Netbsd

Netbsd

171 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.37%
  • Veröffentlicht 16.07.2009 16:30:00
  • Zuletzt bearbeitet 16.06.2026 23:09:32

libprop/prop_object.c in proplib in NetBSD 4.0 and 4.0.1 allows local users to cause a denial of service (NULL pointer dereference and kernel panic) via a malformed externalized plist (XML form) containing an undefined element.

Exploit
  • EPSS 28.05%
  • Veröffentlicht 01.07.2009 13:00:01
  • Zuletzt bearbeitet 16.06.2026 23:05:34

Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the (2) gdtoa (aka new dtoa) implementation in gdtoa/misc.c in libc, as used in multiple operating systems and products including in FreeBSD 6.4 and 7.2, NetBSD 5.0, OpenBSD...

  • EPSS 32.12%
  • Veröffentlicht 20.10.2008 17:59:26
  • Zuletzt bearbeitet 16.06.2026 22:58:09

The TCP implementation in (1) Linux, (2) platforms based on BSD Unix, (3) Microsoft Windows, (4) Cisco products, and probably other operating systems allows remote attackers to cause a denial of service (connection queue exhaustion) via multiple vect...

  • EPSS 7.43%
  • Veröffentlicht 03.10.2008 15:07:10
  • Zuletzt bearbeitet 16.06.2026 22:53:50

The IPv6 Neighbor Discovery Protocol (NDP) implementation in (1) FreeBSD 6.3 through 7.1, (2) OpenBSD 4.2 and 4.3, (3) NetBSD, (4) Force10 FTOS before E7.7.1.1, (5) Juniper JUNOS, and (6) Wind River VxWorks 5.x through 6.4 does not validate the origi...

Exploit
  • EPSS 4.05%
  • Veröffentlicht 25.09.2008 19:25:18
  • Zuletzt bearbeitet 16.06.2026 22:57:29

ftpd in OpenBSD 4.3, FreeBSD 7.0, NetBSD 4.0, Solaris, and possibly other operating systems interprets long commands from an FTP client as multiple commands, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and execu...

  • EPSS 3.31%
  • Veröffentlicht 11.09.2008 21:06:44
  • Zuletzt bearbeitet 16.06.2026 22:56:05

NetBSD 3.0, 3.1, and 4.0, when a pppoe instance exists, does not properly check the length of a PPPoE packet tag, which allows remote attackers to cause a denial of service (system crash) via a crafted PPPoE packet.

Exploit
  • EPSS 2.43%
  • Veröffentlicht 11.09.2008 01:10:39
  • Zuletzt bearbeitet 16.06.2026 22:53:49

The mld_input function in sys/netinet6/mld6.c in the kernel in NetBSD 4.0, FreeBSD, and KAME, when INET6 is enabled, allows remote attackers to cause a denial of service (divide-by-zero error and panic) via a malformed ICMPv6 Multicast Listener Disco...

Exploit
  • EPSS 18.8%
  • Veröffentlicht 27.03.2008 17:44:00
  • Zuletzt bearbeitet 16.06.2026 22:51:38

Multiple integer overflows in libc in NetBSD 4.x, FreeBSD 6.x and 7.x, and probably other BSD and Apple Mac OS platforms allow context-dependent attackers to execute arbitrary code via large values of certain integer fields in the format argument to ...

  • EPSS 1.94%
  • Veröffentlicht 13.03.2008 18:44:00
  • Zuletzt bearbeitet 16.06.2026 22:51:31

The ipsec4_get_ulp function in the kernel in NetBSD 2.0 through 3.1 and NetBSD-current before 20071028, when the fast_ipsec subsystem is enabled, allows remote attackers to bypass the IPsec policy by sending packets from a source machine with a diffe...

Exploit
  • EPSS 0.79%
  • Veröffentlicht 09.03.2008 02:44:00
  • Zuletzt bearbeitet 16.06.2026 22:51:14

Stack-based buffer overflow in the command_Expand_Interpret function in command.c in ppp (aka user-ppp), as distributed in FreeBSD 6.3 and 7.0, OpenBSD 4.1 and 4.2, and the net/userppp package for NetBSD, allows local users to gain privileges via lon...