CVE-2002-0701
- EPSS 0.15%
- Veröffentlicht 23.07.2002 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
ktrace in BSD-based operating systems allows the owner of a process with special privileges to trace the process after its privileges have been lowered, which may allow the owner to obtain sensitive information that the process obtained while it was ...
CVE-2002-0542
- EPSS 0.36%
- Veröffentlicht 03.07.2002 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
mail in OpenBSD 2.9 and 3.0 processes a tilde (~) escape character in a message even when it is not in interactive mode, which could allow local users to gain root privileges via calls to mail in cron.
CVE-2002-0557
- EPSS 0.53%
- Veröffentlicht 03.07.2002 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Vulnerability in OpenBSD 3.0, when using YP with netgroups in the password database, causes (1) rexec or (2) rsh to run another user's shell, or (3) atrun to change to a different user's directory, possibly due to memory allocation failures or an inc...
CVE-2002-0572
- EPSS 0.28%
- Veröffentlicht 03.07.2002 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
FreeBSD 4.5 and earlier, and possibly other BSD-based operating systems, allows local users to write to or read from restricted files by closing the file descriptors 0 (standard input), 1 (standard output), or 2 (standard error), which may then be re...
- EPSS 0.78%
- Veröffentlicht 25.06.2002 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
The TCP implementation in various BSD operating systems (tcp_input.c) does not properly block connections to broadcast addresses, which could allow remote attackers to bypass intended filters via packets with a unicast link layer address and an IP br...
CVE-2001-1559
- EPSS 0.4%
- Veröffentlicht 31.12.2001 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
The uipc system calls (uipc_syscalls.c) in OpenBSD 2.9 and 3.0 provide user mode return instead of versus rval kernel mode values to the fdrelease function, which allows local users to cause a denial of service and trigger a null dereference.
CVE-2001-1415
- EPSS 0.1%
- Veröffentlicht 13.11.2001 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
vi.recover in OpenBSD before 3.1 allows local users to remove arbitrary zero-byte files such as device nodes.
CVE-2001-0670
- EPSS 16.16%
- Veröffentlicht 03.10.2001 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Buffer overflow in BSD line printer daemon (in.lpd or lpd) in various BSD-based operating systems allows remote attackers to execute arbitrary code via an incomplete print job followed by a request to display the printer queue.
CVE-2001-1145
- EPSS 0.06%
- Veröffentlicht 17.08.2001 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
fts routines in FreeBSD 4.3 and earlier, NetBSD before 1.5.2, and OpenBSD 2.9 and earlier can be forced to change (chdir) into a different directory than intended when the directory above the current directory is moved, which could cause scripts to p...
- EPSS 16.67%
- Veröffentlicht 14.08.2001 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a set of options including AYT (Are You There), which is not properly handled by the telrcv function.