Перейти к содержимому
Noroxi

Записи OpenBSD

360 опубликованных записей вендора openbsd.

Профиль для исследователя

Попали в KEV
1 · 0,3 %
С эксплойтом
7 · 1,9 %
Pre-auth RCE
44
С записью об исправлении
42,2 %
Медиана: публикация → KEV
786 дн.

Все записи

360 записей
  • CVE-2020-7247
    99Срочно

    smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary co

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %

    openbsd · opensmtpd29 янв. 2020 г.

  • CVE-2023-38408
    63На этой неделе

    The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if

    КритическаяCVSS 9,8Proof of conceptEPSS 80 %

    openbsd · openssh19 июл. 2023 г.

  • CVE-2024-6387
    62На этой неделе

    Openssh: regresshion - race condition in ssh allows rce/dos

    ВысокаяCVSS 8,1Proof of conceptEPSS 100 %

    sonicwall · sma 6200 firmware1 июл. 2024 г.

  • CVE-2003-0466
    62На этой неделе

    Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code,

    КритическаяCVSS 9,8Proof of conceptEPSS 78 %

    redhat · wu ftpd27 авг. 2003 г.

  • CVE-2002-0391
    56В плане

    Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including di

    КритическаяCVSS 9,8Эксплойта нетEPSS 58 %

    sun · solaris12 авг. 2002 г.

  • CVE-2023-25136
    53В плане

    OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling.

    СредняяCVSS 6,5Proof of conceptEPSS 90 %

    openbsd · openssh3 февр. 2023 г.

  • CVE-2007-5365
    52В плане

    Stack-based buffer overflow in the cons_options function in options.c in dhcpd in OpenBSD 4.0 through 4.2, and some other dhcpd implementati

    ВысокаяCVSS 7,2Proof of conceptEPSS 80 %

    openbsd · openbsd11 окт. 2007 г.

  • CVE-2001-0554
    52В плане

    Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a

    КритическаяCVSS 10,0Proof of conceptEPSS 39 %

    mit · kerberos14 авг. 2001 г.

  • CVE-2018-15473
    51В плане

    OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after

    СредняяCVSS 5,3Готовый эксплойтEPSS 99 %

    openbsd · openssh17 авг. 2018 г.

  • CVE-2023-48795
    51В плане

    The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypas

    СредняяCVSS 5,9Proof of conceptEPSS 94 %

    ssh · ssh18 дек. 2023 г.

  • CVE-2016-6210
    50В плане

    sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static password when the us

    СредняяCVSS 5,9Готовый эксплойтEPSS 89 %

    openbsd · openssh13 февр. 2017 г.

  • CVE-2004-0492
    50В плане

    Heap-based buffer overflow in proxy_util.c for mod_proxy in Apache 1.3.25 to 1.3.31 allows remote attackers to cause a denial of service (pr

    КритическаяCVSS 10,0Эксплойта нетEPSS 34 %

    apache · http server6 авг. 2004 г.

  • CVE-2001-0144
    50В плане

    CORE SDI SSH1 CRC-32 compensation attack detector allows remote attackers to execute arbitrary commands on an SSH server or client via an in

    КритическаяCVSS 10,0Proof of conceptEPSS 32 %

    ssh · ssh12 мар. 2001 г.

  • CVE-2016-6515
    48В плане

    The auth_password function in auth-passwd.c in sshd in OpenSSH before 7.3 does not limit password lengths for password authentication, which

    ВысокаяCVSS 7,5Proof of conceptEPSS 59 %

    openbsd · openssh7 авг. 2016 г.

  • CVE-2002-0640
    48В плане

    Buffer overflow in sshd in OpenSSH 2.3.1 through 3.3 may allow remote attackers to execute arbitrary code via a large number of responses du

    КритическаяCVSS 10,0Proof of conceptEPSS 27 %

    openbsd · openssh3 июл. 2002 г.

  • CVE-2004-0084
    47В плане

    Buffer overflow in the ReadFontAlias function in XFree86 4.1.0 to 4.3.0, when using the CopyISOLatin1Lowered function, allows local or remot

    КритическаяCVSS 10,0Proof of conceptEPSS 25 %

    xfree86 project · x11r63 мар. 2004 г.

  • CVE-2004-0083
    46В плане

    Buffer overflow in ReadFontAlias from dirfile.c of XFree86 4.1.0 through 4.3.0 allows local users and remote attackers to execute arbitrary

    КритическаяCVSS 10,0Proof of conceptEPSS 21 %

    xfree86 project · x11r63 мар. 2004 г.

  • CVE-2001-0247
    46В плане

    Buffer overflows in BSD-based FTP servers allows remote attackers to execute arbitrary commands via a long pattern string containing a {} se

    КритическаяCVSS 10,0Proof of conceptEPSS 19 %

    mit · kerberos 518 июн. 2001 г.

  • CVE-2005-0356
    45В плане

    Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attacke

    СредняяCVSS 5,0Proof of conceptEPSS 83 %

    cisco · agent desktop31 мая 2005 г.

  • CVE-2016-0777
    45В плане

    The resend_bytes function in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2 allows remote servers to obtain sensit

    СредняяCVSS 6,5Proof of conceptEPSS 63 %

    sophos · unified threat management software14 янв. 2016 г.

  • CVE-2006-5051
    45В плане

    Signal handler race condition in OpenSSH before 4.4 allows remote attackers to cause a denial of service (crash), and possibly execute arbit

    ВысокаяCVSS 8,1Proof of conceptEPSS 45 %

    openbsd · openssh27 сент. 2006 г.

  • CVE-2001-0053
    45В плане

    One-byte buffer overflow in replydirname function in BSD-based ftpd allows remote attackers to gain root privileges.

    КритическаяCVSS 10,0Proof of conceptEPSS 18 %

    david madore · ftpd-bsd12 февр. 2001 г.

  • CVE-2007-1365
    45В плане

    Buffer overflow in kern/uipc_mbuf2.c in OpenBSD 3.9 and 4.0 allows remote attackers to execute arbitrary code via fragmented IPv6 packets du

    КритическаяCVSS 10,0Proof of conceptEPSS 18 %

    openbsd · openbsd10 мар. 2007 г.

  • CVE-2002-0639
    44В плане

    Integer overflow in sshd in OpenSSH 2.9.9 through 3.3 allows remote attackers to execute arbitrary code during challenge response authentica

    КритическаяCVSS 9,8Эксплойта нетEPSS 18 %

    openbsd · openssh3 июл. 2002 г.

  • CVE-2004-0416
    44В плане

    Double free vulnerability for the error_prog_name string in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attacker

    КритическаяCVSS 10,0Proof of conceptEPSS 13 %

    cvs · cvs6 авг. 2004 г.