← Back

Openbsd

openbsd

347 CVEs • 7 products

Products (7)

Click to collapse
Toggle
Openbsd
openbsd
Openssh
openssh
Libressl
libressl
Opensmtpd
opensmtpd
Ftpd
ftpd
Linux
linux

CVEs (347)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Openbsd
1Openbsd
Jun 17, 2026
Jul 28, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
iked in OpenIKED, as used in OpenBSD through 6.7, allows authentication bypass because ca.c has the wrong logic for checking whether a public key matches.
3Broadcom
NetappOpenbsd
9A700s Firmware
Active Iq Unified ManagerFabric Operating System+6 more
Jun 17, 2026
Jul 24, 2020
N/A· v4
7.4 HIGH· v3
6.8 MEDIUM· v2
scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that they intentionally omi...Show more
scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that they intentionally omit validation of "anomalous argument transfers" because that could "stand a great chance of breaking existing workflows."Show less
2Netapp
Openbsd
9Active Iq Unified Manager
Aff A700s FirmwareHci Compute Node+6 more
Jun 17, 2026
Jun 29, 2020
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The client side in OpenSSH 5.7 through 8.4 has an Observable Discrepancy leading to an information leak in the algorithm negotiation. This allows man-in-the-middle attackers to target initial connection attempts (where n...Show more
The client side in OpenSSH 5.7 through 8.4 has an Observable Discrepancy leading to an information leak in the algorithm negotiation. This allows man-in-the-middle attackers to target initial connection attempts (where no host key for the server has been cached by the client). NOTE: some reports state that 8.5 and 8.6 are also affected.Show less
1Openbsd
1Openssh
Jun 17, 2026
Jun 1, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The scp client in OpenSSH 8.2 incorrectly sends duplicate responses to the server upon a utimes system call failure, which allows a malicious unprivileged user on the remote server to overwrite arbitrary files in the cli...Show more
The scp client in OpenSSH 8.2 incorrectly sends duplicate responses to the server upon a utimes system call failure, which allows a malicious unprivileged user on the remote server to overwrite arbitrary files in the client's download directory by creating a crafted subdirectory anywhere on the remote server. The victim must use the command scp -rp to download a file hierarchy containing, anywhere inside, this crafted subdirectory. NOTE: the vendor points out that "this attack can achieve no more than a hostile peer is already able to achieve within the scp protocol" and "utimes does not fail under normal circumstances.Show less
4Apple
FreebsdOpenbsd+1 more
4Freebsd
Mac Os XOpenbsd+1 more
Nov 21, 2024
Feb 12, 2020
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
regcomp in the BSD implementation of libc is vulnerable to denial of service due to stack exhaustion.
4Canonical
DebianFedoraproject+1 more
4Debian Linux
FedoraOpensmtpd+1 more
Jun 17, 2026
Jan 29, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary commands as root via a crafted SMTP session, as demonstrated by shell metacharacte...Show more
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary commands as root via a crafted SMTP session, as demonstrated by shell metacharacters in a MAIL FROM field. This affects the "uncommented" default configuration. The issue exists because of an incorrect return value upon failure of input validation.Show less
2Openbsd
Opensuse
2Libressl
Opensuse
Nov 21, 2024
Jan 23, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Memory leak in the OBJ_obj2txt function in LibreSSL before 2.3.1 allows remote attackers to cause a denial of service (memory consumption) via a large number of ASN.1 object identifiers in X.509 certificates.
2Openbsd
Opensuse
2Libressl
Opensuse
Nov 21, 2024
Jan 23, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Off-by-one error in the OBJ_obj2txt function in LibreSSL before 2.3.1 allows remote attackers to cause a denial of service (program crash) or possible execute arbitrary code via a crafted X.509 certificate, which trigger...Show more
Off-by-one error in the OBJ_obj2txt function in LibreSSL before 2.3.1 allows remote attackers to cause a denial of service (program crash) or possible execute arbitrary code via a crafted X.509 certificate, which triggers a stack-based buffer overflow. Note: this vulnerability exists because of an incorrect fix for CVE-2014-3508.Show less
1Openbsd
1Textproc/isearch
Nov 21, 2024
Dec 30, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The isearch package (textproc/isearch) before 1.47.01nb1 uses the tempnam() function to create insecure temporary files into a publicly-writable area (/tmp).
1Openbsd
1Openbsd
Jun 17, 2026
Dec 12, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
OpenBSD through 6.6 allows local users to escalate to root because a check for LD_LIBRARY_PATH in setuid programs can be defeated by setting a very small RLIMIT_DATA resource limit. When executing chpass or passwd (which...Show more
OpenBSD through 6.6 allows local users to escalate to root because a check for LD_LIBRARY_PATH in setuid programs can be defeated by setting a very small RLIMIT_DATA resource limit. When executing chpass or passwd (which are setuid root), _dl_setup_env in ld.so tries to strip LD_LIBRARY_PATH from the environment, but fails when it cannot allocate memory. Thus, the attacker is able to execute their own library code as root.Show less
4Apple
FreebsdLinux+1 more
8Freebsd
IpadosIphone Os+5 more
Jun 17, 2026
Dec 11, 2019
N/A· v4
7.4 HIGH· v3
4.9 MEDIUM· v2
A vulnerability was discovered in Linux, FreeBSD, OpenBSD, MacOS, iOS, and Android that allows a malicious access point, or an adjacent user, to determine if a connected user is using a VPN, make positive inferences abou...Show more
A vulnerability was discovered in Linux, FreeBSD, OpenBSD, MacOS, iOS, and Android that allows a malicious access point, or an adjacent user, to determine if a connected user is using a VPN, make positive inferences about the websites they are visiting, and determine the correct sequence and acknowledgement numbers in use, allowing the bad actor to inject data into the TCP stream. This provides everything that is needed for an attacker to hijack active connections inside the VPN tunnel.Show less
3Debian
Dietlibc ProjectOpenbsd
3Debian Linux
DietlibcOpenbsd
Nov 21, 2024
Dec 10, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
lib/libc/stdlib/random.c in OpenBSD returns 0 when seeded with 0.
1Openbsd
1Openbsd
Jun 17, 2026
Dec 5, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
OpenBSD 6.6, in a non-default configuration where S/Key or YubiKey authentication is enabled, allows local users to become root by leveraging membership in the auth group. This occurs because root's file can be written t...Show more
OpenBSD 6.6, in a non-default configuration where S/Key or YubiKey authentication is enabled, allows local users to become root by leveraging membership in the auth group. This occurs because root's file can be written to /etc/skey or /var/db/yubikey, and need not be owned by root.Show less
1Openbsd
1Openbsd
Jun 17, 2026
Dec 5, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
libc in OpenBSD 6.6 allows authentication bypass via the -schallenge username, as demonstrated by smtpd, ldapd, or radiusd. This is related to gen/auth_subr.c and gen/authenticate.c in libc (and login/login.c and xenocar...Show more
libc in OpenBSD 6.6 allows authentication bypass via the -schallenge username, as demonstrated by smtpd, ldapd, or radiusd. This is related to gen/auth_subr.c and gen/authenticate.c in libc (and login/login.c and xenocara/app/xenodm/greeter/verify.c).Show less
1Openbsd
1Openbsd
Jun 17, 2026
Dec 5, 2019
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
xlock in OpenBSD 6.6 allows local users to gain the privileges of the auth group by providing a LIBGL_DRIVERS_PATH environment variable, because xenocara/lib/mesa/src/loader/loader.c mishandles dlopen.
1Openbsd
1Openbsd
Jun 17, 2026
Dec 5, 2019
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
In OpenBSD 6.6, local users can use the su -L option to achieve any login class (often excluding root) because there is a logic error in the main function in su/su.c.
3Netapp
OpenbsdSiemens
5Cloud Backup
OpensshScalance X204rna Ecc Firmware+2 more
Jun 17, 2026
Oct 9, 2019
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
OpenSSH 7.7 through 7.9 and 8.x before 8.1, when compiled with an experimental key type, has a pre-authentication integer overflow if a client or server is configured to use a crafted XMSS key. This leads to memory corru...Show more
OpenSSH 7.7 through 7.9 and 8.x before 8.1, when compiled with an experimental key type, has a pre-authentication integer overflow if a client or server is configured to use a crafted XMSS key. This leads to memory corruption and local code execution because of an error in the XMSS key parsing algorithm. NOTE: the XMSS implementation is considered experimental in all released OpenSSH versions, and there is no supported way to enable it when building portable OpenSSH.Show less
1Openbsd
1Openbsd
Jun 17, 2026
Aug 26, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
OpenBSD kernel version <= 6.5 can be forced to create long chains of TCP SACK holes that causes very expensive calls to tcp_sack_option() for every incoming SACK packet which can lead to a denial of service.
10Apache
CanonicalDebian+7 more
19Debian Linux
Enterprise LinuxEnterprise Linux Eus+16 more
Jun 17, 2026
Jan 31, 2019
N/A· v4
5.9 MEDIUM· v3
5.8 MEDIUM· v2
An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses which files/directories are sent to the client. However, the scp client only performs cursory validati...Show more
An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses which files/directories are sent to the client. However, the scp client only performs cursory validation of the object name returned (only directory traversal attacks are prevented). A malicious scp server (or Man-in-The-Middle attacker) can overwrite arbitrary files in the scp client target directory. If recursive operation (-r) is performed, the server can manipulate subdirectories as well (for example, to overwrite the .ssh/authorized_keys file).Show less
4Netapp
OpenbsdSiemens+1 more
7Element Software
Ontap Select DeployOpenssh+4 more
Jun 17, 2026
Jan 31, 2019
N/A· v4
6.8 MEDIUM· v3
4.0 MEDIUM· v2
In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-The-Middle attacker) can manipulate the client output, for example to use ANSI control codes to hide...Show more
In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-The-Middle attacker) can manipulate the client output, for example to use ANSI control codes to hide additional files being transferred.Show less