Show filters
321 Total Results
Displaying 21-30 of 321
Sort by:
Attacker Value
Unknown
CVE-2023-51767
Disclosure Date: December 24, 2023 (last updated February 28, 2024)
OpenSSH through 9.6, when common types of DRAM are used, might allow row hammer attacks (for authentication bypass) because the integer value of authenticated in mm_answer_authpassword does not resist flips of a single bit. NOTE: this is applicable to a certain threat model of attacker-victim co-location in which the attacker has user privileges.
0
Attacker Value
Unknown
CVE-2023-51385
Disclosure Date: December 18, 2023 (last updated January 04, 2024)
In ssh in OpenSSH before 9.6, OS command injection might occur if a user name or host name has shell metacharacters, and this name is referenced by an expansion token in certain situations. For example, an untrusted Git repository can have a submodule with shell metacharacters in a user name or host name.
0
Attacker Value
Unknown
CVE-2023-51384
Disclosure Date: December 18, 2023 (last updated May 17, 2024)
In ssh-agent in OpenSSH before 9.6, certain destination constraints can be incompletely applied. When destination constraints are specified during addition of PKCS#11-hosted private keys, these constraints are only applied to the first key, even if a PKCS#11 token returns multiple keys.
0
Attacker Value
Unknown
CVE-2023-40216
Disclosure Date: August 10, 2023 (last updated October 08, 2023)
OpenBSD 7.3 before errata 014 is missing an argument-count bounds check in console terminal emulation. This could cause incorrect memory access and a kernel crash after receiving crafted DCS or CSI terminal escape sequences.
0
Attacker Value
Unknown
CVE-2023-35784
Disclosure Date: June 16, 2023 (last updated October 08, 2023)
A double free or use after free could occur after SSL_clear in OpenBSD 7.2 before errata 026 and 7.3 before errata 004, and in LibreSSL before 3.6.3 and 3.7.x before 3.7.3. NOTE: OpenSSL is not affected.
0
Attacker Value
Unknown
CVE-2021-46880
Disclosure Date: April 15, 2023 (last updated October 08, 2023)
x509/x509_verify.c in LibreSSL before 3.4.2, and OpenBSD before 7.0 errata 006, allows authentication bypass because an error for an unverified certificate chain is sometimes discarded.
0
Attacker Value
Unknown
CVE-2022-48437
Disclosure Date: April 12, 2023 (last updated October 08, 2023)
An issue was discovered in x509/x509_verify.c in LibreSSL before 3.6.1, and in OpenBSD before 7.2 errata 001. x509_verify_ctx_add_chain does not store errors that occur during leaf certificate verification, and therefore an incorrect error is returned. This behavior occurs when there is an installed verification callback that instructs the verifier to continue upon detecting an invalid certificate.
0
Attacker Value
Unknown
CVE-2023-29323
Disclosure Date: April 04, 2023 (last updated October 08, 2023)
ascii_load_sockaddr in smtpd in OpenBSD before 7.1 errata 024 and 7.2 before errata 020, and OpenSMTPD Portable before 7.0.0-portable commit f748277, can abort upon a connection from a local, scoped IPv6 address.
0
Attacker Value
Unknown
CVE-2023-28531
Disclosure Date: March 17, 2023 (last updated October 08, 2023)
ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints. The earliest affected version is 8.9.
0
Attacker Value
Unknown
CVE-2023-27567
Disclosure Date: March 03, 2023 (last updated October 08, 2023)
In OpenBSD 7.2, a TCP packet with destination port 0 that matches a pf divert-to rule can crash the kernel.
0