CVE-2006-6397
- EPSS 0.26%
- Veröffentlicht 08.12.2006 01:28:00
- Zuletzt bearbeitet 16.06.2026 22:33:03
Integer overflow in banner/banner.c in FreeBSD, NetBSD, and OpenBSD might allow local users to modify memory via a long banner. NOTE: CVE and multiple third parties dispute this issue. Since banner is not setuid, an exploit would not cross privilege...
CVE-2006-6165
- EPSS 0.34%
- Veröffentlicht 29.11.2006 01:28:00
- Zuletzt bearbeitet 16.06.2026 22:32:35
ld.so in FreeBSD, NetBSD, and possibly other BSD distributions does not remove certain harmful environment variables, which allows local users to gain privileges by passing certain environment variables to loading processes. NOTE: this issue has bee...
CVE-2006-6013
- EPSS 0.41%
- Veröffentlicht 21.11.2006 23:07:00
- Zuletzt bearbeitet 16.06.2026 22:32:17
Integer signedness error in the fw_ioctl (FW_IOCTL) function in the FireWire (IEEE-1394) drivers (dev/firewire/fwdev.c) in various BSD kernels, including DragonFlyBSD, FreeBSD 5.5, MidnightBSD 0.1-CURRENT before 20061115, NetBSD-current before 200611...
CVE-2006-6014
- EPSS 0.34%
- Veröffentlicht 21.11.2006 23:07:00
- Zuletzt bearbeitet 16.06.2026 22:32:17
The NetBSD-current kernel before 20061028 does not properly perform bounds checking of an unspecified userspace parameter in the ptrace system call during a PT_DUMPCORE request, which allows local users to have an unknown impact.
CVE-2006-5214
- EPSS 0.35%
- Veröffentlicht 10.10.2006 04:06:00
- Zuletzt bearbeitet 16.06.2026 22:30:45
Race condition in the Xsession script, as used by X Display Manager (xdm) in NetBSD before 20060212, X.Org before 20060225, and Solaris 8 through 10 before 20061006, causes a user's Xsession errors file to have weak permissions before a chmod is perf...
CVE-2006-5215
- EPSS 0.3%
- Veröffentlicht 10.10.2006 04:06:00
- Zuletzt bearbeitet 16.06.2026 22:30:45
The Xsession script, as used by X Display Manager (xdm) in NetBSD before 20060212, X.Org before 20060317, and Solaris 8 through 10 before 20061006, allows local users to overwrite arbitrary files, or read another user's Xsession errors file, via a sy...
CVE-2006-5218
- EPSS 0.41%
- Veröffentlicht 10.10.2006 04:06:00
- Zuletzt bearbeitet 16.06.2026 22:30:46
Integer overflow in the systrace_preprepl function (STRIOCREPLACE) in systrace in OpenBSD 3.9 and NetBSD 3 allows local users to cause a denial of service (crash), gain privileges, or read arbitrary kernel memory via large numeric arguments to the sy...
- EPSS 11.7%
- Veröffentlicht 24.08.2006 01:04:00
- Zuletzt bearbeitet 16.06.2026 22:28:49
Buffer overflow in the sppp driver in FreeBSD 4.11 through 6.1, NetBSD 2.0 through 4.0 beta before 20060823, and OpenBSD 3.8 and 3.9 before 20060902 allows remote attackers to cause a denial of service (panic), obtain sensitive information, and possi...
CVE-2006-3202
- EPSS 0.39%
- Veröffentlicht 23.06.2006 20:06:00
- Zuletzt bearbeitet 16.06.2026 22:26:36
The ip6_savecontrol function in NetBSD 2.0 through 3.0, under certain configurations, does not check to see if IPv4-mapped sockets are being used before processing IPv6 socket options, which allows local users to cause a denial of service (crash) by ...
CVE-2006-2205
- EPSS 0.34%
- Veröffentlicht 05.05.2006 12:46:00
- Zuletzt bearbeitet 16.06.2026 22:24:32
The audio_write function in NetBSD 3.0 allows local users to cause a denial of service (kernel crash) by using the audiosetinfo ioctl to change the sample rate of an audio device.