Show filters
193 Total Results
Displaying 1-10 of 193
Sort by:
Attacker Value
Unknown
CVE-2024-11149
Disclosure Date: December 06, 2024 (last updated December 21, 2024)
In OpenBSD 7.4 before errata 014, vmm(4) did not restore GDTR limits properly on Intel (VMX) CPUs.
0
Attacker Value
Unknown
CVE-2024-11148
Disclosure Date: December 05, 2024 (last updated December 21, 2024)
In OpenBSD 7.4 before errata 006 and OpenBSD 7.3 before errata 020, httpd(8) is vulnerable to a NULL dereference when handling a malformed fastcgi request.
0
Attacker Value
Unknown
CVE-2024-10933
Disclosure Date: December 05, 2024 (last updated December 21, 2024)
In OpenBSD 7.5 before errata 009 and OpenBSD 7.4 before errata 022, exclude any '/' in readdir name validation to avoid unexpected directory traversal on untrusted file systems.
0
Attacker Value
Unknown
CVE-2024-10934
Disclosure Date: November 15, 2024 (last updated November 16, 2024)
In OpenBSD 7.5 before errata 008 and OpenBSD 7.4 before errata 021,
avoid possible mbuf double free in NFS client and server implementation, do not use uninitialized variable in error handling of NFS server.
0
Attacker Value
Unknown
CVE-2023-52558
Disclosure Date: March 01, 2024 (last updated March 02, 2024)
In OpenBSD 7.4 before errata 002 and OpenBSD 7.3 before errata 019, a network buffer that had to be split at certain length that could crash the kernel after receiving specially crafted escape sequences.
0
Attacker Value
Unknown
CVE-2023-52557
Disclosure Date: March 01, 2024 (last updated March 02, 2024)
In OpenBSD 7.3 before errata 016, npppd(8) could crash by a l2tp message which has an AVP (Attribute-Value Pair) with wrong length.
0
Attacker Value
Unknown
CVE-2023-52556
Disclosure Date: March 01, 2024 (last updated March 02, 2024)
In OpenBSD 7.4 before errata 009, a race condition between pf(4)'s processing of packets and expiration of packet states may cause a kernel panic.
0
Attacker Value
Unknown
CVE-2023-40216
Disclosure Date: August 10, 2023 (last updated October 08, 2023)
OpenBSD 7.3 before errata 014 is missing an argument-count bounds check in console terminal emulation. This could cause incorrect memory access and a kernel crash after receiving crafted DCS or CSI terminal escape sequences.
0
Attacker Value
Unknown
CVE-2023-35784
Disclosure Date: June 16, 2023 (last updated October 08, 2023)
A double free or use after free could occur after SSL_clear in OpenBSD 7.2 before errata 026 and 7.3 before errata 004, and in LibreSSL before 3.6.3 and 3.7.x before 3.7.3. NOTE: OpenSSL is not affected.
0
Attacker Value
Unknown
CVE-2021-46880
Disclosure Date: April 15, 2023 (last updated October 08, 2023)
x509/x509_verify.c in LibreSSL before 3.4.2, and OpenBSD before 7.0 errata 006, allows authentication bypass because an error for an unverified certificate chain is sometimes discarded.
0