- EPSS 0.15%
- Published 02.03.2011 20:00:00
- Last modified 11.04.2025 00:51:21
The (1) remote_glob function in sftp-glob.c and the (2) process_put function in sftp.c in OpenSSH 5.8 and earlier, as used in FreeBSD 7.3 and 8.1, NetBSD 5.0.2, OpenBSD 4.7, and other products, allow remote authenticated users to cause a denial of se...
CVE-2010-2530
- EPSS 0.04%
- Published 29.09.2010 17:00:04
- Last modified 11.04.2025 00:51:21
Multiple integer signedness errors in smb_subr.c in the netsmb module in the kernel in NetBSD 5.0.2 and earlier, FreeBSD, and Apple Mac OS X allow local users to cause a denial of service (panic) via a negative size value in a /dev/nsmb ioctl operati...
CVE-2010-3014
- EPSS 0.06%
- Published 20.08.2010 20:00:02
- Last modified 11.04.2025 00:51:21
The Coda filesystem kernel module, as used in NetBSD and FreeBSD, when Coda is loaded and Venus is running with /coda mounted, allows local users to read sensitive heap memory via a large out_size value in a ViceIoctl struct to a Coda ioctl, which tr...
CVE-2010-0561
- EPSS 0.05%
- Published 08.02.2010 21:30:00
- Last modified 11.04.2025 00:51:21
Integer signedness error in NetBSD 4.0, 5.0, and NetBSD-current before 2010-01-21 allows local users to cause a denial of service (kernel panic) via a negative mixer index number being passed to (1) the azalia_query_devinfo function in the azalia aud...
CVE-2009-2793
- EPSS 0.07%
- Published 18.09.2009 22:30:00
- Last modified 09.04.2025 00:30:58
The kernel in NetBSD, probably 5.0.1 and earlier, on x86 platforms does not properly handle a pre-commit failure of the iret instruction, which might allow local users to gain privileges via vectors related to a tempEIP pseudocode variable that is ou...
CVE-2009-0687
- EPSS 12.33%
- Published 11.08.2009 10:30:00
- Last modified 09.04.2025 00:30:58
The pf_test_rule function in OpenBSD Packet Filter (PF), as used in OpenBSD 4.2 through 4.5, NetBSD 5.0 before RC3, MirOS 10 and earlier, and MidnightBSD 0.3-current allows remote attackers to cause a denial of service (panic) via crafted IP packets ...
CVE-2009-2482
- EPSS 0.05%
- Published 16.07.2009 16:30:00
- Last modified 09.04.2025 00:30:58
The pam_unix module in OpenPAM in NetBSD 4.0 before 4.0.2 and 5.0 before 5.0.1 allows local users to change the current root password if it is already known, even when they are not in the wheel group.
CVE-2009-2483
- EPSS 0.06%
- Published 16.07.2009 16:30:00
- Last modified 09.04.2025 00:30:58
libprop/prop_object.c in proplib in NetBSD 4.0 and 4.0.1 allows local users to cause a denial of service (NULL pointer dereference and kernel panic) via a malformed externalized plist (XML form) containing an undefined element.
CVE-2009-0689
- EPSS 41.05%
- Published 01.07.2009 13:00:01
- Last modified 09.04.2025 00:30:58
Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the (2) gdtoa (aka new dtoa) implementation in gdtoa/misc.c in libc, as used in multiple operating systems and products including in FreeBSD 6.4 and 7.2, NetBSD 5.0, OpenBSD...
CVE-2008-4609
- EPSS 0.48%
- Published 20.10.2008 17:59:26
- Last modified 09.04.2025 00:30:58
The TCP implementation in (1) Linux, (2) platforms based on BSD Unix, (3) Microsoft Windows, (4) Cisco products, and probably other operating systems allows remote attackers to cause a denial of service (connection queue exhaustion) via multiple vect...