Show filters
321 Total Results
Displaying 11-20 of 321
Sort by:
Attacker Value
Unknown

CVE-2007-4752

Disclosure Date: September 12, 2007 (last updated October 04, 2023)
ssh in OpenSSH before 4.7 does not properly handle when an untrusted cookie cannot be created and uses a trusted X11 cookie instead, which allows attackers to violate intended policy and gain privileges by causing an X client to be treated as trusted.
1
Attacker Value
Unknown

CVE-2024-11149

Disclosure Date: December 06, 2024 (last updated December 21, 2024)
In OpenBSD 7.4 before errata 014, vmm(4) did not restore GDTR limits properly on Intel (VMX) CPUs.
0
Attacker Value
Unknown

CVE-2024-11148

Disclosure Date: December 05, 2024 (last updated December 21, 2024)
In OpenBSD 7.4 before errata 006 and OpenBSD 7.3 before errata 020, httpd(8) is vulnerable to a NULL dereference when handling a malformed fastcgi request.
0
Attacker Value
Unknown

CVE-2024-10933

Disclosure Date: December 05, 2024 (last updated December 21, 2024)
In OpenBSD 7.5 before errata 009 and OpenBSD 7.4 before errata 022, exclude any '/' in readdir name validation to avoid unexpected directory traversal on untrusted file systems.
0
Attacker Value
Unknown

CVE-2024-10934

Disclosure Date: November 15, 2024 (last updated November 16, 2024)
In OpenBSD 7.5 before errata 008 and OpenBSD 7.4 before errata 021, avoid possible mbuf double free in NFS client and server implementation, do not use uninitialized variable in error handling of NFS server.
0
Attacker Value
Unknown

CVE-2021-35000

Disclosure Date: May 07, 2024 (last updated September 18, 2024)
OpenBSD Kernel Multicast Routing Uninitialized Memory Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installations of OpenBSD Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the implementation of multicast routing. The issue results from the lack of proper initialization of memory prior to accessing it. An attacker can leverage this in conjunction with other vulnerabilities to escalate privileges and execute arbitrary code in the context of the kernel. . Was ZDI-CAN-16112.
0
Attacker Value
Unknown

CVE-2021-34999

Disclosure Date: May 07, 2024 (last updated September 18, 2024)
OpenBSD Kernel Multicast Routing Uninitialized Memory Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installations of OpenBSD Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the implementation of multicast routing. The issue results from the lack of proper initialization of memory prior to accessing it. An attacker can leverage this in conjunction with other vulnerabilities to escalate privileges and execute arbitrary code in the context of the kernel. . Was ZDI-CAN-14540.
0
Attacker Value
Unknown

CVE-2023-52558

Disclosure Date: March 01, 2024 (last updated March 02, 2024)
In OpenBSD 7.4 before errata 002 and OpenBSD 7.3 before errata 019, a network buffer that had to be split at certain length that could crash the kernel after receiving specially crafted escape sequences.
0
Attacker Value
Unknown

CVE-2023-52557

Disclosure Date: March 01, 2024 (last updated March 02, 2024)
In OpenBSD 7.3 before errata 016, npppd(8) could crash by a l2tp message which has an AVP (Attribute-Value Pair) with wrong length.
0
Attacker Value
Unknown

CVE-2023-52556

Disclosure Date: March 01, 2024 (last updated March 02, 2024)
In OpenBSD 7.4 before errata 009, a race condition between pf(4)'s processing of packets and expiration of packet states may cause a kernel panic.
0