openbsd kayıtları
openbsd üreticisine ait 360 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 1 · %0,3
- Silahlaştırılmış
- 7 · %1,9
- Pre-auth RCE
- 44
- Düzeltme kaydı olan
- %42,2
- Yayından KEV’e ortanca
- 786 gün
Tekrar eden sınıflar
- CWE-264 Permissions, Privileges, and Access Controls14
- CWE-20 Improper Input Validation14
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor10
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer9
- CWE-399 Resource Management Errors9
- CWE-287 Improper Authentication9
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
360 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
99Hemen | CVE-2020-7247Silahlaştırılmış | smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary coopenbsd · opensmtpd · CWE-78 | Kritik9,8 | KEV | %99,0 | 29 Oca 2020 |
63Bu hafta | CVE-2023-38408Kavram kanıtı | The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if openbsd · openssh · CWE-428 | Kritik9,8 | — | %79,7 | 19 Tem 2023 |
62Bu hafta | CVE-2024-6387Kavram kanıtı | Openssh: regresshion - race condition in ssh allows rce/dossonicwall · sma 6200 firmware · CWE-364 | Yüksek8,1 | — | %99,5 | 1 Tem 2024 |
62Bu hafta | CVE-2003-0466Kavram kanıtı | Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code,redhat · wu ftpd · CWE-193 | Kritik9,8 | — | %78,1 | 27 Ağu 2003 |
56Planlayın | CVE-2002-0391İstismar yok | Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including disun · solaris · CWE-190 | Kritik9,8 | — | %58,1 | 12 Ağu 2002 |
53Planlayın | CVE-2023-25136Kavram kanıtı | OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling.openbsd · openssh · CWE-415 | Orta6,5 | — | %89,7 | 3 Şub 2023 |
52Planlayın | CVE-2007-5365Kavram kanıtı | Stack-based buffer overflow in the cons_options function in options.c in dhcpd in OpenBSD 4.0 through 4.2, and some other dhcpd implementatiopenbsd · openbsd · CWE-119 | Yüksek7,2 | — | %80,3 | 11 Eki 2007 |
52Planlayın | CVE-2001-0554Kavram kanıtı | Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a mit · kerberos · CWE-120 | Kritik10,0 | — | %38,7 | 14 Ağu 2001 |
51Planlayın | CVE-2018-15473Silahlaştırılmış | OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after openbsd · openssh · CWE-362 | Orta5,3 | — | %98,6 | 17 Ağu 2018 |
51Planlayın | CVE-2023-48795Kavram kanıtı | The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypasssh · ssh · CWE-354 | Orta5,9 | — | %93,3 | 18 Ara 2023 |
50Planlayın | CVE-2016-6210Silahlaştırılmış | sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static password when the usopenbsd · openssh · CWE-200 | Orta5,9 | — | %88,9 | 13 Şub 2017 |
50Planlayın | CVE-2004-0492İstismar yok | Heap-based buffer overflow in proxy_util.c for mod_proxy in Apache 1.3.25 to 1.3.31 allows remote attackers to cause a denial of service (prapache · http server | Kritik10,0 | — | %33,6 | 6 Ağu 2004 |
50Planlayın | CVE-2001-0144Kavram kanıtı | CORE SDI SSH1 CRC-32 compensation attack detector allows remote attackers to execute arbitrary commands on an SSH server or client via an inssh · ssh | Kritik10,0 | — | %32,4 | 12 Mar 2001 |
48Planlayın | CVE-2016-6515Kavram kanıtı | The auth_password function in auth-passwd.c in sshd in OpenSSH before 7.3 does not limit password lengths for password authentication, whichopenbsd · openssh · CWE-20 | Yüksek7,5 | — | %58,6 | 7 Ağu 2016 |
48Planlayın | CVE-2002-0640Kavram kanıtı | Buffer overflow in sshd in OpenSSH 2.3.1 through 3.3 may allow remote attackers to execute arbitrary code via a large number of responses duopenbsd · openssh | Kritik10,0 | — | %27,3 | 3 Tem 2002 |
47Planlayın | CVE-2004-0084Kavram kanıtı | Buffer overflow in the ReadFontAlias function in XFree86 4.1.0 to 4.3.0, when using the CopyISOLatin1Lowered function, allows local or remotxfree86 project · x11r6 | Kritik10,0 | — | %24,9 | 3 Mar 2004 |
46Planlayın | CVE-2004-0083Kavram kanıtı | Buffer overflow in ReadFontAlias from dirfile.c of XFree86 4.1.0 through 4.3.0 allows local users and remote attackers to execute arbitrary xfree86 project · x11r6 | Kritik10,0 | — | %21,2 | 3 Mar 2004 |
46Planlayın | CVE-2001-0247Kavram kanıtı | Buffer overflows in BSD-based FTP servers allows remote attackers to execute arbitrary commands via a long pattern string containing a {} semit · kerberos 5 | Kritik10,0 | — | %19,3 | 18 Haz 2001 |
45Planlayın | CVE-2005-0356Kavram kanıtı | Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackecisco · agent desktop | Orta5,0 | — | %82,8 | 31 May 2005 |
45Planlayın | CVE-2016-0777Kavram kanıtı | The resend_bytes function in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2 allows remote servers to obtain sensitsophos · unified threat management software · CWE-200 | Orta6,5 | — | %63,5 | 14 Oca 2016 |
45Planlayın | CVE-2006-5051Kavram kanıtı | Signal handler race condition in OpenSSH before 4.4 allows remote attackers to cause a denial of service (crash), and possibly execute arbitopenbsd · openssh · CWE-415 | Yüksek8,1 | — | %45,0 | 27 Eyl 2006 |
45Planlayın | CVE-2001-0053Kavram kanıtı | One-byte buffer overflow in replydirname function in BSD-based ftpd allows remote attackers to gain root privileges.david madore · ftpd-bsd | Kritik10,0 | — | %17,9 | 12 Şub 2001 |
45Planlayın | CVE-2007-1365Kavram kanıtı | Buffer overflow in kern/uipc_mbuf2.c in OpenBSD 3.9 and 4.0 allows remote attackers to execute arbitrary code via fragmented IPv6 packets duopenbsd · openbsd | Kritik10,0 | — | %17,8 | 10 Mar 2007 |
44Planlayın | CVE-2002-0639İstismar yok | Integer overflow in sshd in OpenSSH 2.9.9 through 3.3 allows remote attackers to execute arbitrary code during challenge response authenticaopenbsd · openssh · CWE-190 | Kritik9,8 | — | %18,3 | 3 Tem 2002 |
44Planlayın | CVE-2004-0416Kavram kanıtı | Double free vulnerability for the error_prog_name string in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attackercvs · cvs · CWE-119 | Kritik10,0 | — | %13,2 | 6 Ağu 2004 |
- CVE-2020-724799Hemen
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary co
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99openbsd · opensmtpd29 Oca 2020
- CVE-2023-3840863Bu hafta
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if
KritikCVSS 9,8Kavram kanıtıEPSS %80openbsd · openssh19 Tem 2023
- CVE-2024-638762Bu hafta
Openssh: regresshion - race condition in ssh allows rce/dos
YüksekCVSS 8,1Kavram kanıtıEPSS %100sonicwall · sma 6200 firmware1 Tem 2024
- CVE-2003-046662Bu hafta
Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code,
KritikCVSS 9,8Kavram kanıtıEPSS %78redhat · wu ftpd27 Ağu 2003
- CVE-2002-039156Planlayın
Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including di
KritikCVSS 9,8İstismar yokEPSS %58sun · solaris12 Ağu 2002
- CVE-2023-2513653Planlayın
OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling.
OrtaCVSS 6,5Kavram kanıtıEPSS %90openbsd · openssh3 Şub 2023
- CVE-2007-536552Planlayın
Stack-based buffer overflow in the cons_options function in options.c in dhcpd in OpenBSD 4.0 through 4.2, and some other dhcpd implementati
YüksekCVSS 7,2Kavram kanıtıEPSS %80openbsd · openbsd11 Eki 2007
- CVE-2001-055452Planlayın
Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a
KritikCVSS 10,0Kavram kanıtıEPSS %39mit · kerberos14 Ağu 2001
- CVE-2018-1547351Planlayın
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after
OrtaCVSS 5,3SilahlaştırılmışEPSS %99openbsd · openssh17 Ağu 2018
- CVE-2023-4879551Planlayın
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypas
OrtaCVSS 5,9Kavram kanıtıEPSS %93ssh · ssh18 Ara 2023
- CVE-2016-621050Planlayın
sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static password when the us
OrtaCVSS 5,9SilahlaştırılmışEPSS %89openbsd · openssh13 Şub 2017
- CVE-2004-049250Planlayın
Heap-based buffer overflow in proxy_util.c for mod_proxy in Apache 1.3.25 to 1.3.31 allows remote attackers to cause a denial of service (pr
KritikCVSS 10,0İstismar yokEPSS %34apache · http server6 Ağu 2004
- CVE-2001-014450Planlayın
CORE SDI SSH1 CRC-32 compensation attack detector allows remote attackers to execute arbitrary commands on an SSH server or client via an in
KritikCVSS 10,0Kavram kanıtıEPSS %32ssh · ssh12 Mar 2001
- CVE-2016-651548Planlayın
The auth_password function in auth-passwd.c in sshd in OpenSSH before 7.3 does not limit password lengths for password authentication, which
YüksekCVSS 7,5Kavram kanıtıEPSS %59openbsd · openssh7 Ağu 2016
- CVE-2002-064048Planlayın
Buffer overflow in sshd in OpenSSH 2.3.1 through 3.3 may allow remote attackers to execute arbitrary code via a large number of responses du
KritikCVSS 10,0Kavram kanıtıEPSS %27openbsd · openssh3 Tem 2002
- CVE-2004-008447Planlayın
Buffer overflow in the ReadFontAlias function in XFree86 4.1.0 to 4.3.0, when using the CopyISOLatin1Lowered function, allows local or remot
KritikCVSS 10,0Kavram kanıtıEPSS %25xfree86 project · x11r63 Mar 2004
- CVE-2004-008346Planlayın
Buffer overflow in ReadFontAlias from dirfile.c of XFree86 4.1.0 through 4.3.0 allows local users and remote attackers to execute arbitrary
KritikCVSS 10,0Kavram kanıtıEPSS %21xfree86 project · x11r63 Mar 2004
- CVE-2001-024746Planlayın
Buffer overflows in BSD-based FTP servers allows remote attackers to execute arbitrary commands via a long pattern string containing a {} se
KritikCVSS 10,0Kavram kanıtıEPSS %19mit · kerberos 518 Haz 2001
- CVE-2005-035645Planlayın
Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attacke
OrtaCVSS 5,0Kavram kanıtıEPSS %83cisco · agent desktop31 May 2005
- CVE-2016-077745Planlayın
The resend_bytes function in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2 allows remote servers to obtain sensit
OrtaCVSS 6,5Kavram kanıtıEPSS %63sophos · unified threat management software14 Oca 2016
- CVE-2006-505145Planlayın
Signal handler race condition in OpenSSH before 4.4 allows remote attackers to cause a denial of service (crash), and possibly execute arbit
YüksekCVSS 8,1Kavram kanıtıEPSS %45openbsd · openssh27 Eyl 2006
- CVE-2001-005345Planlayın
One-byte buffer overflow in replydirname function in BSD-based ftpd allows remote attackers to gain root privileges.
KritikCVSS 10,0Kavram kanıtıEPSS %18david madore · ftpd-bsd12 Şub 2001
- CVE-2007-136545Planlayın
Buffer overflow in kern/uipc_mbuf2.c in OpenBSD 3.9 and 4.0 allows remote attackers to execute arbitrary code via fragmented IPv6 packets du
KritikCVSS 10,0Kavram kanıtıEPSS %18openbsd · openbsd10 Mar 2007
- CVE-2002-063944Planlayın
Integer overflow in sshd in OpenSSH 2.9.9 through 3.3 allows remote attackers to execute arbitrary code during challenge response authentica
KritikCVSS 9,8İstismar yokEPSS %18openbsd · openssh3 Tem 2002
- CVE-2004-041644Planlayın
Double free vulnerability for the error_prog_name string in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attacker
KritikCVSS 10,0Kavram kanıtıEPSS %13cvs · cvs6 Ağu 2004