CVE-2026-57843
- EPSS 0.1%
- Veröffentlicht 11.09.2026 13:50:32
- Zuletzt bearbeitet 24.09.2026 21:04:40
NetBSD contains an information disclosure vulnerability in mm_open() within sys/dev/mm.c that allows unprivileged local users to obtain real kernel virtual addresses by opening world-accessible devices such as /dev/null or /dev/zero, which incorrectl...
CVE-2026-57842
- EPSS 0.1%
- Veröffentlicht 11.09.2026 13:48:13
- Zuletzt bearbeitet 24.09.2026 20:44:42
NetBSD contains a use-after-free and double-free vulnerability in msg_recv_copyin() within the COMPAT_NETBSD32 compatibility layer due to a missing return statement before the cleanup label on the success path. Any local user able to execute a 32-bit...
CVE-2026-53996
- EPSS 0.09%
- Veröffentlicht 12.08.2026 12:42:33
- Zuletzt bearbeitet 24.09.2026 20:30:35
NetBSD's hdaudio(4) driver in sys/dev/hdaudio/hdaudio.c contains a missing access control vulnerability that allows unprivileged local attackers to invoke the HDAUDIO_FGRP_SETCONFIG ioctl without elevated permissions by exploiting the absence of an a...
CVE-2024-6387
- EPSS 99.51%
- Veröffentlicht 01.07.2024 13:15:06
- Zuletzt bearbeitet 01.09.2026 12:17:13
A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to aut...
CVE-2021-45484
- EPSS 0.96%
- Veröffentlicht 25.12.2021 02:15:06
- Zuletzt bearbeitet 21.11.2024 06:32:18
In NetBSD through 9.2, the IPv6 fragment ID generation algorithm employs a weak cryptographic PRNG.
CVE-2021-45487
- EPSS 0.96%
- Veröffentlicht 25.12.2021 02:15:06
- Zuletzt bearbeitet 21.11.2024 06:32:19
In NetBSD through 9.2, the IPv4 ID generation algorithm does not use appropriate cryptographic measures.
CVE-2021-45488
- EPSS 0.96%
- Veröffentlicht 25.12.2021 02:15:06
- Zuletzt bearbeitet 21.11.2024 06:32:19
In NetBSD through 9.2, there is an information leak in the TCP ISN (ISS) generation algorithm.
CVE-2021-45489
- EPSS 0.96%
- Veröffentlicht 25.12.2021 02:15:06
- Zuletzt bearbeitet 21.11.2024 06:32:19
In NetBSD through 9.2, the IPv6 Flow Label generation algorithm employs a weak cryptographic PRNG.
CVE-2020-26139
- EPSS 6.49%
- Veröffentlicht 11.05.2021 20:15:08
- Zuletzt bearbeitet 14.04.2026 09:16:21
An issue was discovered in the kernel in NetBSD 7.1. An Access Point (AP) forwards EAPOL frames to other clients even though the sender has not yet successfully authenticated to the AP. This might be abused in projected Wi-Fi networks to launch denia...
CVE-2012-5363
- EPSS 2.56%
- Veröffentlicht 20.02.2020 15:15:11
- Zuletzt bearbeitet 21.11.2024 01:44:35
The IPv6 implementation in FreeBSD and NetBSD (unknown versions, year 2012 and earlier) allows remote attackers to cause a denial of service via a flood of ICMPv6 Neighbor Solicitation messages, a different vulnerability than CVE-2011-2393.