NetBSD kayıtları
netbsd üreticisine ait 180 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 5 · %2,8
- Pre-auth RCE
- 22
- Düzeltme kaydı olan
- %15,6
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-189 Numeric Errors8
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer8
- CWE-20 Improper Input Validation6
- CWE-399 Resource Management Errors5
- CWE-264 Permissions, Privileges, and Access Controls4
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')3
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
180 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
62Bu hafta | CVE-2024-6387Kavram kanıtı | Openssh: regresshion - race condition in ssh allows rce/dossonicwall · sma 6200 firmware · CWE-364 | Yüksek8,1 | — | %99,5 | 1 Tem 2024 |
62Bu hafta | CVE-2003-0466Kavram kanıtı | Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code,redhat · wu ftpd · CWE-193 | Kritik9,8 | — | %78,1 | 27 Ağu 2003 |
62Bu hafta | CVE-2002-1337Kavram kanıtı | Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related tsendmail · sendmail · CWE-120 | Kritik10,0 | — | %72,6 | 7 Mar 2003 |
60Bu hafta | CVE-2003-0694Silahlaştırılmış | The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated usingsendmail · advanced message server | Kritik10,0 | — | %66,2 | 6 Eki 2003 |
56Planlayın | CVE-1999-0046Kavram kanıtı | Buffer overflow of rlogin program using TERM environmental variable.bsdi · bsd os · CWE-120 | Kritik10,0 | — | %51,9 | 6 Şub 1997 |
52Planlayın | CVE-2001-0554Kavram kanıtı | Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a mit · kerberos · CWE-120 | Kritik10,0 | — | %38,7 | 14 Ağu 2001 |
51Planlayın | CVE-2014-8517Silahlaştırılmış | The fetch_url function in usr.bin/ftp/fetch.c in tnftp, as used in NetBSD 5.1 through 5.1.4, 5.2 through 5.2.2, 6.0 through 6.0.6, and 6.1 tnetbsd · netbsd · CWE-77 | Yüksek7,5 | — | %69,1 | 17 Kas 2014 |
49Planlayın | CVE-1999-0016Kavram kanıtı | Land IP denial of service.cisco · ios | Orta5,0 | — | %95,7 | 1 Ara 1997 |
49Planlayın | CVE-1999-0009Kavram kanıtı | Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases.data general · dg ux | Kritik10,0 | — | %29,0 | 8 Nis 1998 |
46Planlayın | CVE-2001-0247Kavram kanıtı | Buffer overflows in BSD-based FTP servers allows remote attackers to execute arbitrary commands via a long pattern string containing a {} semit · kerberos 5 | Kritik10,0 | — | %19,3 | 18 Haz 2001 |
45Planlayın | CVE-2017-1000375Kavram kanıtı | NetBSD maps the run-time link-editor ld.so directly below the stack region, even if ASLR is enabled, this allows attackers to more easily manetbsd · netbsd · CWE-119 | Kritik9,8 | — | %18,9 | 19 Haz 2017 |
45Planlayın | CVE-2001-0053Kavram kanıtı | One-byte buffer overflow in replydirname function in BSD-based ftpd allows remote attackers to gain root privileges.david madore · ftpd-bsd | Kritik10,0 | — | %17,9 | 12 Şub 2001 |
44Planlayın | CVE-2004-0230Kavram kanıtı | TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connectiojuniper · junos | Orta5,0 | — | %80,3 | 18 Ağu 2004 |
44Planlayın | CVE-2006-4304İstismar yok | Buffer overflow in the sppp driver in FreeBSD 4.11 through 6.1, NetBSD 2.0 through 4.0 beta before 20060823, and OpenBSD 3.8 and 3.9 before freebsd · freebsd | Kritik10,0 | — | %11,9 | 23 Ağu 2006 |
43Planlayın | CVE-2014-3566Silahlaştırılmış | The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for manopenssl · openssl · CWE-310 | Düşük3,4 | — | %100,0 | 14 Eki 2014 |
42Planlayın | CVE-2006-6652Kavram kanıtı | Buffer overflow in the glob implementation (glob.c) in libc in NetBSD-current before 20050914, NetBSD 2.* and 3.* before 20061203, and Appleapple · mac os x · CWE-119 | Kritik9,0 | — | %20,0 | 19 Ara 2006 |
41Planlayın | CVE-1999-0513Kavram kanıtı | ICMP messages to broadcast addresses are allowed, allowing for a Smurf attack that can cause a denial of service.digital · unix | Orta5,0 | — | %70,9 | 5 Oca 1998 |
41Planlayın | CVE-2003-0001Kavram kanıtı | Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote attackers to obtain inffreebsd · freebsd · CWE-200 | Orta5,0 | — | %70,2 | 17 Oca 2003 |
40Planlayın | CVE-2012-0217Silahlaştırılmış | The x86-64 kernel system-call functionality in Xen 4.1.2 and earlier, as used in Citrix XenServer 6.0.2 and earlier and other products; Oracxen · xen · CWE-119 | Yüksek7,2 | — | %39,8 | 12 Haz 2012 |
40Planlayın | CVE-2011-2895İstismar yok | The LZW decompressor in (1) the BufCompressedFill function in fontfile/decompress.c in X.Org libXfont before 1.4.4 and (2) compress/compressx · libxfont · CWE-119 | Kritik9,3 | — | %8,4 | 19 Ağu 2011 |
40Planlayın | CVE-2017-1000378İstismar yok | The NetBSD qsort() function is recursive, and not randomized, an attacker can construct a pathological input array of N elements that causesnetbsd · netbsd · CWE-400 | Kritik9,8 | — | %4,1 | 19 Haz 2017 |
40Planlayın | CVE-2017-1000374İstismar yok | A flaw exists in NetBSD's implementation of the stack guard page that allows attackers to bypass it resulting in arbitrary code execution usnetbsd · netbsd | Kritik9,8 | — | %3,4 | 19 Haz 2017 |
40Planlayın | CVE-2015-8212İstismar yok | CGI handling flaw in bozohttpd in NetBSD 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows remote attackers to execute arbitrary code vianetbsd · netbsd · CWE-20 | Kritik9,8 | — | %3,2 | 19 Oca 2017 |
40Planlayın | CVE-1999-0323İstismar yok | FreeBSD mmap function allows users to modify append-only or immutable files.freebsd · freebsd | Kritik10,0 | — | %1,4 | 20 Şub 1998 |
39İzleyin | CVE-2008-2476İstismar yok | The IPv6 Neighbor Discovery Protocol (NDP) implementation in (1) FreeBSD 6.3 through 7.1, (2) OpenBSD 4.2 and 4.3, (3) NetBSD, (4) Force10 Fforce10 · ftos · CWE-20 | Kritik9,3 | — | %7,4 | 3 Eki 2008 |
- CVE-2024-638762Bu hafta
Openssh: regresshion - race condition in ssh allows rce/dos
YüksekCVSS 8,1Kavram kanıtıEPSS %100sonicwall · sma 6200 firmware1 Tem 2024
- CVE-2003-046662Bu hafta
Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code,
KritikCVSS 9,8Kavram kanıtıEPSS %78redhat · wu ftpd27 Ağu 2003
- CVE-2002-133762Bu hafta
Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related t
KritikCVSS 10,0Kavram kanıtıEPSS %73sendmail · sendmail7 Mar 2003
- CVE-2003-069460Bu hafta
The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using
KritikCVSS 10,0SilahlaştırılmışEPSS %66sendmail · advanced message server6 Eki 2003
- CVE-1999-004656Planlayın
Buffer overflow of rlogin program using TERM environmental variable.
KritikCVSS 10,0Kavram kanıtıEPSS %52bsdi · bsd os6 Şub 1997
- CVE-2001-055452Planlayın
Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a
KritikCVSS 10,0Kavram kanıtıEPSS %39mit · kerberos14 Ağu 2001
- CVE-2014-851751Planlayın
The fetch_url function in usr.bin/ftp/fetch.c in tnftp, as used in NetBSD 5.1 through 5.1.4, 5.2 through 5.2.2, 6.0 through 6.0.6, and 6.1 t
YüksekCVSS 7,5SilahlaştırılmışEPSS %69netbsd · netbsd17 Kas 2014
- CVE-1999-001649Planlayın
Land IP denial of service.
OrtaCVSS 5,0Kavram kanıtıEPSS %96cisco · ios1 Ara 1997
- CVE-1999-000949Planlayın
Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases.
KritikCVSS 10,0Kavram kanıtıEPSS %29data general · dg ux8 Nis 1998
- CVE-2001-024746Planlayın
Buffer overflows in BSD-based FTP servers allows remote attackers to execute arbitrary commands via a long pattern string containing a {} se
KritikCVSS 10,0Kavram kanıtıEPSS %19mit · kerberos 518 Haz 2001
- CVE-2017-100037545Planlayın
NetBSD maps the run-time link-editor ld.so directly below the stack region, even if ASLR is enabled, this allows attackers to more easily ma
KritikCVSS 9,8Kavram kanıtıEPSS %19netbsd · netbsd19 Haz 2017
- CVE-2001-005345Planlayın
One-byte buffer overflow in replydirname function in BSD-based ftpd allows remote attackers to gain root privileges.
KritikCVSS 10,0Kavram kanıtıEPSS %18david madore · ftpd-bsd12 Şub 2001
- CVE-2004-023044Planlayın
TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connectio
OrtaCVSS 5,0Kavram kanıtıEPSS %80juniper · junos18 Ağu 2004
- CVE-2006-430444Planlayın
Buffer overflow in the sppp driver in FreeBSD 4.11 through 6.1, NetBSD 2.0 through 4.0 beta before 20060823, and OpenBSD 3.8 and 3.9 before
KritikCVSS 10,0İstismar yokEPSS %12freebsd · freebsd23 Ağu 2006
- CVE-2014-356643Planlayın
The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man
DüşükCVSS 3,4SilahlaştırılmışEPSS %100openssl · openssl14 Eki 2014
- CVE-2006-665242Planlayın
Buffer overflow in the glob implementation (glob.c) in libc in NetBSD-current before 20050914, NetBSD 2.* and 3.* before 20061203, and Apple
KritikCVSS 9,0Kavram kanıtıEPSS %20apple · mac os x19 Ara 2006
- CVE-1999-051341Planlayın
ICMP messages to broadcast addresses are allowed, allowing for a Smurf attack that can cause a denial of service.
OrtaCVSS 5,0Kavram kanıtıEPSS %71digital · unix5 Oca 1998
- CVE-2003-000141Planlayın
Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote attackers to obtain inf
OrtaCVSS 5,0Kavram kanıtıEPSS %70freebsd · freebsd17 Oca 2003
- CVE-2012-021740Planlayın
The x86-64 kernel system-call functionality in Xen 4.1.2 and earlier, as used in Citrix XenServer 6.0.2 and earlier and other products; Orac
YüksekCVSS 7,2SilahlaştırılmışEPSS %40xen · xen12 Haz 2012
- CVE-2011-289540Planlayın
The LZW decompressor in (1) the BufCompressedFill function in fontfile/decompress.c in X.Org libXfont before 1.4.4 and (2) compress/compress
KritikCVSS 9,3İstismar yokEPSS %8x · libxfont19 Ağu 2011
- CVE-2017-100037840Planlayın
The NetBSD qsort() function is recursive, and not randomized, an attacker can construct a pathological input array of N elements that causes
KritikCVSS 9,8İstismar yokEPSS %4netbsd · netbsd19 Haz 2017
- CVE-2017-100037440Planlayın
A flaw exists in NetBSD's implementation of the stack guard page that allows attackers to bypass it resulting in arbitrary code execution us
KritikCVSS 9,8İstismar yokEPSS %3netbsd · netbsd19 Haz 2017
- CVE-2015-821240Planlayın
CGI handling flaw in bozohttpd in NetBSD 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows remote attackers to execute arbitrary code via
KritikCVSS 9,8İstismar yokEPSS %3netbsd · netbsd19 Oca 2017
- CVE-1999-032340Planlayın
FreeBSD mmap function allows users to modify append-only or immutable files.
KritikCVSS 10,0İstismar yokEPSS %1freebsd · freebsd20 Şub 1998
- CVE-2008-247639İzleyin
The IPv6 Neighbor Discovery Protocol (NDP) implementation in (1) FreeBSD 6.3 through 7.1, (2) OpenBSD 4.2 and 4.3, (3) NetBSD, (4) Force10 F
KritikCVSS 9,3İstismar yokEPSS %7force10 · ftos3 Eki 2008