Show filters
19 Total Results
Displaying 11-19 of 19
Sort by:
Attacker Value
Unknown
CVE-2002-2092
Disclosure Date: December 31, 2002 (last updated October 03, 2023)
Race condition in exec in OpenBSD 4.0 and earlier, NetBSD 1.5.2 and earlier, and FreeBSD 4.4 and earlier allows local users to gain privileges by attaching a debugger to a process before the kernel has determined that the process is setuid or setgid.
0
Attacker Value
Unknown
CVE-2002-1915
Disclosure Date: December 31, 2002 (last updated February 09, 2024)
tip on multiple BSD-based operating systems allows local users to cause a denial of service (execution prevention) by using flock() to lock the /var/log/acculog file.
0
Attacker Value
Unknown
CVE-2002-2280
Disclosure Date: December 31, 2002 (last updated October 03, 2023)
syslogd on OpenBSD 2.9 through 3.2 does not change the source IP address of syslog packets when the machine's IP addressed is changed without rebooting, e.g. via ifconfig, which can cause incorrect information to be sent to the syslog server.
0
Attacker Value
Unknown
CVE-2002-0766
Disclosure Date: August 12, 2002 (last updated October 03, 2023)
OpenBSD 2.9 through 3.1 allows local users to cause a denial of service (resource exhaustion) and gain root privileges by filling the kernel's file descriptor table and closing file descriptors 0, 1, or 2 before executing a privileged process, which is not properly handled when OpenBSD fails to open an alternate descriptor.
0
Attacker Value
Unknown
CVE-2002-0542
Disclosure Date: July 03, 2002 (last updated October 03, 2023)
mail in OpenBSD 2.9 and 3.0 processes a tilde (~) escape character in a message even when it is not in interactive mode, which could allow local users to gain root privileges via calls to mail in cron.
0
Attacker Value
Unknown
CVE-2001-1559
Disclosure Date: December 31, 2001 (last updated February 17, 2024)
The uipc system calls (uipc_syscalls.c) in OpenBSD 2.9 and 3.0 provide user mode return instead of versus rval kernel mode values to the fdrelease function, which allows local users to cause a denial of service and trigger a null dereference.
0
Attacker Value
Unknown
CVE-2001-1415
Disclosure Date: November 13, 2001 (last updated October 03, 2023)
vi.recover in OpenBSD before 3.1 allows local users to remove arbitrary zero-byte files such as device nodes.
0
Attacker Value
Unknown
CVE-2001-1244
Disclosure Date: July 07, 2001 (last updated October 03, 2023)
Multiple TCP implementations could allow remote attackers to cause a denial of service (bandwidth and CPU exhaustion) by setting the maximum segment size (MSS) to a very small number and requesting large amounts of data, which generates more packets with less TCP-level data that amplify network traffic and consume more server CPU to process.
0
Attacker Value
Unknown
CVE-2001-1047
Disclosure Date: June 02, 2001 (last updated October 03, 2023)
Race condition in OpenBSD VFS allows local users to cause a denial of service (kernel panic) by (1) creating a pipe in one thread and causing another thread to set one of the file descriptors to NULL via a close, or (2) calling dup2 on a file descriptor in one process, then setting the descriptor to NULL via a close in another process that is created via rfork.
0