Openbsd

Openbsd

11 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.04%
  • Published 06.12.2024 02:15:18
  • Last modified 23.09.2025 12:07:11

In OpenBSD 7.4 before errata 014, vmm(4) did not restore GDTR limits properly on Intel (VMX) CPUs.

  • EPSS 0.06%
  • Published 05.12.2024 20:15:21
  • Last modified 23.09.2025 12:54:18

In OpenBSD 7.5 before errata 009 and OpenBSD 7.4 before errata 022, exclude any '/' in readdir name validation to avoid unexpected directory traversal on untrusted file systems.

  • EPSS 0.23%
  • Published 05.12.2024 20:15:21
  • Last modified 23.09.2025 12:22:43

In OpenBSD 7.4 before errata 006 and OpenBSD 7.3 before errata 020, httpd(8) is vulnerable to a NULL dereference when handling a malformed fastcgi request.

  • EPSS 0.24%
  • Published 15.11.2024 20:15:17
  • Last modified 02.10.2025 15:15:51

In OpenBSD 7.5 before errata 008 and OpenBSD 7.4 before errata 021, avoid possible mbuf double free in NFS client and server implementation, do not use uninitialized variable in error handling of NFS server.

  • EPSS 0.04%
  • Published 20.08.2024 06:15:04
  • Last modified 26.08.2024 14:35:06

cron/entry.c in vixie cron before 9cc8ab1, as used in OpenBSD 7.4 and 7.5, allows a heap-based buffer underflow and memory corruption. NOTE: this issue was introduced during a May 2023 refactoring.

  • EPSS 0.05%
  • Published 07.05.2024 23:15:13
  • Last modified 14.08.2025 01:40:22

OpenBSD Kernel Multicast Routing Uninitialized Memory Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installations of OpenBSD Kernel. An attacker must first obtain the abi...

Exploit
  • EPSS 6.3%
  • Published 11.04.2024 01:25:15
  • Last modified 17.06.2025 20:54:57

NFS in a BSD derived codebase, as used in OpenBSD through 7.4 and FreeBSD through 14.0-RELEASE, allows remote attackers to execute arbitrary code via a bug that is unrelated to memory corruption.

  • EPSS 0.02%
  • Published 01.03.2024 17:15:07
  • Last modified 21.11.2024 08:40:03

In OpenBSD 7.4 before errata 009, a race condition between pf(4)'s processing of packets and expiration of packet states may cause a kernel panic.

  • EPSS 0.08%
  • Published 01.03.2024 17:15:07
  • Last modified 21.11.2024 08:40:03

In OpenBSD 7.4 before errata 002 and OpenBSD 7.3 before errata 019, a network buffer that had to be split at certain length that could crash the kernel after receiving specially crafted escape sequences.

Exploit
  • EPSS 1.08%
  • Published 25.03.2022 18:15:27
  • Last modified 21.11.2024 06:56:24

engine.c in slaacd in OpenBSD 6.9 and 7.0 before 2022-02-21 has a buffer overflow triggerable by an IPv6 router advertisement with more than seven nameservers. NOTE: privilege separation and pledge can prevent exploitation.