CVE-2019-14899
- EPSS 0.84%
- Veröffentlicht 11.12.2019 15:15:14
- Zuletzt bearbeitet 21.11.2024 04:27:38
A vulnerability was discovered in Linux, FreeBSD, OpenBSD, MacOS, iOS, and Android that allows a malicious access point, or an adjacent user, to determine if a connected user is using a VPN, make positive inferences about the websites they are visiti...
CVE-2012-1577
- EPSS 1.55%
- Veröffentlicht 10.12.2019 19:15:14
- Zuletzt bearbeitet 21.11.2024 01:37:14
lib/libc/stdlib/random.c in OpenBSD returns 0 when seeded with 0.
CVE-2019-19519
- EPSS 0.39%
- Veröffentlicht 05.12.2019 00:15:11
- Zuletzt bearbeitet 21.11.2024 04:34:52
In OpenBSD 6.6, local users can use the su -L option to achieve any login class (often excluding root) because there is a logic error in the main function in su/su.c.
CVE-2019-19520
- EPSS 1.36%
- Veröffentlicht 05.12.2019 00:15:11
- Zuletzt bearbeitet 21.11.2024 04:34:52
xlock in OpenBSD 6.6 allows local users to gain the privileges of the auth group by providing a LIBGL_DRIVERS_PATH environment variable, because xenocara/lib/mesa/src/loader/loader.c mishandles dlopen.
CVE-2019-19521
- EPSS 2.74%
- Veröffentlicht 05.12.2019 00:15:11
- Zuletzt bearbeitet 21.11.2024 04:34:52
libc in OpenBSD 6.6 allows authentication bypass via the -schallenge username, as demonstrated by smtpd, ldapd, or radiusd. This is related to gen/auth_subr.c and gen/authenticate.c in libc (and login/login.c and xenocara/app/xenodm/greeter/verify.c)...
CVE-2019-19522
- EPSS 0.47%
- Veröffentlicht 05.12.2019 00:15:11
- Zuletzt bearbeitet 21.11.2024 04:34:52
OpenBSD 6.6, in a non-default configuration where S/Key or YubiKey authentication is enabled, allows local users to become root by leveraging membership in the auth group. This occurs because root's file can be written to /etc/skey or /var/db/yubikey...
CVE-2019-8460
- EPSS 2.19%
- Veröffentlicht 26.08.2019 20:15:10
- Zuletzt bearbeitet 21.11.2024 04:49:56
OpenBSD kernel version <= 6.5 can be forced to create long chains of TCP SACK holes that causes very expensive calls to tcp_sack_option() for every incoming SACK packet which can lead to a denial of service.
CVE-2018-14775
- EPSS 0.34%
- Veröffentlicht 01.08.2018 06:29:00
- Zuletzt bearbeitet 21.11.2024 03:49:45
tss_alloc in sys/arch/i386/i386/gdt.c in OpenBSD 6.2 and 6.3 has a Local Denial of Service (system crash) due to incorrect I/O port access control on the i386 architecture.
CVE-2017-1000372
- EPSS 3.96%
- Veröffentlicht 19.06.2017 16:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
A flaw exists in OpenBSD's implementation of the stack guard page that allows attackers to bypass it resulting in arbitrary code execution using setuid binaries such as /usr/bin/at. This affects OpenBSD 6.1 and possibly earlier versions.
CVE-2017-1000373
- EPSS 13.38%
- Veröffentlicht 19.06.2017 16:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The OpenBSD qsort() function is recursive, and not randomized, an attacker can construct a pathological input array of N elements that causes qsort() to deterministically recurse N/4 times. This allows attackers to consume arbitrary amounts of stack ...