CVE-2008-2476
- EPSS 10.5%
- Veröffentlicht 03.10.2008 15:07:10
- Zuletzt bearbeitet 23.04.2026 00:35:47
The IPv6 Neighbor Discovery Protocol (NDP) implementation in (1) FreeBSD 6.3 through 7.1, (2) OpenBSD 4.2 and 4.3, (3) NetBSD, (4) Force10 FTOS before E7.7.1.1, (5) Juniper JUNOS, and (6) Wind River VxWorks 5.x through 6.4 does not validate the origi...
CVE-2008-4247
- EPSS 12.61%
- Veröffentlicht 25.09.2008 19:25:18
- Zuletzt bearbeitet 23.04.2026 00:35:47
ftpd in OpenBSD 4.3, FreeBSD 7.0, NetBSD 4.0, Solaris, and possibly other operating systems interprets long commands from an FTP client as multiple commands, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and execu...
CVE-2008-1215
- EPSS 0.43%
- Veröffentlicht 09.03.2008 02:44:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Stack-based buffer overflow in the command_Expand_Interpret function in command.c in ppp (aka user-ppp), as distributed in FreeBSD 6.3 and 7.0, OpenBSD 4.1 and 4.2, and the net/userppp package for NetBSD, allows local users to gain privileges via lon...
CVE-2008-1057
- EPSS 0.39%
- Veröffentlicht 28.02.2008 19:44:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
The ip6_check_rh0hdr function in netinet6/ip6_input.c in OpenBSD 4.2 allows attackers to cause a denial of service (panic) via malformed IPv6 routing headers.
CVE-2008-1058
- EPSS 0.32%
- Veröffentlicht 28.02.2008 19:44:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
The tcp_respond function in netinet/tcp_subr.c in OpenBSD 4.1 and 4.2 allows attackers to cause a denial of service (panic) via crafted TCP packets. NOTE: some of these details are obtained from third party information.
CVE-2007-6700
- EPSS 4.56%
- Veröffentlicht 05.02.2008 02:00:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Cross-site scripting (XSS) vulnerability in cgi-bin/bgplg in the web interface for the BGPD daemon in OpenBSD 4.1 allows remote attackers to inject arbitrary web script or HTML via the cmd parameter.
CVE-2008-0384
- EPSS 0.33%
- Veröffentlicht 22.01.2008 20:00:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
OpenBSD 4.2 allows local users to cause a denial of service (kernel panic) by calling the SIOCGIFRTLABEL IOCTL on an interface that does not have a route label, which triggers a NULL pointer dereference when the return value from the rtlabel_id2name ...
CVE-2007-5365
- EPSS 43.51%
- Veröffentlicht 11.10.2007 10:17:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Stack-based buffer overflow in the cons_options function in options.c in dhcpd in OpenBSD 4.0 through 4.2, and some other dhcpd implementations based on ISC dhcp-2, allows remote attackers to execute arbitrary code or cause a denial of service (daemo...
CVE-2007-1351
- EPSS 7.77%
- Veröffentlicht 06.04.2007 01:19:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Integer overflow in the bdfReadCharacters function in bdfread.c in (1) X.Org libXfont before 20070403 and (2) freetype 2.3.2 and earlier allows remote authenticated users to execute arbitrary code via crafted BDF fonts, which result in a heap overflo...
CVE-2007-1352
- EPSS 1.7%
- Veröffentlicht 06.04.2007 01:19:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Integer overflow in the FontFileInitTable function in X.Org libXfont before 20070403 allows remote authenticated users to execute arbitrary code via a long first line in the fonts.dir file, which results in a heap overflow.