OpenBSD records
360 published records for vendor openbsd.
Researcher profile
- Entered KEV
- 1 · 0.3%
- Weaponized
- 7 · 1.9%
- Pre-auth RCE
- 44
- With a fix record
- 42.2%
- Median publish → KEV
- 786 days
Recurring classes
- CWE-264 Permissions, Privileges, and Access Controls14
- CWE-20 Improper Input Validation14
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor10
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer9
- CWE-399 Resource Management Errors9
- CWE-287 Improper Authentication9
The weakness classes this vendor ships most often: where to look.
CWEAll records
360 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
99Now | CVE-2020-7247Weaponized | smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary coopenbsd · opensmtpd · CWE-78 | Critical9.8 | KEV | 99.0% | Jan 29, 2020 |
63This week | CVE-2023-38408Proof of concept | The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if openbsd · openssh · CWE-428 | Critical9.8 | — | 79.7% | Jul 19, 2023 |
62This week | CVE-2024-6387Proof of concept | Openssh: regresshion - race condition in ssh allows rce/dossonicwall · sma 6200 firmware · CWE-364 | High8.1 | — | 99.5% | Jul 1, 2024 |
62This week | CVE-2003-0466Proof of concept | Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code,redhat · wu ftpd · CWE-193 | Critical9.8 | — | 78.1% | Aug 27, 2003 |
56Plan | CVE-2002-0391No exploit | Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including disun · solaris · CWE-190 | Critical9.8 | — | 58.1% | Aug 12, 2002 |
53Plan | CVE-2023-25136Proof of concept | OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling.openbsd · openssh · CWE-415 | Medium6.5 | — | 89.7% | Feb 3, 2023 |
52Plan | CVE-2007-5365Proof of concept | Stack-based buffer overflow in the cons_options function in options.c in dhcpd in OpenBSD 4.0 through 4.2, and some other dhcpd implementatiopenbsd · openbsd · CWE-119 | High7.2 | — | 80.3% | Oct 11, 2007 |
52Plan | CVE-2001-0554Proof of concept | Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a mit · kerberos · CWE-120 | Critical10.0 | — | 38.7% | Aug 14, 2001 |
51Plan | CVE-2018-15473Weaponized | OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after openbsd · openssh · CWE-362 | Medium5.3 | — | 98.6% | Aug 17, 2018 |
51Plan | CVE-2023-48795Proof of concept | The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypasssh · ssh · CWE-354 | Medium5.9 | — | 93.3% | Dec 18, 2023 |
50Plan | CVE-2016-6210Weaponized | sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static password when the usopenbsd · openssh · CWE-200 | Medium5.9 | — | 88.9% | Feb 13, 2017 |
50Plan | CVE-2004-0492No exploit | Heap-based buffer overflow in proxy_util.c for mod_proxy in Apache 1.3.25 to 1.3.31 allows remote attackers to cause a denial of service (prapache · http server | Critical10.0 | — | 33.6% | Aug 6, 2004 |
50Plan | CVE-2001-0144Proof of concept | CORE SDI SSH1 CRC-32 compensation attack detector allows remote attackers to execute arbitrary commands on an SSH server or client via an inssh · ssh | Critical10.0 | — | 32.4% | Mar 12, 2001 |
48Plan | CVE-2016-6515Proof of concept | The auth_password function in auth-passwd.c in sshd in OpenSSH before 7.3 does not limit password lengths for password authentication, whichopenbsd · openssh · CWE-20 | High7.5 | — | 58.6% | Aug 7, 2016 |
48Plan | CVE-2002-0640Proof of concept | Buffer overflow in sshd in OpenSSH 2.3.1 through 3.3 may allow remote attackers to execute arbitrary code via a large number of responses duopenbsd · openssh | Critical10.0 | — | 27.3% | Jul 3, 2002 |
47Plan | CVE-2004-0084Proof of concept | Buffer overflow in the ReadFontAlias function in XFree86 4.1.0 to 4.3.0, when using the CopyISOLatin1Lowered function, allows local or remotxfree86 project · x11r6 | Critical10.0 | — | 24.9% | Mar 3, 2004 |
46Plan | CVE-2004-0083Proof of concept | Buffer overflow in ReadFontAlias from dirfile.c of XFree86 4.1.0 through 4.3.0 allows local users and remote attackers to execute arbitrary xfree86 project · x11r6 | Critical10.0 | — | 21.2% | Mar 3, 2004 |
46Plan | CVE-2001-0247Proof of concept | Buffer overflows in BSD-based FTP servers allows remote attackers to execute arbitrary commands via a long pattern string containing a {} semit · kerberos 5 | Critical10.0 | — | 19.3% | Jun 18, 2001 |
45Plan | CVE-2005-0356Proof of concept | Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackecisco · agent desktop | Medium5.0 | — | 82.8% | May 31, 2005 |
45Plan | CVE-2016-0777Proof of concept | The resend_bytes function in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2 allows remote servers to obtain sensitsophos · unified threat management software · CWE-200 | Medium6.5 | — | 63.5% | Jan 14, 2016 |
45Plan | CVE-2006-5051Proof of concept | Signal handler race condition in OpenSSH before 4.4 allows remote attackers to cause a denial of service (crash), and possibly execute arbitopenbsd · openssh · CWE-415 | High8.1 | — | 45.0% | Sep 27, 2006 |
45Plan | CVE-2001-0053Proof of concept | One-byte buffer overflow in replydirname function in BSD-based ftpd allows remote attackers to gain root privileges.david madore · ftpd-bsd | Critical10.0 | — | 17.9% | Feb 12, 2001 |
45Plan | CVE-2007-1365Proof of concept | Buffer overflow in kern/uipc_mbuf2.c in OpenBSD 3.9 and 4.0 allows remote attackers to execute arbitrary code via fragmented IPv6 packets duopenbsd · openbsd | Critical10.0 | — | 17.8% | Mar 10, 2007 |
44Plan | CVE-2002-0639No exploit | Integer overflow in sshd in OpenSSH 2.9.9 through 3.3 allows remote attackers to execute arbitrary code during challenge response authenticaopenbsd · openssh · CWE-190 | Critical9.8 | — | 18.3% | Jul 3, 2002 |
44Plan | CVE-2004-0416Proof of concept | Double free vulnerability for the error_prog_name string in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attackercvs · cvs · CWE-119 | Critical10.0 | — | 13.2% | Aug 6, 2004 |
- CVE-2020-724799Now
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary co
CriticalCVSS 9.8KEVWeaponizedEPSS 99%openbsd · opensmtpdJan 29, 2020
- CVE-2023-3840863This week
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if
CriticalCVSS 9.8Proof of conceptEPSS 80%openbsd · opensshJul 19, 2023
- CVE-2024-638762This week
Openssh: regresshion - race condition in ssh allows rce/dos
HighCVSS 8.1Proof of conceptEPSS 100%sonicwall · sma 6200 firmwareJul 1, 2024
- CVE-2003-046662This week
Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code,
CriticalCVSS 9.8Proof of conceptEPSS 78%redhat · wu ftpdAug 27, 2003
- CVE-2002-039156Plan
Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including di
CriticalCVSS 9.8No exploitEPSS 58%sun · solarisAug 12, 2002
- CVE-2023-2513653Plan
OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling.
MediumCVSS 6.5Proof of conceptEPSS 90%openbsd · opensshFeb 3, 2023
- CVE-2007-536552Plan
Stack-based buffer overflow in the cons_options function in options.c in dhcpd in OpenBSD 4.0 through 4.2, and some other dhcpd implementati
HighCVSS 7.2Proof of conceptEPSS 80%openbsd · openbsdOct 11, 2007
- CVE-2001-055452Plan
Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a
CriticalCVSS 10.0Proof of conceptEPSS 39%mit · kerberosAug 14, 2001
- CVE-2018-1547351Plan
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after
MediumCVSS 5.3WeaponizedEPSS 99%openbsd · opensshAug 17, 2018
- CVE-2023-4879551Plan
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypas
MediumCVSS 5.9Proof of conceptEPSS 93%ssh · sshDec 18, 2023
- CVE-2016-621050Plan
sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static password when the us
MediumCVSS 5.9WeaponizedEPSS 89%openbsd · opensshFeb 13, 2017
- CVE-2004-049250Plan
Heap-based buffer overflow in proxy_util.c for mod_proxy in Apache 1.3.25 to 1.3.31 allows remote attackers to cause a denial of service (pr
CriticalCVSS 10.0No exploitEPSS 34%apache · http serverAug 6, 2004
- CVE-2001-014450Plan
CORE SDI SSH1 CRC-32 compensation attack detector allows remote attackers to execute arbitrary commands on an SSH server or client via an in
CriticalCVSS 10.0Proof of conceptEPSS 32%ssh · sshMar 12, 2001
- CVE-2016-651548Plan
The auth_password function in auth-passwd.c in sshd in OpenSSH before 7.3 does not limit password lengths for password authentication, which
HighCVSS 7.5Proof of conceptEPSS 59%openbsd · opensshAug 7, 2016
- CVE-2002-064048Plan
Buffer overflow in sshd in OpenSSH 2.3.1 through 3.3 may allow remote attackers to execute arbitrary code via a large number of responses du
CriticalCVSS 10.0Proof of conceptEPSS 27%openbsd · opensshJul 3, 2002
- CVE-2004-008447Plan
Buffer overflow in the ReadFontAlias function in XFree86 4.1.0 to 4.3.0, when using the CopyISOLatin1Lowered function, allows local or remot
CriticalCVSS 10.0Proof of conceptEPSS 25%xfree86 project · x11r6Mar 3, 2004
- CVE-2004-008346Plan
Buffer overflow in ReadFontAlias from dirfile.c of XFree86 4.1.0 through 4.3.0 allows local users and remote attackers to execute arbitrary
CriticalCVSS 10.0Proof of conceptEPSS 21%xfree86 project · x11r6Mar 3, 2004
- CVE-2001-024746Plan
Buffer overflows in BSD-based FTP servers allows remote attackers to execute arbitrary commands via a long pattern string containing a {} se
CriticalCVSS 10.0Proof of conceptEPSS 19%mit · kerberos 5Jun 18, 2001
- CVE-2005-035645Plan
Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attacke
MediumCVSS 5.0Proof of conceptEPSS 83%cisco · agent desktopMay 31, 2005
- CVE-2016-077745Plan
The resend_bytes function in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2 allows remote servers to obtain sensit
MediumCVSS 6.5Proof of conceptEPSS 63%sophos · unified threat management softwareJan 14, 2016
- CVE-2006-505145Plan
Signal handler race condition in OpenSSH before 4.4 allows remote attackers to cause a denial of service (crash), and possibly execute arbit
HighCVSS 8.1Proof of conceptEPSS 45%openbsd · opensshSep 27, 2006
- CVE-2001-005345Plan
One-byte buffer overflow in replydirname function in BSD-based ftpd allows remote attackers to gain root privileges.
CriticalCVSS 10.0Proof of conceptEPSS 18%david madore · ftpd-bsdFeb 12, 2001
- CVE-2007-136545Plan
Buffer overflow in kern/uipc_mbuf2.c in OpenBSD 3.9 and 4.0 allows remote attackers to execute arbitrary code via fragmented IPv6 packets du
CriticalCVSS 10.0Proof of conceptEPSS 18%openbsd · openbsdMar 10, 2007
- CVE-2002-063944Plan
Integer overflow in sshd in OpenSSH 2.9.9 through 3.3 allows remote attackers to execute arbitrary code during challenge response authentica
CriticalCVSS 9.8No exploitEPSS 18%openbsd · opensshJul 3, 2002
- CVE-2004-041644Plan
Double free vulnerability for the error_prog_name string in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attacker
CriticalCVSS 10.0Proof of conceptEPSS 13%cvs · cvsAug 6, 2004