Show filters
201 Total Results
Displaying 141-150 of 201
Sort by:
Attacker Value
Unknown

CVE-2002-0514

Disclosure Date: August 12, 2002 (last updated February 22, 2025)
PF in OpenBSD 3.0 with the return-rst rule sets the TTL to 128 in the RST packet, which allows remote attackers to determine if a port is being filtered because the TTL is different than the default TTL.
0
Attacker Value
Unknown

CVE-2002-0765

Disclosure Date: August 12, 2002 (last updated February 22, 2025)
sshd in OpenSSH 3.2.2, when using YP with netgroups and under certain conditions, may allow users to successfully authenticate and log in with another user's password.
0
Attacker Value
Unknown

CVE-2000-1208

Disclosure Date: August 12, 2002 (last updated February 22, 2025)
Format string vulnerability in startprinting() function of printjob.c in BSD-based lpr lpd package may allow local users to gain privileges via an improper syslog call that uses format strings from the checkremote() call.
0
Attacker Value
Unknown

CVE-2002-0414

Disclosure Date: August 12, 2002 (last updated February 22, 2025)
KAME-derived implementations of IPsec on NetBSD 1.5.2, FreeBSD 4.5, and other operating systems, does not properly consult the Security Policy Database (SPD), which could cause a Security Gateway (SG) that does not use Encapsulating Security Payload (ESP) to forward forged IPv4 packets.
0
Attacker Value
Unknown

CVE-2002-0766

Disclosure Date: August 12, 2002 (last updated February 22, 2025)
OpenBSD 2.9 through 3.1 allows local users to cause a denial of service (resource exhaustion) and gain root privileges by filling the kernel's file descriptor table and closing file descriptors 0, 1, or 2 before executing a privileged process, which is not properly handled when OpenBSD fails to open an alternate descriptor.
0
Attacker Value
Unknown

CVE-2002-0701

Disclosure Date: July 23, 2002 (last updated February 22, 2025)
ktrace in BSD-based operating systems allows the owner of a process with special privileges to trace the process after its privileges have been lowered, which may allow the owner to obtain sensitive information that the process obtained while it was running with the extra privileges.
0
Attacker Value
Unknown

CVE-2002-0557

Disclosure Date: July 03, 2002 (last updated February 22, 2025)
Vulnerability in OpenBSD 3.0, when using YP with netgroups in the password database, causes (1) rexec or (2) rsh to run another user's shell, or (3) atrun to change to a different user's directory, possibly due to memory allocation failures or an incorrect call to auth_approval().
0
Attacker Value
Unknown

CVE-2002-0572

Disclosure Date: July 03, 2002 (last updated February 22, 2025)
FreeBSD 4.5 and earlier, and possibly other BSD-based operating systems, allows local users to write to or read from restricted files by closing the file descriptors 0 (standard input), 1 (standard output), or 2 (standard error), which may then be reused by a called setuid process that intended to perform I/O on normal files.
0
Attacker Value
Unknown

CVE-2002-0542

Disclosure Date: July 03, 2002 (last updated February 22, 2025)
mail in OpenBSD 2.9 and 3.0 processes a tilde (~) escape character in a message even when it is not in interactive mode, which could allow local users to gain root privileges via calls to mail in cron.
0
Attacker Value
Unknown

CVE-2002-0381

Disclosure Date: June 25, 2002 (last updated February 22, 2025)
The TCP implementation in various BSD operating systems (tcp_input.c) does not properly block connections to broadcast addresses, which could allow remote attackers to bypass intended filters via packets with a unicast link layer address and an IP broadcast address.
0