CVE-2023-35784
- EPSS 0.11%
- Veröffentlicht 16.06.2023 20:15:09
- Zuletzt bearbeitet 21.11.2024 08:08:41
A double free or use after free could occur after SSL_clear in OpenBSD 7.2 before errata 026 and 7.3 before errata 004, and in LibreSSL before 3.6.3 and 3.7.x before 3.7.3. NOTE: OpenSSL is not affected.
CVE-2021-46880
- EPSS 0.03%
- Veröffentlicht 15.04.2023 00:15:07
- Zuletzt bearbeitet 07.02.2025 16:15:33
x509/x509_verify.c in LibreSSL before 3.4.2, and OpenBSD before 7.0 errata 006, allows authentication bypass because an error for an unverified certificate chain is sometimes discarded.
CVE-2022-48437
- EPSS 0.07%
- Veröffentlicht 12.04.2023 05:15:07
- Zuletzt bearbeitet 10.02.2025 17:15:15
An issue was discovered in x509/x509_verify.c in LibreSSL before 3.6.1, and in OpenBSD before 7.2 errata 001. x509_verify_ctx_add_chain does not store errors that occur during leaf certificate verification, and therefore an incorrect error is returne...
CVE-2023-29323
- EPSS 0.03%
- Veröffentlicht 04.04.2023 23:15:07
- Zuletzt bearbeitet 21.11.2024 07:56:51
ascii_load_sockaddr in smtpd in OpenBSD before 7.1 errata 024 and 7.2 before errata 020, and OpenSMTPD Portable before 7.0.0-portable commit f748277, can abort upon a connection from a local, scoped IPv6 address.
CVE-2023-27567
- EPSS 0.08%
- Veröffentlicht 03.03.2023 22:15:10
- Zuletzt bearbeitet 06.03.2025 17:15:17
In OpenBSD 7.2, a TCP packet with destination port 0 that matches a pf divert-to rule can crash the kernel.
CVE-2022-27882
- EPSS 0.91%
- Veröffentlicht 25.03.2022 18:15:28
- Zuletzt bearbeitet 21.11.2024 06:56:24
slaacd in OpenBSD 6.9 and 7.0 before 2022-03-22 has an integer signedness error and resultant heap-based buffer overflow triggerable by a crafted IPv6 router advertisement. NOTE: privilege separation and pledge can prevent exploitation.
CVE-2010-4816
- EPSS 1.19%
- Veröffentlicht 22.06.2021 14:15:08
- Zuletzt bearbeitet 21.11.2024 01:21:50
It was found in FreeBSD 8.0, 6.3 and 4.9, and OpenBSD 4.6 that a null pointer dereference in ftpd/popen.c may lead to remote denial of service of the ftpd service.
CVE-2020-26142
- EPSS 0.58%
- Veröffentlicht 11.05.2021 20:15:08
- Zuletzt bearbeitet 21.11.2024 05:19:21
An issue was discovered in the kernel in OpenBSD 6.6. The WEP, WPA, WPA2, and WPA3 implementations treat fragmented frames as full frames. An adversary can abuse this to inject arbitrary network packets, independent of the network configuration.
CVE-2020-16088
- EPSS 0.16%
- Veröffentlicht 28.07.2020 12:15:12
- Zuletzt bearbeitet 21.11.2024 05:06:44
iked in OpenIKED, as used in OpenBSD through 6.7, allows authentication bypass because ca.c has the wrong logic for checking whether a public key matches.
CVE-2011-3336
- EPSS 24.64%
- Veröffentlicht 12.02.2020 20:15:13
- Zuletzt bearbeitet 21.11.2024 01:30:17
regcomp in the BSD implementation of libc is vulnerable to denial of service due to stack exhaustion.