Openbsd

Openbsd

194 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.11%
  • Published 16.06.2023 20:15:09
  • Last modified 21.11.2024 08:08:41

A double free or use after free could occur after SSL_clear in OpenBSD 7.2 before errata 026 and 7.3 before errata 004, and in LibreSSL before 3.6.3 and 3.7.x before 3.7.3. NOTE: OpenSSL is not affected.

  • EPSS 0.03%
  • Published 15.04.2023 00:15:07
  • Last modified 07.02.2025 16:15:33

x509/x509_verify.c in LibreSSL before 3.4.2, and OpenBSD before 7.0 errata 006, allows authentication bypass because an error for an unverified certificate chain is sometimes discarded.

  • EPSS 0.07%
  • Published 12.04.2023 05:15:07
  • Last modified 10.02.2025 17:15:15

An issue was discovered in x509/x509_verify.c in LibreSSL before 3.6.1, and in OpenBSD before 7.2 errata 001. x509_verify_ctx_add_chain does not store errors that occur during leaf certificate verification, and therefore an incorrect error is returne...

  • EPSS 0.03%
  • Published 04.04.2023 23:15:07
  • Last modified 21.11.2024 07:56:51

ascii_load_sockaddr in smtpd in OpenBSD before 7.1 errata 024 and 7.2 before errata 020, and OpenSMTPD Portable before 7.0.0-portable commit f748277, can abort upon a connection from a local, scoped IPv6 address.

  • EPSS 0.08%
  • Published 03.03.2023 22:15:10
  • Last modified 06.03.2025 17:15:17

In OpenBSD 7.2, a TCP packet with destination port 0 that matches a pf divert-to rule can crash the kernel.

Exploit
  • EPSS 0.91%
  • Published 25.03.2022 18:15:28
  • Last modified 21.11.2024 06:56:24

slaacd in OpenBSD 6.9 and 7.0 before 2022-03-22 has an integer signedness error and resultant heap-based buffer overflow triggerable by a crafted IPv6 router advertisement. NOTE: privilege separation and pledge can prevent exploitation.

Exploit
  • EPSS 1.19%
  • Published 22.06.2021 14:15:08
  • Last modified 21.11.2024 01:21:50

It was found in FreeBSD 8.0, 6.3 and 4.9, and OpenBSD 4.6 that a null pointer dereference in ftpd/popen.c may lead to remote denial of service of the ftpd service.

  • EPSS 0.58%
  • Published 11.05.2021 20:15:08
  • Last modified 21.11.2024 05:19:21

An issue was discovered in the kernel in OpenBSD 6.6. The WEP, WPA, WPA2, and WPA3 implementations treat fragmented frames as full frames. An adversary can abuse this to inject arbitrary network packets, independent of the network configuration.

Exploit
  • EPSS 0.16%
  • Published 28.07.2020 12:15:12
  • Last modified 21.11.2024 05:06:44

iked in OpenIKED, as used in OpenBSD through 6.7, allows authentication bypass because ca.c has the wrong logic for checking whether a public key matches.

Exploit
  • EPSS 24.64%
  • Published 12.02.2020 20:15:13
  • Last modified 21.11.2024 01:30:17

regcomp in the BSD implementation of libc is vulnerable to denial of service due to stack exhaustion.