- EPSS 1.74%
- Veröffentlicht 24.07.2014 14:55:09
- Zuletzt bearbeitet 06.05.2026 22:30:45
bozotic HTTP server (aka bozohttpd) before 20140708, as used in NetBSD, truncates paths when checking .htpasswd restrictions, which allows remote attackers to bypass the HTTP authentication scheme and access restrictions via a long path.
- EPSS 1.1%
- Veröffentlicht 25.07.2012 19:55:01
- Zuletzt bearbeitet 16.06.2026 22:34:39
Integer overflow in the calloc function in libc/stdlib/malloc.c in jemalloc in libc for FreeBSD 6.4 and NetBSD makes it easier for context-dependent attackers to perform memory-related attacks such as buffer overflows via a large size value, which tr...
- EPSS 1.1%
- Veröffentlicht 25.07.2012 19:55:01
- Zuletzt bearbeitet 16.06.2026 22:48:42
The ipalloc function in libc/stdlib/malloc.c in jemalloc in libc for FreeBSD 6.4 and NetBSD does not properly allocate memory, which makes it easier for context-dependent attackers to perform memory-related attacks such as buffer overflows via a larg...
CVE-2012-0217
- EPSS 37.47%
- Veröffentlicht 12.06.2012 22:55:01
- Zuletzt bearbeitet 16.06.2026 23:36:54
The x86-64 kernel system-call functionality in Xen 4.1.2 and earlier, as used in Citrix XenServer 6.0.2 and earlier and other products; Oracle Solaris 11 and earlier; illumos before r13724; Joyent SmartOS before 20120614T184600Z; FreeBSD before 9.0-R...
CVE-2011-2393
- EPSS 1.98%
- Veröffentlicht 02.02.2012 17:55:00
- Zuletzt bearbeitet 16.06.2026 23:31:14
The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in FreeBSD, NetBSD, and possibly other BSD-based operating systems allows remote attackers to cause a denial of service (CPU consumption and device hang) by sending many Router Adv...
CVE-2011-2895
- EPSS 8.36%
- Veröffentlicht 19.08.2011 17:55:03
- Zuletzt bearbeitet 16.06.2026 23:32:12
The LZW decompressor in (1) the BufCompressedFill function in fontfile/decompress.c in X.Org libXfont before 1.4.4 and (2) compress/compress.c in 4.3BSD, as used in zopen.c in OpenBSD before 3.8, FreeBSD, NetBSD 4.0.x and 5.0.x before 5.0.3 and 5.1.x...
- EPSS 7.26%
- Veröffentlicht 24.05.2011 23:55:01
- Zuletzt bearbeitet 16.06.2026 23:27:18
The glob implementation in Pure-FTPd before 1.0.32, and in libc in NetBSD 5.1, does not properly expand expressions containing curly brackets, which allows remote authenticated users to cause a denial of service (memory consumption) via a crafted FTP...
CVE-2011-1920
- EPSS 0.44%
- Veröffentlicht 23.05.2011 22:55:01
- Zuletzt bearbeitet 16.06.2026 23:30:22
The make include files in NetBSD before 1.6.2, as used in pmake 1.111 and other products, allow local users to overwrite arbitrary files via a symlink attack on a /tmp/_depend##### temporary file, related to (1) bsd.lib.mk and (2) bsd.prog.mk.
CVE-2011-0419
- EPSS 30.41%
- Veröffentlicht 16.05.2011 17:55:02
- Zuletzt bearbeitet 16.06.2026 23:27:19
Stack consumption vulnerability in the fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library before 1.4.3 and the Apache HTTP Server before 2.2.18, and in fnmatch.c in libc in NetBSD 5.1, OpenBSD 4.8, FreeBSD, Apple Mac...
CVE-2011-1547
- EPSS 5.08%
- Veröffentlicht 09.05.2011 19:55:03
- Zuletzt bearbeitet 16.06.2026 23:29:35
Multiple stack consumption vulnerabilities in the kernel in NetBSD 4.0, 5.0 before 5.0.3, and 5.1 before 5.1.1, when IPsec is enabled, allow remote attackers to cause a denial of service (memory corruption and panic) or possibly have unspecified othe...