CVE-2023-52557
- EPSS 0.07%
- Veröffentlicht 01.03.2024 17:15:07
- Zuletzt bearbeitet 10.10.2025 17:46:02
In OpenBSD 7.3 before errata 016, npppd(8) could crash by a l2tp message which has an AVP (Attribute-Value Pair) with wrong length.
CVE-2023-52558
- EPSS 0.07%
- Veröffentlicht 01.03.2024 17:15:07
- Zuletzt bearbeitet 10.10.2025 17:36:59
In OpenBSD 7.4 before errata 002 and OpenBSD 7.3 before errata 019, a network buffer that had to be split at certain length that could crash the kernel after receiving specially crafted escape sequences.
CVE-2023-40216
- EPSS 0.04%
- Veröffentlicht 10.08.2023 16:15:09
- Zuletzt bearbeitet 21.11.2024 08:19:01
OpenBSD 7.3 before errata 014 is missing an argument-count bounds check in console terminal emulation. This could cause incorrect memory access and a kernel crash after receiving crafted DCS or CSI terminal escape sequences.
CVE-2023-35784
- EPSS 0.11%
- Veröffentlicht 16.06.2023 20:15:09
- Zuletzt bearbeitet 21.11.2024 08:08:41
A double free or use after free could occur after SSL_clear in OpenBSD 7.2 before errata 026 and 7.3 before errata 004, and in LibreSSL before 3.6.3 and 3.7.x before 3.7.3. NOTE: OpenSSL is not affected.
CVE-2021-46880
- EPSS 0.03%
- Veröffentlicht 15.04.2023 00:15:07
- Zuletzt bearbeitet 07.02.2025 16:15:33
x509/x509_verify.c in LibreSSL before 3.4.2, and OpenBSD before 7.0 errata 006, allows authentication bypass because an error for an unverified certificate chain is sometimes discarded.
CVE-2022-48437
- EPSS 0.09%
- Veröffentlicht 12.04.2023 05:15:07
- Zuletzt bearbeitet 10.02.2025 17:15:15
An issue was discovered in x509/x509_verify.c in LibreSSL before 3.6.1, and in OpenBSD before 7.2 errata 001. x509_verify_ctx_add_chain does not store errors that occur during leaf certificate verification, and therefore an incorrect error is returne...
CVE-2023-29323
- EPSS 0.04%
- Veröffentlicht 04.04.2023 23:15:07
- Zuletzt bearbeitet 04.11.2025 19:15:42
ascii_load_sockaddr in smtpd in OpenBSD before 7.1 errata 024 and 7.2 before errata 020, and OpenSMTPD Portable before 7.0.0-portable commit f748277, can abort upon a connection from a local, scoped IPv6 address.
CVE-2023-27567
- EPSS 0.1%
- Veröffentlicht 03.03.2023 22:15:10
- Zuletzt bearbeitet 06.03.2025 17:15:17
In OpenBSD 7.2, a TCP packet with destination port 0 that matches a pf divert-to rule can crash the kernel.
CVE-2022-27882
- EPSS 0.91%
- Veröffentlicht 25.03.2022 18:15:28
- Zuletzt bearbeitet 21.11.2024 06:56:24
slaacd in OpenBSD 6.9 and 7.0 before 2022-03-22 has an integer signedness error and resultant heap-based buffer overflow triggerable by a crafted IPv6 router advertisement. NOTE: privilege separation and pledge can prevent exploitation.
CVE-2010-4816
- EPSS 1.19%
- Veröffentlicht 22.06.2021 14:15:08
- Zuletzt bearbeitet 21.11.2024 01:21:50
It was found in FreeBSD 8.0, 6.3 and 4.9, and OpenBSD 4.6 that a null pointer dereference in ftpd/popen.c may lead to remote denial of service of the ftpd service.