Skip to content
Noroxi

NetBSD records

180 published records for vendor netbsd.

Researcher profile

Entered KEV
0 · 0%
Weaponized
5 · 2.8%
Pre-auth RCE
22
With a fix record
15.6%
Median publish → KEV
No record has entered KEV

All records

180 records
  • CVE-2024-6387
    62This week

    Openssh: regresshion - race condition in ssh allows rce/dos

    HighCVSS 8.1Proof of conceptEPSS 100%

    sonicwall · sma 6200 firmwareJul 1, 2024

  • CVE-2003-0466
    62This week

    Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code,

    CriticalCVSS 9.8Proof of conceptEPSS 78%

    redhat · wu ftpdAug 27, 2003

  • CVE-2002-1337
    62This week

    Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related t

    CriticalCVSS 10.0Proof of conceptEPSS 73%

    sendmail · sendmailMar 7, 2003

  • CVE-2003-0694
    60This week

    The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using

    CriticalCVSS 10.0WeaponizedEPSS 66%

    sendmail · advanced message serverOct 6, 2003

  • Buffer overflow of rlogin program using TERM environmental variable.

    CriticalCVSS 10.0Proof of conceptEPSS 52%

    bsdi · bsd osFeb 6, 1997

  • Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a

    CriticalCVSS 10.0Proof of conceptEPSS 39%

    mit · kerberosAug 14, 2001

  • The fetch_url function in usr.bin/ftp/fetch.c in tnftp, as used in NetBSD 5.1 through 5.1.4, 5.2 through 5.2.2, 6.0 through 6.0.6, and 6.1 t

    HighCVSS 7.5WeaponizedEPSS 69%

    netbsd · netbsdNov 17, 2014

  • Land IP denial of service.

    MediumCVSS 5.0Proof of conceptEPSS 96%

    cisco · iosDec 1, 1997

  • Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases.

    CriticalCVSS 10.0Proof of conceptEPSS 29%

    data general · dg uxApr 8, 1998

  • Buffer overflows in BSD-based FTP servers allows remote attackers to execute arbitrary commands via a long pattern string containing a {} se

    CriticalCVSS 10.0Proof of conceptEPSS 19%

    mit · kerberos 5Jun 18, 2001

  • NetBSD maps the run-time link-editor ld.so directly below the stack region, even if ASLR is enabled, this allows attackers to more easily ma

    CriticalCVSS 9.8Proof of conceptEPSS 19%

    netbsd · netbsdJun 19, 2017

  • One-byte buffer overflow in replydirname function in BSD-based ftpd allows remote attackers to gain root privileges.

    CriticalCVSS 10.0Proof of conceptEPSS 18%

    david madore · ftpd-bsdFeb 12, 2001

  • TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connectio

    MediumCVSS 5.0Proof of conceptEPSS 80%

    juniper · junosAug 18, 2004

  • Buffer overflow in the sppp driver in FreeBSD 4.11 through 6.1, NetBSD 2.0 through 4.0 beta before 20060823, and OpenBSD 3.8 and 3.9 before

    CriticalCVSS 10.0No exploitEPSS 12%

    freebsd · freebsdAug 23, 2006

  • The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man

    LowCVSS 3.4WeaponizedEPSS 100%

    openssl · opensslOct 14, 2014

  • Buffer overflow in the glob implementation (glob.c) in libc in NetBSD-current before 20050914, NetBSD 2.* and 3.* before 20061203, and Apple

    CriticalCVSS 9.0Proof of conceptEPSS 20%

    apple · mac os xDec 19, 2006

  • ICMP messages to broadcast addresses are allowed, allowing for a Smurf attack that can cause a denial of service.

    MediumCVSS 5.0Proof of conceptEPSS 71%

    digital · unixJan 5, 1998

  • Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote attackers to obtain inf

    MediumCVSS 5.0Proof of conceptEPSS 70%

    freebsd · freebsdJan 17, 2003

  • The x86-64 kernel system-call functionality in Xen 4.1.2 and earlier, as used in Citrix XenServer 6.0.2 and earlier and other products; Orac

    HighCVSS 7.2WeaponizedEPSS 40%

    xen · xenJun 12, 2012

  • The LZW decompressor in (1) the BufCompressedFill function in fontfile/decompress.c in X.Org libXfont before 1.4.4 and (2) compress/compress

    CriticalCVSS 9.3No exploitEPSS 8%

    x · libxfontAug 19, 2011

  • The NetBSD qsort() function is recursive, and not randomized, an attacker can construct a pathological input array of N elements that causes

    CriticalCVSS 9.8No exploitEPSS 4%

    netbsd · netbsdJun 19, 2017

  • A flaw exists in NetBSD's implementation of the stack guard page that allows attackers to bypass it resulting in arbitrary code execution us

    CriticalCVSS 9.8No exploitEPSS 3%

    netbsd · netbsdJun 19, 2017

  • CGI handling flaw in bozohttpd in NetBSD 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows remote attackers to execute arbitrary code via

    CriticalCVSS 9.8No exploitEPSS 3%

    netbsd · netbsdJan 19, 2017

  • FreeBSD mmap function allows users to modify append-only or immutable files.

    CriticalCVSS 10.0No exploitEPSS 1%

    freebsd · freebsdFeb 20, 1998

  • CVE-2008-2476
    39Monitor

    The IPv6 Neighbor Discovery Protocol (NDP) implementation in (1) FreeBSD 6.3 through 7.1, (2) OpenBSD 4.2 and 4.3, (3) NetBSD, (4) Force10 F

    CriticalCVSS 9.3No exploitEPSS 7%

    force10 · ftosOct 3, 2008