Записи OpenBSD
360 опубликованных записей вендора openbsd.
Профиль для исследователя
- Попали в KEV
- 1 · 0,3 %
- С эксплойтом
- 7 · 1,9 %
- Pre-auth RCE
- 44
- С записью об исправлении
- 42,2 %
- Медиана: публикация → KEV
- 786 дн.
Повторяющиеся классы
- CWE-264 Permissions, Privileges, and Access Controls14
- CWE-20 Improper Input Validation14
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor10
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer9
- CWE-399 Resource Management Errors9
- CWE-287 Improper Authentication9
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
360 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
99Срочно | CVE-2020-7247Готовый эксплойт | smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary coopenbsd · opensmtpd · CWE-78 | Критическая9,8 | KEV | 99,0 % | 29 янв. 2020 г. |
63На этой неделе | CVE-2023-38408Proof of concept | The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if openbsd · openssh · CWE-428 | Критическая9,8 | — | 79,7 % | 19 июл. 2023 г. |
62На этой неделе | CVE-2024-6387Proof of concept | Openssh: regresshion - race condition in ssh allows rce/dossonicwall · sma 6200 firmware · CWE-364 | Высокая8,1 | — | 99,5 % | 1 июл. 2024 г. |
62На этой неделе | CVE-2003-0466Proof of concept | Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code,redhat · wu ftpd · CWE-193 | Критическая9,8 | — | 78,1 % | 27 авг. 2003 г. |
56В плане | CVE-2002-0391Эксплойта нет | Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including disun · solaris · CWE-190 | Критическая9,8 | — | 58,1 % | 12 авг. 2002 г. |
53В плане | CVE-2023-25136Proof of concept | OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling.openbsd · openssh · CWE-415 | Средняя6,5 | — | 89,7 % | 3 февр. 2023 г. |
52В плане | CVE-2007-5365Proof of concept | Stack-based buffer overflow in the cons_options function in options.c in dhcpd in OpenBSD 4.0 through 4.2, and some other dhcpd implementatiopenbsd · openbsd · CWE-119 | Высокая7,2 | — | 80,3 % | 11 окт. 2007 г. |
52В плане | CVE-2001-0554Proof of concept | Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a mit · kerberos · CWE-120 | Критическая10,0 | — | 38,7 % | 14 авг. 2001 г. |
51В плане | CVE-2018-15473Готовый эксплойт | OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after openbsd · openssh · CWE-362 | Средняя5,3 | — | 98,6 % | 17 авг. 2018 г. |
51В плане | CVE-2023-48795Proof of concept | The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypasssh · ssh · CWE-354 | Средняя5,9 | — | 93,5 % | 18 дек. 2023 г. |
50В плане | CVE-2016-6210Готовый эксплойт | sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static password when the usopenbsd · openssh · CWE-200 | Средняя5,9 | — | 88,9 % | 13 февр. 2017 г. |
50В плане | CVE-2004-0492Эксплойта нет | Heap-based buffer overflow in proxy_util.c for mod_proxy in Apache 1.3.25 to 1.3.31 allows remote attackers to cause a denial of service (prapache · http server | Критическая10,0 | — | 33,6 % | 6 авг. 2004 г. |
50В плане | CVE-2001-0144Proof of concept | CORE SDI SSH1 CRC-32 compensation attack detector allows remote attackers to execute arbitrary commands on an SSH server or client via an inssh · ssh | Критическая10,0 | — | 32,4 % | 12 мар. 2001 г. |
48В плане | CVE-2016-6515Proof of concept | The auth_password function in auth-passwd.c in sshd in OpenSSH before 7.3 does not limit password lengths for password authentication, whichopenbsd · openssh · CWE-20 | Высокая7,5 | — | 58,6 % | 7 авг. 2016 г. |
48В плане | CVE-2002-0640Proof of concept | Buffer overflow in sshd in OpenSSH 2.3.1 through 3.3 may allow remote attackers to execute arbitrary code via a large number of responses duopenbsd · openssh | Критическая10,0 | — | 27,3 % | 3 июл. 2002 г. |
47В плане | CVE-2004-0084Proof of concept | Buffer overflow in the ReadFontAlias function in XFree86 4.1.0 to 4.3.0, when using the CopyISOLatin1Lowered function, allows local or remotxfree86 project · x11r6 | Критическая10,0 | — | 24,9 % | 3 мар. 2004 г. |
46В плане | CVE-2004-0083Proof of concept | Buffer overflow in ReadFontAlias from dirfile.c of XFree86 4.1.0 through 4.3.0 allows local users and remote attackers to execute arbitrary xfree86 project · x11r6 | Критическая10,0 | — | 21,2 % | 3 мар. 2004 г. |
46В плане | CVE-2001-0247Proof of concept | Buffer overflows in BSD-based FTP servers allows remote attackers to execute arbitrary commands via a long pattern string containing a {} semit · kerberos 5 | Критическая10,0 | — | 19,3 % | 18 июн. 2001 г. |
45В плане | CVE-2005-0356Proof of concept | Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackecisco · agent desktop | Средняя5,0 | — | 82,8 % | 31 мая 2005 г. |
45В плане | CVE-2016-0777Proof of concept | The resend_bytes function in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2 allows remote servers to obtain sensitsophos · unified threat management software · CWE-200 | Средняя6,5 | — | 63,5 % | 14 янв. 2016 г. |
45В плане | CVE-2006-5051Proof of concept | Signal handler race condition in OpenSSH before 4.4 allows remote attackers to cause a denial of service (crash), and possibly execute arbitopenbsd · openssh · CWE-415 | Высокая8,1 | — | 45,0 % | 27 сент. 2006 г. |
45В плане | CVE-2001-0053Proof of concept | One-byte buffer overflow in replydirname function in BSD-based ftpd allows remote attackers to gain root privileges.david madore · ftpd-bsd | Критическая10,0 | — | 17,9 % | 12 февр. 2001 г. |
45В плане | CVE-2007-1365Proof of concept | Buffer overflow in kern/uipc_mbuf2.c in OpenBSD 3.9 and 4.0 allows remote attackers to execute arbitrary code via fragmented IPv6 packets duopenbsd · openbsd | Критическая10,0 | — | 17,8 % | 10 мар. 2007 г. |
44В плане | CVE-2002-0639Эксплойта нет | Integer overflow in sshd in OpenSSH 2.9.9 through 3.3 allows remote attackers to execute arbitrary code during challenge response authenticaopenbsd · openssh · CWE-190 | Критическая9,8 | — | 18,3 % | 3 июл. 2002 г. |
44В плане | CVE-2004-0416Proof of concept | Double free vulnerability for the error_prog_name string in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attackercvs · cvs · CWE-119 | Критическая10,0 | — | 13,2 % | 6 авг. 2004 г. |
- CVE-2020-724799Срочно
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary co
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %openbsd · opensmtpd29 янв. 2020 г.
- CVE-2023-3840863На этой неделе
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if
КритическаяCVSS 9,8Proof of conceptEPSS 80 %openbsd · openssh19 июл. 2023 г.
- CVE-2024-638762На этой неделе
Openssh: regresshion - race condition in ssh allows rce/dos
ВысокаяCVSS 8,1Proof of conceptEPSS 100 %sonicwall · sma 6200 firmware1 июл. 2024 г.
- CVE-2003-046662На этой неделе
Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code,
КритическаяCVSS 9,8Proof of conceptEPSS 78 %redhat · wu ftpd27 авг. 2003 г.
- CVE-2002-039156В плане
Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including di
КритическаяCVSS 9,8Эксплойта нетEPSS 58 %sun · solaris12 авг. 2002 г.
- CVE-2023-2513653В плане
OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling.
СредняяCVSS 6,5Proof of conceptEPSS 90 %openbsd · openssh3 февр. 2023 г.
- CVE-2007-536552В плане
Stack-based buffer overflow in the cons_options function in options.c in dhcpd in OpenBSD 4.0 through 4.2, and some other dhcpd implementati
ВысокаяCVSS 7,2Proof of conceptEPSS 80 %openbsd · openbsd11 окт. 2007 г.
- CVE-2001-055452В плане
Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a
КритическаяCVSS 10,0Proof of conceptEPSS 39 %mit · kerberos14 авг. 2001 г.
- CVE-2018-1547351В плане
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after
СредняяCVSS 5,3Готовый эксплойтEPSS 99 %openbsd · openssh17 авг. 2018 г.
- CVE-2023-4879551В плане
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypas
СредняяCVSS 5,9Proof of conceptEPSS 94 %ssh · ssh18 дек. 2023 г.
- CVE-2016-621050В плане
sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static password when the us
СредняяCVSS 5,9Готовый эксплойтEPSS 89 %openbsd · openssh13 февр. 2017 г.
- CVE-2004-049250В плане
Heap-based buffer overflow in proxy_util.c for mod_proxy in Apache 1.3.25 to 1.3.31 allows remote attackers to cause a denial of service (pr
КритическаяCVSS 10,0Эксплойта нетEPSS 34 %apache · http server6 авг. 2004 г.
- CVE-2001-014450В плане
CORE SDI SSH1 CRC-32 compensation attack detector allows remote attackers to execute arbitrary commands on an SSH server or client via an in
КритическаяCVSS 10,0Proof of conceptEPSS 32 %ssh · ssh12 мар. 2001 г.
- CVE-2016-651548В плане
The auth_password function in auth-passwd.c in sshd in OpenSSH before 7.3 does not limit password lengths for password authentication, which
ВысокаяCVSS 7,5Proof of conceptEPSS 59 %openbsd · openssh7 авг. 2016 г.
- CVE-2002-064048В плане
Buffer overflow in sshd in OpenSSH 2.3.1 through 3.3 may allow remote attackers to execute arbitrary code via a large number of responses du
КритическаяCVSS 10,0Proof of conceptEPSS 27 %openbsd · openssh3 июл. 2002 г.
- CVE-2004-008447В плане
Buffer overflow in the ReadFontAlias function in XFree86 4.1.0 to 4.3.0, when using the CopyISOLatin1Lowered function, allows local or remot
КритическаяCVSS 10,0Proof of conceptEPSS 25 %xfree86 project · x11r63 мар. 2004 г.
- CVE-2004-008346В плане
Buffer overflow in ReadFontAlias from dirfile.c of XFree86 4.1.0 through 4.3.0 allows local users and remote attackers to execute arbitrary
КритическаяCVSS 10,0Proof of conceptEPSS 21 %xfree86 project · x11r63 мар. 2004 г.
- CVE-2001-024746В плане
Buffer overflows in BSD-based FTP servers allows remote attackers to execute arbitrary commands via a long pattern string containing a {} se
КритическаяCVSS 10,0Proof of conceptEPSS 19 %mit · kerberos 518 июн. 2001 г.
- CVE-2005-035645В плане
Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attacke
СредняяCVSS 5,0Proof of conceptEPSS 83 %cisco · agent desktop31 мая 2005 г.
- CVE-2016-077745В плане
The resend_bytes function in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2 allows remote servers to obtain sensit
СредняяCVSS 6,5Proof of conceptEPSS 63 %sophos · unified threat management software14 янв. 2016 г.
- CVE-2006-505145В плане
Signal handler race condition in OpenSSH before 4.4 allows remote attackers to cause a denial of service (crash), and possibly execute arbit
ВысокаяCVSS 8,1Proof of conceptEPSS 45 %openbsd · openssh27 сент. 2006 г.
- CVE-2001-005345В плане
One-byte buffer overflow in replydirname function in BSD-based ftpd allows remote attackers to gain root privileges.
КритическаяCVSS 10,0Proof of conceptEPSS 18 %david madore · ftpd-bsd12 февр. 2001 г.
- CVE-2007-136545В плане
Buffer overflow in kern/uipc_mbuf2.c in OpenBSD 3.9 and 4.0 allows remote attackers to execute arbitrary code via fragmented IPv6 packets du
КритическаяCVSS 10,0Proof of conceptEPSS 18 %openbsd · openbsd10 мар. 2007 г.
- CVE-2002-063944В плане
Integer overflow in sshd in OpenSSH 2.9.9 through 3.3 allows remote attackers to execute arbitrary code during challenge response authentica
КритическаяCVSS 9,8Эксплойта нетEPSS 18 %openbsd · openssh3 июл. 2002 г.
- CVE-2004-041644В плане
Double free vulnerability for the error_prog_name string in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attacker
КритическаяCVSS 10,0Proof of conceptEPSS 13 %cvs · cvs6 авг. 2004 г.