Show filters
29 Total Results
Displaying 21-29 of 29
Sort by:
Attacker Value
Unknown

CVE-2002-0666

Disclosure Date: November 04, 2002 (last updated February 22, 2025)
IPSEC implementations including (1) FreeS/WAN and (2) KAME do not properly calculate the length of authentication data, which allows remote attackers to cause a denial of service (kernel panic) via spoofed, short Encapsulating Security Payload (ESP) packets, which result in integer signedness errors.
0
Attacker Value
Unknown

CVE-2002-1194

Disclosure Date: October 28, 2002 (last updated February 22, 2025)
Buffer overflow in talkd on NetBSD 1.6 and earlier, and possibly other operating systems, may allow remote attackers to execute arbitrary code via a long inbound message.
0
Attacker Value
Unknown

CVE-2002-1192

Disclosure Date: October 28, 2002 (last updated February 22, 2025)
Multiple buffer overflows in rogue on NetBSD 1.6 and earlier, FreeBSD 4.6, and possibly other operating systems, allows local users to gain "games" group privileges via malformed entries in a game save file.
0
Attacker Value
Unknown

CVE-2002-1165

Disclosure Date: October 11, 2002 (last updated February 22, 2025)
Sendmail Consortium's Restricted Shell (SMRSH) in Sendmail 8.12.6, 8.11.6-15, and possibly other versions after 8.11 from 5/19/1998, allows attackers to bypass the intended restrictions of smrsh by inserting additional commands after (1) "||" sequences or (2) "/" characters, which are not properly filtered or verified.
0
Attacker Value
Unknown

CVE-2002-0414

Disclosure Date: August 12, 2002 (last updated February 22, 2025)
KAME-derived implementations of IPsec on NetBSD 1.5.2, FreeBSD 4.5, and other operating systems, does not properly consult the Security Policy Database (SPD), which could cause a Security Gateway (SG) that does not use Encapsulating Security Payload (ESP) to forward forged IPv4 packets.
0
Attacker Value
Unknown

CVE-2001-1091

Disclosure Date: August 23, 2001 (last updated February 22, 2025)
The (1) dump and (2) dump_lfs commands in NetBSD 1.4.x through 1.5.1 do not properly drop privileges, which could allow local users to gain privileges via the RCMD_CMD environment variable.
0
Attacker Value
Unknown

CVE-2001-1145

Disclosure Date: August 17, 2001 (last updated February 22, 2025)
fts routines in FreeBSD 4.3 and earlier, NetBSD before 1.5.2, and OpenBSD 2.9 and earlier can be forced to change (chdir) into a different directory than intended when the directory above the current directory is moved, which could cause scripts to perform dangerous actions on the wrong directories.
0
Attacker Value
Unknown

CVE-2001-0554

Disclosure Date: August 14, 2001 (last updated February 22, 2025)
Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a set of options including AYT (Are You There), which is not properly handled by the telrcv function.
0
Attacker Value
Unknown

CVE-2001-1244

Disclosure Date: July 07, 2001 (last updated February 22, 2025)
Multiple TCP implementations could allow remote attackers to cause a denial of service (bandwidth and CPU exhaustion) by setting the maximum segment size (MSS) to a very small number and requesting large amounts of data, which generates more packets with less TCP-level data that amplify network traffic and consume more server CPU to process.
0