Записи NetBSD
180 опубликованных записей вендора netbsd.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 5 · 2,8 %
- Pre-auth RCE
- 22
- С записью об исправлении
- 15,6 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-189 Numeric Errors8
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer8
- CWE-20 Improper Input Validation6
- CWE-399 Resource Management Errors5
- CWE-264 Permissions, Privileges, and Access Controls4
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')3
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
180 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
62На этой неделе | CVE-2024-6387Proof of concept | Openssh: regresshion - race condition in ssh allows rce/dossonicwall · sma 6200 firmware · CWE-364 | Высокая8,1 | — | 99,5 % | 1 июл. 2024 г. |
62На этой неделе | CVE-2003-0466Proof of concept | Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code,redhat · wu ftpd · CWE-193 | Критическая9,8 | — | 78,1 % | 27 авг. 2003 г. |
62На этой неделе | CVE-2002-1337Proof of concept | Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related tsendmail · sendmail · CWE-120 | Критическая10,0 | — | 72,6 % | 7 мар. 2003 г. |
60На этой неделе | CVE-2003-0694Готовый эксплойт | The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated usingsendmail · advanced message server | Критическая10,0 | — | 66,2 % | 6 окт. 2003 г. |
56В плане | CVE-1999-0046Proof of concept | Buffer overflow of rlogin program using TERM environmental variable.bsdi · bsd os · CWE-120 | Критическая10,0 | — | 51,9 % | 6 февр. 1997 г. |
52В плане | CVE-2001-0554Proof of concept | Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a mit · kerberos · CWE-120 | Критическая10,0 | — | 38,7 % | 14 авг. 2001 г. |
51В плане | CVE-2014-8517Готовый эксплойт | The fetch_url function in usr.bin/ftp/fetch.c in tnftp, as used in NetBSD 5.1 through 5.1.4, 5.2 through 5.2.2, 6.0 through 6.0.6, and 6.1 tnetbsd · netbsd · CWE-77 | Высокая7,5 | — | 69,1 % | 17 нояб. 2014 г. |
49В плане | CVE-1999-0016Proof of concept | Land IP denial of service.cisco · ios | Средняя5,0 | — | 95,7 % | 1 дек. 1997 г. |
49В плане | CVE-1999-0009Proof of concept | Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases.data general · dg ux | Критическая10,0 | — | 29,0 % | 8 апр. 1998 г. |
46В плане | CVE-2001-0247Proof of concept | Buffer overflows in BSD-based FTP servers allows remote attackers to execute arbitrary commands via a long pattern string containing a {} semit · kerberos 5 | Критическая10,0 | — | 19,3 % | 18 июн. 2001 г. |
45В плане | CVE-2017-1000375Proof of concept | NetBSD maps the run-time link-editor ld.so directly below the stack region, even if ASLR is enabled, this allows attackers to more easily manetbsd · netbsd · CWE-119 | Критическая9,8 | — | 18,9 % | 19 июн. 2017 г. |
45В плане | CVE-2001-0053Proof of concept | One-byte buffer overflow in replydirname function in BSD-based ftpd allows remote attackers to gain root privileges.david madore · ftpd-bsd | Критическая10,0 | — | 17,9 % | 12 февр. 2001 г. |
44В плане | CVE-2004-0230Proof of concept | TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connectiojuniper · junos | Средняя5,0 | — | 80,3 % | 18 авг. 2004 г. |
44В плане | CVE-2006-4304Эксплойта нет | Buffer overflow in the sppp driver in FreeBSD 4.11 through 6.1, NetBSD 2.0 through 4.0 beta before 20060823, and OpenBSD 3.8 and 3.9 before freebsd · freebsd | Критическая10,0 | — | 11,9 % | 23 авг. 2006 г. |
43В плане | CVE-2014-3566Готовый эксплойт | The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for manopenssl · openssl · CWE-310 | Низкая3,4 | — | 100,0 % | 14 окт. 2014 г. |
42В плане | CVE-2006-6652Proof of concept | Buffer overflow in the glob implementation (glob.c) in libc in NetBSD-current before 20050914, NetBSD 2.* and 3.* before 20061203, and Appleapple · mac os x · CWE-119 | Критическая9,0 | — | 20,0 % | 19 дек. 2006 г. |
41В плане | CVE-1999-0513Proof of concept | ICMP messages to broadcast addresses are allowed, allowing for a Smurf attack that can cause a denial of service.digital · unix | Средняя5,0 | — | 70,9 % | 5 янв. 1998 г. |
41В плане | CVE-2003-0001Proof of concept | Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote attackers to obtain inffreebsd · freebsd · CWE-200 | Средняя5,0 | — | 70,2 % | 17 янв. 2003 г. |
40В плане | CVE-2012-0217Готовый эксплойт | The x86-64 kernel system-call functionality in Xen 4.1.2 and earlier, as used in Citrix XenServer 6.0.2 and earlier and other products; Oracxen · xen · CWE-119 | Высокая7,2 | — | 39,8 % | 12 июн. 2012 г. |
40В плане | CVE-2011-2895Эксплойта нет | The LZW decompressor in (1) the BufCompressedFill function in fontfile/decompress.c in X.Org libXfont before 1.4.4 and (2) compress/compressx · libxfont · CWE-119 | Критическая9,3 | — | 8,4 % | 19 авг. 2011 г. |
40В плане | CVE-2017-1000378Эксплойта нет | The NetBSD qsort() function is recursive, and not randomized, an attacker can construct a pathological input array of N elements that causesnetbsd · netbsd · CWE-400 | Критическая9,8 | — | 4,1 % | 19 июн. 2017 г. |
40В плане | CVE-2017-1000374Эксплойта нет | A flaw exists in NetBSD's implementation of the stack guard page that allows attackers to bypass it resulting in arbitrary code execution usnetbsd · netbsd | Критическая9,8 | — | 3,4 % | 19 июн. 2017 г. |
40В плане | CVE-2015-8212Эксплойта нет | CGI handling flaw in bozohttpd in NetBSD 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows remote attackers to execute arbitrary code vianetbsd · netbsd · CWE-20 | Критическая9,8 | — | 3,2 % | 19 янв. 2017 г. |
40В плане | CVE-1999-0323Эксплойта нет | FreeBSD mmap function allows users to modify append-only or immutable files.freebsd · freebsd | Критическая10,0 | — | 1,4 % | 20 февр. 1998 г. |
39Наблюдать | CVE-2008-2476Эксплойта нет | The IPv6 Neighbor Discovery Protocol (NDP) implementation in (1) FreeBSD 6.3 through 7.1, (2) OpenBSD 4.2 and 4.3, (3) NetBSD, (4) Force10 Fforce10 · ftos · CWE-20 | Критическая9,3 | — | 7,4 % | 3 окт. 2008 г. |
- CVE-2024-638762На этой неделе
Openssh: regresshion - race condition in ssh allows rce/dos
ВысокаяCVSS 8,1Proof of conceptEPSS 100 %sonicwall · sma 6200 firmware1 июл. 2024 г.
- CVE-2003-046662На этой неделе
Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code,
КритическаяCVSS 9,8Proof of conceptEPSS 78 %redhat · wu ftpd27 авг. 2003 г.
- CVE-2002-133762На этой неделе
Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related t
КритическаяCVSS 10,0Proof of conceptEPSS 73 %sendmail · sendmail7 мар. 2003 г.
- CVE-2003-069460На этой неделе
The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using
КритическаяCVSS 10,0Готовый эксплойтEPSS 66 %sendmail · advanced message server6 окт. 2003 г.
- CVE-1999-004656В плане
Buffer overflow of rlogin program using TERM environmental variable.
КритическаяCVSS 10,0Proof of conceptEPSS 52 %bsdi · bsd os6 февр. 1997 г.
- CVE-2001-055452В плане
Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a
КритическаяCVSS 10,0Proof of conceptEPSS 39 %mit · kerberos14 авг. 2001 г.
- CVE-2014-851751В плане
The fetch_url function in usr.bin/ftp/fetch.c in tnftp, as used in NetBSD 5.1 through 5.1.4, 5.2 through 5.2.2, 6.0 through 6.0.6, and 6.1 t
ВысокаяCVSS 7,5Готовый эксплойтEPSS 69 %netbsd · netbsd17 нояб. 2014 г.
- CVE-1999-001649В плане
Land IP denial of service.
СредняяCVSS 5,0Proof of conceptEPSS 96 %cisco · ios1 дек. 1997 г.
- CVE-1999-000949В плане
Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases.
КритическаяCVSS 10,0Proof of conceptEPSS 29 %data general · dg ux8 апр. 1998 г.
- CVE-2001-024746В плане
Buffer overflows in BSD-based FTP servers allows remote attackers to execute arbitrary commands via a long pattern string containing a {} se
КритическаяCVSS 10,0Proof of conceptEPSS 19 %mit · kerberos 518 июн. 2001 г.
- CVE-2017-100037545В плане
NetBSD maps the run-time link-editor ld.so directly below the stack region, even if ASLR is enabled, this allows attackers to more easily ma
КритическаяCVSS 9,8Proof of conceptEPSS 19 %netbsd · netbsd19 июн. 2017 г.
- CVE-2001-005345В плане
One-byte buffer overflow in replydirname function in BSD-based ftpd allows remote attackers to gain root privileges.
КритическаяCVSS 10,0Proof of conceptEPSS 18 %david madore · ftpd-bsd12 февр. 2001 г.
- CVE-2004-023044В плане
TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connectio
СредняяCVSS 5,0Proof of conceptEPSS 80 %juniper · junos18 авг. 2004 г.
- CVE-2006-430444В плане
Buffer overflow in the sppp driver in FreeBSD 4.11 through 6.1, NetBSD 2.0 through 4.0 beta before 20060823, and OpenBSD 3.8 and 3.9 before
КритическаяCVSS 10,0Эксплойта нетEPSS 12 %freebsd · freebsd23 авг. 2006 г.
- CVE-2014-356643В плане
The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man
НизкаяCVSS 3,4Готовый эксплойтEPSS 100 %openssl · openssl14 окт. 2014 г.
- CVE-2006-665242В плане
Buffer overflow in the glob implementation (glob.c) in libc in NetBSD-current before 20050914, NetBSD 2.* and 3.* before 20061203, and Apple
КритическаяCVSS 9,0Proof of conceptEPSS 20 %apple · mac os x19 дек. 2006 г.
- CVE-1999-051341В плане
ICMP messages to broadcast addresses are allowed, allowing for a Smurf attack that can cause a denial of service.
СредняяCVSS 5,0Proof of conceptEPSS 71 %digital · unix5 янв. 1998 г.
- CVE-2003-000141В плане
Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote attackers to obtain inf
СредняяCVSS 5,0Proof of conceptEPSS 70 %freebsd · freebsd17 янв. 2003 г.
- CVE-2012-021740В плане
The x86-64 kernel system-call functionality in Xen 4.1.2 and earlier, as used in Citrix XenServer 6.0.2 and earlier and other products; Orac
ВысокаяCVSS 7,2Готовый эксплойтEPSS 40 %xen · xen12 июн. 2012 г.
- CVE-2011-289540В плане
The LZW decompressor in (1) the BufCompressedFill function in fontfile/decompress.c in X.Org libXfont before 1.4.4 and (2) compress/compress
КритическаяCVSS 9,3Эксплойта нетEPSS 8 %x · libxfont19 авг. 2011 г.
- CVE-2017-100037840В плане
The NetBSD qsort() function is recursive, and not randomized, an attacker can construct a pathological input array of N elements that causes
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %netbsd · netbsd19 июн. 2017 г.
- CVE-2017-100037440В плане
A flaw exists in NetBSD's implementation of the stack guard page that allows attackers to bypass it resulting in arbitrary code execution us
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %netbsd · netbsd19 июн. 2017 г.
- CVE-2015-821240В плане
CGI handling flaw in bozohttpd in NetBSD 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows remote attackers to execute arbitrary code via
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %netbsd · netbsd19 янв. 2017 г.
- CVE-1999-032340В плане
FreeBSD mmap function allows users to modify append-only or immutable files.
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %freebsd · freebsd20 февр. 1998 г.
- CVE-2008-247639Наблюдать
The IPv6 Neighbor Discovery Protocol (NDP) implementation in (1) FreeBSD 6.3 through 7.1, (2) OpenBSD 4.2 and 4.3, (3) NetBSD, (4) Force10 F
КритическаяCVSS 9,3Эксплойта нетEPSS 7 %force10 · ftos3 окт. 2008 г.