Show filters
201 Total Results
Displaying 121-130 of 201
Sort by:
Attacker Value
Unknown
CVE-2003-0955
Disclosure Date: December 15, 2003 (last updated February 22, 2025)
OpenBSD kernel 3.3 and 3.4 allows local users to cause a denial of service (kernel panic) and possibly execute arbitrary code in 3.4 via a program with an invalid header that is not properly handled by (1) ibcs2_exec.c in the iBCS2 emulation (compat_ibcs2) or (2) exec_elf.c, which leads to a stack-based buffer overflow.
0
Attacker Value
Unknown
CVE-2003-0804
Disclosure Date: November 17, 2003 (last updated February 22, 2025)
The arplookup function in FreeBSD 5.1 and earlier, Mac OS X before 10.2.8, and possibly other BSD-based systems, allows remote attackers on a local subnet to cause a denial of service (resource starvation and panic) via a flood of spoofed ARP requests.
0
Attacker Value
Unknown
CVE-2003-0688
Disclosure Date: October 20, 2003 (last updated February 22, 2025)
The DNS map code in Sendmail 8.12.8 and earlier, when using the "enhdnsbl" feature, does not properly initialize certain data structures, which allows remote attackers to cause a denial of service (process crash) via an invalid DNS response that causes Sendmail to free incorrect data.
0
Attacker Value
Unknown
CVE-2003-0681
Disclosure Date: October 06, 2003 (last updated February 22, 2025)
A "potential buffer overflow in ruleset parsing" for Sendmail 8.12.9, when using the nonstandard rulesets (1) recipient (2), final, or (3) mailer-specific envelope recipients, has unknown consequences.
0
Attacker Value
Unknown
CVE-2003-0466
Disclosure Date: August 27, 2003 (last updated February 22, 2025)
Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code, as demonstrated in wu-ftpd 2.5.0 through 2.6.2 via commands that cause pathnames of length MAXPATHLEN+1 to trigger a buffer overflow, including (1) STOR, (2) RETR, (3) APPE, (4) DELE, (5) MKD, (6) RMD, (7) STOU, or (8) RNTO.
0
Attacker Value
Unknown
CVE-2002-1420
Disclosure Date: April 11, 2003 (last updated February 22, 2025)
Integer signedness error in select() on OpenBSD 3.1 and earlier allows local users to overwrite arbitrary kernel memory via a negative value for the size parameter, which satisfies the boundary check as a signed integer, but is later used as an unsigned integer during a data copying operation.
0
Attacker Value
Unknown
CVE-2003-0144
Disclosure Date: March 31, 2003 (last updated February 22, 2025)
Buffer overflow in the lprm command in the lprold lpr package on SuSE 7.1 through 7.3, OpenBSD 3.2 and earlier, and possibly other operating systems, allows local users to gain root privileges via long command line arguments such as (1) request ID or (2) user name.
0
Attacker Value
Unknown
CVE-2003-0028
Disclosure Date: March 25, 2003 (last updated February 22, 2025)
Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via certain integer values in length fields, a different vulnerability than CVE-2002-0391.
0
Attacker Value
Unknown
CVE-2003-0078
Disclosure Date: March 03, 2003 (last updated February 22, 2025)
ssl3_get_record in s3_pkt.c for OpenSSL before 0.9.7a and 0.9.6 before 0.9.6i does not perform a MAC computation if an incorrect block cipher padding is used, which causes an information leak (timing discrepancy) that may make it easier to launch cryptographic attacks that rely on distinguishing between padding and MAC verification errors, possibly leading to extraction of the original plaintext, aka the "Vaudenay timing attack."
0
Attacker Value
Unknown
CVE-2002-2188
Disclosure Date: December 31, 2002 (last updated February 22, 2025)
OpenBSD before 3.2 allows local users to cause a denial of service (kernel crash) via a call to getrlimit(2) with invalid arguments, possibly due to an integer signedness error.
0