CVE-2002-0414
- EPSS 0.74%
- Published 12.08.2002 04:00:00
- Last modified 03.04.2025 01:03:51
KAME-derived implementations of IPsec on NetBSD 1.5.2, FreeBSD 4.5, and other operating systems, does not properly consult the Security Policy Database (SPD), which could cause a Security Gateway (SG) that does not use Encapsulating Security Payload ...
- EPSS 0.78%
- Published 25.06.2002 04:00:00
- Last modified 03.04.2025 01:03:51
The TCP implementation in various BSD operating systems (tcp_input.c) does not properly block connections to broadcast addresses, which could allow remote attackers to bypass intended filters via packets with a unicast link layer address and an IP br...
CVE-2002-0004
- EPSS 0.27%
- Published 27.02.2002 05:00:00
- Last modified 03.04.2025 01:03:51
Heap corruption vulnerability in the "at" program allows local users to execute arbitrary code via a malformed execution time, which causes at to free the same memory twice.
CVE-2001-0734
- EPSS 0.05%
- Published 18.10.2001 04:00:00
- Last modified 03.04.2025 01:03:51
Hitachi Super-H architecture in NetBSD 1.5 and 1.4.1 allows a local user to gain privileges via modified Status Register contents, which are not properly handled by (1) the sigreturn system call or (2) the process_write_regs kernel routine.
CVE-2001-0670
- EPSS 16.16%
- Published 03.10.2001 04:00:00
- Last modified 03.04.2025 01:03:51
Buffer overflow in BSD line printer daemon (in.lpd or lpd) in various BSD-based operating systems allows remote attackers to execute arbitrary code via an incomplete print job followed by a request to display the printer queue.
- EPSS 0.92%
- Published 20.09.2001 04:00:00
- Last modified 03.04.2025 01:03:51
NetBSD 1.5 and earlier and FreeBSD 4.3 and earlier allows a remote attacker to cause a denial of service by sending a large number of IP fragments to the machine, exhausting the mbuf pool.
CVE-2001-1091
- EPSS 0.06%
- Published 23.08.2001 04:00:00
- Last modified 03.04.2025 01:03:51
The (1) dump and (2) dump_lfs commands in NetBSD 1.4.x through 1.5.1 do not properly drop privileges, which could allow local users to gain privileges via the RCMD_CMD environment variable.
CVE-2001-1145
- EPSS 0.06%
- Published 17.08.2001 04:00:00
- Last modified 03.04.2025 01:03:51
fts routines in FreeBSD 4.3 and earlier, NetBSD before 1.5.2, and OpenBSD 2.9 and earlier can be forced to change (chdir) into a different directory than intended when the directory above the current directory is moved, which could cause scripts to p...
- EPSS 16.67%
- Published 14.08.2001 04:00:00
- Last modified 03.04.2025 01:03:51
Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a set of options including AYT (Are You There), which is not properly handled by the telrcv function.
CVE-2001-0993
- EPSS 0.07%
- Published 24.07.2001 04:00:00
- Last modified 03.04.2025 01:03:51
sendmsg function in NetBSD 1.3 through 1.5 allows local users to cause a denial of service (kernel trap or panic) via a msghdr structure with a large msg_controllen length.