İçeriğe atla
Noroxi

openbsd kayıtları

openbsd üreticisine ait 360 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
1 · %0,3
Silahlaştırılmış
7 · %1,9
Pre-auth RCE
44
Düzeltme kaydı olan
%42,2
Yayından KEV’e ortanca
786 gün

Tüm kayıtlar

360 kayıt
  • smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary co

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99

    openbsd · opensmtpd29 Oca 2020

  • CVE-2023-38408
    63Bu hafta

    The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if

    KritikCVSS 9,8Kavram kanıtıEPSS %80

    openbsd · openssh19 Tem 2023

  • CVE-2024-6387
    62Bu hafta

    Openssh: regresshion - race condition in ssh allows rce/dos

    YüksekCVSS 8,1Kavram kanıtıEPSS %100

    sonicwall · sma 6200 firmware1 Tem 2024

  • CVE-2003-0466
    62Bu hafta

    Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code,

    KritikCVSS 9,8Kavram kanıtıEPSS %78

    redhat · wu ftpd27 Ağu 2003

  • CVE-2002-0391
    56Planlayın

    Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including di

    KritikCVSS 9,8İstismar yokEPSS %58

    sun · solaris12 Ağu 2002

  • CVE-2023-25136
    53Planlayın

    OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling.

    OrtaCVSS 6,5Kavram kanıtıEPSS %90

    openbsd · openssh3 Şub 2023

  • CVE-2007-5365
    52Planlayın

    Stack-based buffer overflow in the cons_options function in options.c in dhcpd in OpenBSD 4.0 through 4.2, and some other dhcpd implementati

    YüksekCVSS 7,2Kavram kanıtıEPSS %80

    openbsd · openbsd11 Eki 2007

  • CVE-2001-0554
    52Planlayın

    Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a

    KritikCVSS 10,0Kavram kanıtıEPSS %39

    mit · kerberos14 Ağu 2001

  • CVE-2018-15473
    51Planlayın

    OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after

    OrtaCVSS 5,3SilahlaştırılmışEPSS %99

    openbsd · openssh17 Ağu 2018

  • CVE-2023-48795
    51Planlayın

    The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypas

    OrtaCVSS 5,9Kavram kanıtıEPSS %93

    ssh · ssh18 Ara 2023

  • CVE-2016-6210
    50Planlayın

    sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static password when the us

    OrtaCVSS 5,9SilahlaştırılmışEPSS %89

    openbsd · openssh13 Şub 2017

  • CVE-2004-0492
    50Planlayın

    Heap-based buffer overflow in proxy_util.c for mod_proxy in Apache 1.3.25 to 1.3.31 allows remote attackers to cause a denial of service (pr

    KritikCVSS 10,0İstismar yokEPSS %34

    apache · http server6 Ağu 2004

  • CVE-2001-0144
    50Planlayın

    CORE SDI SSH1 CRC-32 compensation attack detector allows remote attackers to execute arbitrary commands on an SSH server or client via an in

    KritikCVSS 10,0Kavram kanıtıEPSS %32

    ssh · ssh12 Mar 2001

  • CVE-2016-6515
    48Planlayın

    The auth_password function in auth-passwd.c in sshd in OpenSSH before 7.3 does not limit password lengths for password authentication, which

    YüksekCVSS 7,5Kavram kanıtıEPSS %59

    openbsd · openssh7 Ağu 2016

  • CVE-2002-0640
    48Planlayın

    Buffer overflow in sshd in OpenSSH 2.3.1 through 3.3 may allow remote attackers to execute arbitrary code via a large number of responses du

    KritikCVSS 10,0Kavram kanıtıEPSS %27

    openbsd · openssh3 Tem 2002

  • CVE-2004-0084
    47Planlayın

    Buffer overflow in the ReadFontAlias function in XFree86 4.1.0 to 4.3.0, when using the CopyISOLatin1Lowered function, allows local or remot

    KritikCVSS 10,0Kavram kanıtıEPSS %25

    xfree86 project · x11r63 Mar 2004

  • CVE-2004-0083
    46Planlayın

    Buffer overflow in ReadFontAlias from dirfile.c of XFree86 4.1.0 through 4.3.0 allows local users and remote attackers to execute arbitrary

    KritikCVSS 10,0Kavram kanıtıEPSS %21

    xfree86 project · x11r63 Mar 2004

  • CVE-2001-0247
    46Planlayın

    Buffer overflows in BSD-based FTP servers allows remote attackers to execute arbitrary commands via a long pattern string containing a {} se

    KritikCVSS 10,0Kavram kanıtıEPSS %19

    mit · kerberos 518 Haz 2001

  • CVE-2005-0356
    45Planlayın

    Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attacke

    OrtaCVSS 5,0Kavram kanıtıEPSS %83

    cisco · agent desktop31 May 2005

  • CVE-2016-0777
    45Planlayın

    The resend_bytes function in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2 allows remote servers to obtain sensit

    OrtaCVSS 6,5Kavram kanıtıEPSS %63

    sophos · unified threat management software14 Oca 2016

  • CVE-2006-5051
    45Planlayın

    Signal handler race condition in OpenSSH before 4.4 allows remote attackers to cause a denial of service (crash), and possibly execute arbit

    YüksekCVSS 8,1Kavram kanıtıEPSS %45

    openbsd · openssh27 Eyl 2006

  • CVE-2001-0053
    45Planlayın

    One-byte buffer overflow in replydirname function in BSD-based ftpd allows remote attackers to gain root privileges.

    KritikCVSS 10,0Kavram kanıtıEPSS %18

    david madore · ftpd-bsd12 Şub 2001

  • CVE-2007-1365
    45Planlayın

    Buffer overflow in kern/uipc_mbuf2.c in OpenBSD 3.9 and 4.0 allows remote attackers to execute arbitrary code via fragmented IPv6 packets du

    KritikCVSS 10,0Kavram kanıtıEPSS %18

    openbsd · openbsd10 Mar 2007

  • CVE-2002-0639
    44Planlayın

    Integer overflow in sshd in OpenSSH 2.9.9 through 3.3 allows remote attackers to execute arbitrary code during challenge response authentica

    KritikCVSS 9,8İstismar yokEPSS %18

    openbsd · openssh3 Tem 2002

  • CVE-2004-0416
    44Planlayın

    Double free vulnerability for the error_prog_name string in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attacker

    KritikCVSS 10,0Kavram kanıtıEPSS %13

    cvs · cvs6 Ağu 2004