Show filters
172 Total Results
Displaying 11-20 of 172
Sort by:
Attacker Value
Unknown
CVE-2011-2480
Disclosure Date: November 27, 2019 (last updated November 27, 2024)
Information Disclosure vulnerability in the 802.11 stack, as used in FreeBSD before 8.2 and NetBSD when using certain non-x86 architectures. A signedness error in the IEEE80211_IOC_CHANINFO ioctl allows a local unprivileged user to cause the kernel to copy large amounts of kernel memory back to the user, disclosing potentially sensitive information.
0
Attacker Value
Unknown
CVE-2017-1000375
Disclosure Date: June 19, 2017 (last updated November 26, 2024)
NetBSD maps the run-time link-editor ld.so directly below the stack region, even if ASLR is enabled, this allows attackers to more easily manipulate memory leading to arbitrary code execution. This affects NetBSD 7.1 and possibly earlier versions.
0
Attacker Value
Unknown
CVE-2017-1000378
Disclosure Date: June 19, 2017 (last updated November 26, 2024)
The NetBSD qsort() function is recursive, and not randomized, an attacker can construct a pathological input array of N elements that causes qsort() to deterministically recurse N/4 times. This allows attackers to consume arbitrary amounts of stack memory and manipulate stack memory to assist in arbitrary code execution attacks. This affects NetBSD 7.1 and possibly earlier versions.
0
Attacker Value
Unknown
CVE-2017-1000374
Disclosure Date: June 19, 2017 (last updated November 26, 2024)
A flaw exists in NetBSD's implementation of the stack guard page that allows attackers to bypass it resulting in arbitrary code execution using certain setuid binaries. This affects NetBSD 7.1 and possibly earlier versions.
0
Attacker Value
Unknown
CVE-2016-6253
Disclosure Date: January 20, 2017 (last updated November 25, 2024)
mail.local in NetBSD versions 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows local users to change ownership of or append data to arbitrary files on the target system via a symlink attack on the user mailbox.
0
Attacker Value
Unknown
CVE-2015-8212
Disclosure Date: January 19, 2017 (last updated November 25, 2024)
CGI handling flaw in bozohttpd in NetBSD 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows remote attackers to execute arbitrary code via crafted arguments, which are handled by a non-CGI aware program.
0
Attacker Value
Unknown
CVE-2015-5917
Disclosure Date: October 09, 2015 (last updated October 05, 2023)
The glob implementation in tnftpd (formerly lukemftpd), as used in Apple OS X before 10.11, allows remote attackers to cause a denial of service (memory consumption and daemon outage) via a STAT command containing a crafted pattern, as demonstrated by multiple instances of the {..,..,..}/* substring.
0
Attacker Value
Unknown
CVE-2014-7250
Disclosure Date: December 12, 2014 (last updated October 05, 2023)
The TCP stack in 4.3BSD Net/2, as used in FreeBSD 5.4, NetBSD possibly 2.0, and OpenBSD possibly 3.6, does not properly implement the session timer, which allows remote attackers to cause a denial of service (resource consumption) via crafted packets.
0
Attacker Value
Unknown
CVE-2014-8517
Disclosure Date: November 17, 2014 (last updated October 05, 2023)
The fetch_url function in usr.bin/ftp/fetch.c in tnftp, as used in NetBSD 5.1 through 5.1.4, 5.2 through 5.2.2, 6.0 through 6.0.6, and 6.1 through 6.1.5 allows remote attackers to execute arbitrary commands via a | (pipe) character at the end of an HTTP redirect.
0
Attacker Value
Unknown
CVE-2014-5384
Disclosure Date: August 21, 2014 (last updated October 05, 2023)
The VIQR module in the iconv implementation in FreeBSD 10.0 before p6 and NetBSD allows context-dependent attackers to cause a denial of service (out-of-bounds array access) via a crafted argument to the iconv_open function. NOTE: this issue was SPLIT from CVE-2014-3951 per ADT2 due to different vulnerability types.
0