CVE-2003-0028
- EPSS 56.05%
- Published 25.03.2003 05:00:00
- Last modified 03.04.2025 01:03:51
Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via ...
- EPSS 11.64%
- Published 03.03.2003 05:00:00
- Last modified 03.04.2025 01:03:51
ssl3_get_record in s3_pkt.c for OpenSSL before 0.9.7a and 0.9.6 before 0.9.6i does not perform a MAC computation if an incorrect block cipher padding is used, which causes an information leak (timing discrepancy) that may make it easier to launch cry...
CVE-2002-1915
- EPSS 0.23%
- Published 31.12.2002 05:00:00
- Last modified 03.04.2025 01:03:51
tip on multiple BSD-based operating systems allows local users to cause a denial of service (execution prevention) by using flock() to lock the /var/log/acculog file.
CVE-2002-2092
- EPSS 0.07%
- Published 31.12.2002 05:00:00
- Last modified 03.04.2025 01:03:51
Race condition in exec in OpenBSD 4.0 and earlier, NetBSD 1.5.2 and earlier, and FreeBSD 4.4 and earlier allows local users to gain privileges by attaching a debugger to a process before the kernel has determined that the process is setuid or setgid.
CVE-2002-2180
- EPSS 0.14%
- Published 31.12.2002 05:00:00
- Last modified 03.04.2025 01:03:51
The setitimer(2) system call in OpenBSD 2.0 through 3.1 does not properly check certain arguments, which allows local users to write to kernel memory and possibly gain root privileges, possibly via an integer signedness error.
CVE-2002-2188
- EPSS 0.16%
- Published 31.12.2002 05:00:00
- Last modified 03.04.2025 01:03:51
OpenBSD before 3.2 allows local users to cause a denial of service (kernel crash) via a call to getrlimit(2) with invalid arguments, possibly due to an integer signedness error.
CVE-2002-2222
- EPSS 0.67%
- Published 31.12.2002 05:00:00
- Last modified 03.04.2025 01:03:51
isakmpd/message.c in isakmpd in FreeBSD before isakmpd-20020403_1, and in OpenBSD 3.1, allows remote attackers to cause a denial of service (crash) by sending Internet Key Exchange (IKE) payloads out of sequence.
CVE-2002-2280
- EPSS 0.07%
- Published 31.12.2002 05:00:00
- Last modified 03.04.2025 01:03:51
syslogd on OpenBSD 2.9 through 3.2 does not change the source IP address of syslog packets when the machine's IP addressed is changed without rebooting, e.g. via ifconfig, which can cause incorrect information to be sent to the syslog server.
- EPSS 2.13%
- Published 23.12.2002 05:00:00
- Last modified 03.04.2025 01:03:51
Directory traversal vulnerabilities in multiple FTP clients on UNIX systems allow remote malicious FTP servers to create or overwrite files as the client user via filenames containing /absolute/path or .. (dot dot) sequences.
CVE-2002-1219
- EPSS 7.09%
- Published 29.11.2002 05:00:00
- Last modified 03.04.2025 01:03:51
Buffer overflow in named in BIND 4 versions 4.9.10 and earlier, and 8 versions 8.3.3 and earlier, allows remote attackers to execute arbitrary code via a certain DNS server response containing SIG resource records (RR).