Openbsd

Openbsd

11 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.04%
  • Veröffentlicht 06.12.2024 02:15:18
  • Zuletzt bearbeitet 23.09.2025 12:07:11

In OpenBSD 7.4 before errata 014, vmm(4) did not restore GDTR limits properly on Intel (VMX) CPUs.

  • EPSS 0.06%
  • Veröffentlicht 05.12.2024 20:15:21
  • Zuletzt bearbeitet 23.09.2025 12:54:18

In OpenBSD 7.5 before errata 009 and OpenBSD 7.4 before errata 022, exclude any '/' in readdir name validation to avoid unexpected directory traversal on untrusted file systems.

  • EPSS 0.23%
  • Veröffentlicht 05.12.2024 20:15:21
  • Zuletzt bearbeitet 23.09.2025 12:22:43

In OpenBSD 7.4 before errata 006 and OpenBSD 7.3 before errata 020, httpd(8) is vulnerable to a NULL dereference when handling a malformed fastcgi request.

  • EPSS 0.24%
  • Veröffentlicht 15.11.2024 20:15:17
  • Zuletzt bearbeitet 02.10.2025 15:15:51

In OpenBSD 7.5 before errata 008 and OpenBSD 7.4 before errata 021, avoid possible mbuf double free in NFS client and server implementation, do not use uninitialized variable in error handling of NFS server.

  • EPSS 0.04%
  • Veröffentlicht 20.08.2024 06:15:04
  • Zuletzt bearbeitet 26.08.2024 14:35:06

cron/entry.c in vixie cron before 9cc8ab1, as used in OpenBSD 7.4 and 7.5, allows a heap-based buffer underflow and memory corruption. NOTE: this issue was introduced during a May 2023 refactoring.

  • EPSS 0.05%
  • Veröffentlicht 07.05.2024 23:15:13
  • Zuletzt bearbeitet 14.08.2025 01:40:22

OpenBSD Kernel Multicast Routing Uninitialized Memory Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installations of OpenBSD Kernel. An attacker must first obtain the abi...

Exploit
  • EPSS 6.3%
  • Veröffentlicht 11.04.2024 01:25:15
  • Zuletzt bearbeitet 17.06.2025 20:54:57

NFS in a BSD derived codebase, as used in OpenBSD through 7.4 and FreeBSD through 14.0-RELEASE, allows remote attackers to execute arbitrary code via a bug that is unrelated to memory corruption.

  • EPSS 0.02%
  • Veröffentlicht 01.03.2024 17:15:07
  • Zuletzt bearbeitet 21.11.2024 08:40:03

In OpenBSD 7.4 before errata 009, a race condition between pf(4)'s processing of packets and expiration of packet states may cause a kernel panic.

  • EPSS 0.08%
  • Veröffentlicht 01.03.2024 17:15:07
  • Zuletzt bearbeitet 21.11.2024 08:40:03

In OpenBSD 7.4 before errata 002 and OpenBSD 7.3 before errata 019, a network buffer that had to be split at certain length that could crash the kernel after receiving specially crafted escape sequences.

Exploit
  • EPSS 1.08%
  • Veröffentlicht 25.03.2022 18:15:27
  • Zuletzt bearbeitet 21.11.2024 06:56:24

engine.c in slaacd in OpenBSD 6.9 and 7.0 before 2022-02-21 has a buffer overflow triggerable by an IPv6 router advertisement with more than seven nameservers. NOTE: privilege separation and pledge can prevent exploitation.