CVE-2017-1000373
- EPSS 18.75%
- Published 19.06.2017 16:29:00
- Last modified 20.04.2025 01:37:25
The OpenBSD qsort() function is recursive, and not randomized, an attacker can construct a pathological input array of N elements that causes qsort() to deterministically recurse N/4 times. This allows attackers to consume arbitrary amounts of stack ...
CVE-2017-5850
- EPSS 49.59%
- Published 27.03.2017 15:59:00
- Last modified 20.04.2025 01:37:25
httpd in OpenBSD allows remote attackers to cause a denial of service (memory consumption) via a series of requests for a large file using an HTTP Range header.
CVE-2016-6239
- EPSS 0.14%
- Published 07.03.2017 16:59:00
- Last modified 20.04.2025 01:37:25
The mmap extension __MAP_NOFAULT in OpenBSD 5.8 and 5.9 allows attackers to cause a denial of service (kernel panic and crash) via a large size value.
CVE-2016-6240
- EPSS 0.14%
- Published 07.03.2017 16:59:00
- Last modified 20.04.2025 01:37:25
Integer truncation error in the amap_alloc function in OpenBSD 5.8 and 5.9 allows local users to execute arbitrary code with kernel privileges via a large size value.
CVE-2016-6241
- EPSS 0.13%
- Published 07.03.2017 16:59:00
- Last modified 20.04.2025 01:37:25
Integer overflow in the amap_alloc1 function in OpenBSD 5.8 and 5.9 allows local users to execute arbitrary code with kernel privileges via a large size value.
CVE-2016-6242
- EPSS 0.04%
- Published 07.03.2017 16:59:00
- Last modified 20.04.2025 01:37:25
OpenBSD 5.8 and 5.9 allows local users to cause a denial of service (assertion failure and kernel panic) via a large ident value in a kevent system call.
CVE-2016-6243
- EPSS 0.04%
- Published 07.03.2017 16:59:00
- Last modified 20.04.2025 01:37:25
thrsleep in kern/kern_synch.c in OpenBSD 5.8 and 5.9 allows local users to cause a denial of service (kernel panic) via a crafted value in the tsp parameter of the __thrsleep system call.
CVE-2016-6245
- EPSS 0.04%
- Published 07.03.2017 16:59:00
- Last modified 20.04.2025 01:37:25
OpenBSD 5.8 and 5.9 allows local users to cause a denial of service (kernel panic) via a large size in a getdents system call.
CVE-2016-6246
- EPSS 0.05%
- Published 07.03.2017 16:59:00
- Last modified 20.04.2025 01:37:25
OpenBSD 5.8 and 5.9 allows certain local users with kern.usermount privileges to cause a denial of service (kernel panic) by mounting a tmpfs with a VNOVAL in the (1) username, (2) groupname, or (3) device name of the root node.
CVE-2016-6247
- EPSS 0.04%
- Published 07.03.2017 16:59:00
- Last modified 20.04.2025 01:37:25
OpenBSD 5.8 and 5.9 allows certain local users to cause a denial of service (kernel panic) by unmounting a filesystem with an open vnode on the mnt_vnodelist.