signedness error. |
The setitimer(2) system call in OpenBSD 2.0 through 3.1 does not properly check certain arguments, which allows local users to write to kernel memory and possibly gain root privileges, possibly via an integer signedness...Show more |
3Freebsd NetbsdOpenbsd3Freebsd NetbsdOpenbsdApr 16, 2026 Dec 31, 2002 N/A· v4 N/A· v3 3.7 LOW· v2 Race condition in exec in OpenBSD 4.0 and earlier, NetBSD 1.5.2 and earlier, and FreeBSD 4.4 and earlier allows local users to gain privileges by attaching a debugger to a process before the kernel has determined that th...Show more |
3Freebsd NetbsdOpenbsd3Freebsd NetbsdOpenbsdApr 16, 2026 Dec 31, 2002 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 tip on multiple BSD-based operating systems allows local users to cause a denial of service (execution prevention) by using flock() to lock the /var/log/acculog file. |
3Ncftp Software OpenbsdSun4Ncftp OpenbsdSolaris+1 moreApr 16, 2026 Dec 23, 2002 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Directory traversal vulnerabilities in multiple FTP clients on UNIX systems allow remote malicious FTP servers to create or overwrite files as the client user via filenames containing /absolute/path or .. (dot dot) seque...Show more |
3Freebsd IscOpenbsd3Bind FreebsdOpenbsdApr 16, 2026 Nov 29, 2002 N/A· v4 N/A· v3 5.0 MEDIUM· v2 BIND 8.x through 8.3.3 allows remote attackers to cause a denial of service (crash) via SIG RR elements with invalid expiry times, which are removed from the internal BIND database and later cause a null dereference. |
3Freebsd IscOpenbsd3Bind FreebsdOpenbsdApr 16, 2026 Nov 29, 2002 N/A· v4 N/A· v3 5.0 MEDIUM· v2 BIND 8.3.x through 8.3.3 allows remote attackers to cause a denial of service (termination due to assertion failure) via a request for a subdomain that does not exist, with an OPT resource record with a large UDP payload...Show more |