CVE-2008-2476
- EPSS 14.85%
- Veröffentlicht 03.10.2008 15:07:10
- Zuletzt bearbeitet 09.04.2025 00:30:58
The IPv6 Neighbor Discovery Protocol (NDP) implementation in (1) FreeBSD 6.3 through 7.1, (2) OpenBSD 4.2 and 4.3, (3) NetBSD, (4) Force10 FTOS before E7.7.1.1, (5) Juniper JUNOS, and (6) Wind River VxWorks 5.x through 6.4 does not validate the origi...
CVE-2008-4247
- EPSS 11.1%
- Veröffentlicht 25.09.2008 19:25:18
- Zuletzt bearbeitet 09.04.2025 00:30:58
ftpd in OpenBSD 4.3, FreeBSD 7.0, NetBSD 4.0, Solaris, and possibly other operating systems interprets long commands from an FTP client as multiple commands, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and execu...
CVE-2008-3584
- EPSS 2.48%
- Veröffentlicht 11.09.2008 21:06:44
- Zuletzt bearbeitet 09.04.2025 00:30:58
NetBSD 3.0, 3.1, and 4.0, when a pppoe instance exists, does not properly check the length of a PPPoE packet tag, which allows remote attackers to cause a denial of service (system crash) via a crafted PPPoE packet.
CVE-2008-2464
- EPSS 3.59%
- Veröffentlicht 11.09.2008 01:10:39
- Zuletzt bearbeitet 09.04.2025 00:30:58
The mld_input function in sys/netinet6/mld6.c in the kernel in NetBSD 4.0, FreeBSD, and KAME, when INET6 is enabled, allows remote attackers to cause a denial of service (divide-by-zero error and panic) via a malformed ICMPv6 Multicast Listener Disco...
CVE-2008-1391
- EPSS 20.12%
- Veröffentlicht 27.03.2008 17:44:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple integer overflows in libc in NetBSD 4.x, FreeBSD 6.x and 7.x, and probably other BSD and Apple Mac OS platforms allow context-dependent attackers to execute arbitrary code via large values of certain integer fields in the format argument to ...
CVE-2008-1335
- EPSS 0.3%
- Veröffentlicht 13.03.2008 18:44:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The ipsec4_get_ulp function in the kernel in NetBSD 2.0 through 3.1 and NetBSD-current before 20071028, when the fast_ipsec subsystem is enabled, allows remote attackers to bypass the IPsec policy by sending packets from a source machine with a diffe...
CVE-2008-1215
- EPSS 0.4%
- Veröffentlicht 09.03.2008 02:44:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Stack-based buffer overflow in the command_Expand_Interpret function in command.c in ppp (aka user-ppp), as distributed in FreeBSD 6.3 and 7.0, OpenBSD 4.1 and 4.2, and the net/userppp package for NetBSD, allows local users to gain privileges via lon...
CVE-2007-3654
- EPSS 0.07%
- Veröffentlicht 17.09.2007 17:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The display driver allocattr functions in NetBSD 3.0 through 4.0_BETA2, and NetBSD-current before 20070728, allow local users to cause a denial of service (panic) via a (1) negative or (2) large value in an ioctl call, as demonstrated by the vga_allo...
CVE-2007-1677
- EPSS 0.05%
- Veröffentlicht 30.03.2007 00:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple buffer overflows in the ISO network protocol support in the NetBSD kernel 2.0 through 4.0_BETA2, and NetBSD-current before 20070329, allow local users to execute arbitrary code via long parameters to certain functions, as demonstrated by a l...
CVE-2007-1523
- EPSS 0.39%
- Veröffentlicht 20.03.2007 20:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Heap-based buffer overflow in the kernel in NetBSD 3.0, certain versions of FreeBSD and OpenBSD, and possibly other BSD derived operating systems allows local users to have an unknown impact. NOTE: this information is based upon a vague pre-advisory...