Openbsd

Openbsd

203 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 1.69%
  • Veröffentlicht 05.02.2008 02:00:00
  • Zuletzt bearbeitet 16.06.2026 22:48:36

Cross-site scripting (XSS) vulnerability in cgi-bin/bgplg in the web interface for the BGPD daemon in OpenBSD 4.1 allows remote attackers to inject arbitrary web script or HTML via the cmd parameter.

Exploit
  • EPSS 0.85%
  • Veröffentlicht 22.01.2008 20:00:00
  • Zuletzt bearbeitet 16.06.2026 22:49:30

OpenBSD 4.2 allows local users to cause a denial of service (kernel panic) by calling the SIOCGIFRTLABEL IOCTL on an interface that does not have a route label, which triggers a NULL pointer dereference when the return value from the rtlabel_id2name ...

  • EPSS 80.27%
  • Veröffentlicht 11.10.2007 10:17:00
  • Zuletzt bearbeitet 16.06.2026 22:45:58

Stack-based buffer overflow in the cons_options function in options.c in dhcpd in OpenBSD 4.0 through 4.2, and some other dhcpd implementations based on ISC dhcp-2, allows remote attackers to execute arbitrary code or cause a denial of service (daemo...

  • EPSS 5.59%
  • Veröffentlicht 06.04.2007 01:19:00
  • Zuletzt bearbeitet 16.06.2026 22:37:24

Integer overflow in the bdfReadCharacters function in bdfread.c in (1) X.Org libXfont before 20070403 and (2) freetype 2.3.2 and earlier allows remote authenticated users to execute arbitrary code via crafted BDF fonts, which result in a heap overflo...

  • EPSS 1.52%
  • Veröffentlicht 06.04.2007 01:19:00
  • Zuletzt bearbeitet 16.06.2026 22:37:24

Integer overflow in the FontFileInitTable function in X.Org libXfont before 20070403 allows remote authenticated users to execute arbitrary code via a long first line in the fonts.dir file, which results in a heap overflow.

  • EPSS 17.79%
  • Veröffentlicht 10.03.2007 21:19:00
  • Zuletzt bearbeitet 16.06.2026 22:37:26

Buffer overflow in kern/uipc_mbuf2.c in OpenBSD 3.9 and 4.0 allows remote attackers to execute arbitrary code via fragmented IPv6 packets due to "incorrect mbuf handling for ICMP6 packets." NOTE: this was originally reported as a denial of service.

  • EPSS 2.28%
  • Veröffentlicht 18.01.2007 02:28:00
  • Zuletzt bearbeitet 16.06.2026 22:35:23

OpenBSD before 20070116 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via certain IPv6 ICMP (aka ICMP6) echo request packets.

  • EPSS 0.56%
  • Veröffentlicht 05.01.2007 11:28:00
  • Zuletzt bearbeitet 16.06.2026 22:34:53

Unspecified vulnerability in sys/dev/pci/vga_pci.c in the VGA graphics driver for wscons in OpenBSD 3.9 and 4.0, when the kernel is compiled with the PCIAGP option and a non-AGP device is being used, allows local users to gain privileges via unspecif...

  • EPSS 0.26%
  • Veröffentlicht 26.12.2006 23:28:00
  • Zuletzt bearbeitet 16.06.2026 22:33:40

OpenBSD and NetBSD permit usermode code to kill the display server and write to the X.Org /dev/xf86 device, which allows local users with root privileges to reduce securelevel by replacing the System Management Mode (SMM) handler via a write to an SM...

  • EPSS 0.26%
  • Veröffentlicht 08.12.2006 01:28:00
  • Zuletzt bearbeitet 16.06.2026 22:33:03

Integer overflow in banner/banner.c in FreeBSD, NetBSD, and OpenBSD might allow local users to modify memory via a long banner. NOTE: CVE and multiple third parties dispute this issue. Since banner is not setuid, an exploit would not cross privilege...