Page 5 of 52 results (0.008 seconds)

CVSS: 10.0EPSS: 1%CPEs: 1EXPL: 0

03 May 2001 — Buffer overflow in IPSEC authentication mechanism for OpenBSD 2.8 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a malformed Authentication header (AH) IPv4 option. • http://www.openbsd.org/errata.html#ipsec_ah •

CVSS: 7.5EPSS: 6%CPEs: 7EXPL: 3

19 Dec 2000 — OpenBSD 2.6 and earlier allows remote attackers to cause a denial of service by flooding the server with ARP requests. • https://www.exploit-db.com/exploits/20271 •

CVSS: 7.8EPSS: 0%CPEs: 13EXPL: 2

19 Dec 2000 — Format string vulnerability in pw_error function in BSD libutil library allows local users to gain root privileges via a malformed password in commands such as chpass or passwd. • https://www.exploit-db.com/exploits/243 •

CVSS: 7.8EPSS: 0%CPEs: 5EXPL: 2

19 Dec 2000 — Format string vulnerability in OpenBSD fstat program (and possibly other BSD-based operating systems) allows local users to gain root privileges via the PWD environmental variable. • https://www.exploit-db.com/exploits/20256 •

CVSS: 7.8EPSS: 0%CPEs: 5EXPL: 0

11 Dec 2000 — Format string vulnerability in OpenBSD photurisd allows local users to execute arbitrary commands via a configuration file directory name that contains formatting characters. • http://marc.info/?l=bugtraq&m=97068555106135&w=2 •

CVSS: 10.0EPSS: 2%CPEs: 10EXPL: 0

11 Dec 2000 — Format string vulnerability in talkd in OpenBSD and possibly other BSD-based OSes allows remote attackers to execute arbitrary commands via a user name that contains format characters. • http://www.securityfocus.com/archive/1/137890 •

CVSS: 7.8EPSS: 0%CPEs: 8EXPL: 0

29 Nov 2000 — Format string vulnerabilities in eeprom program in OpenBSD, NetBSD, and possibly other operating systems allows local attackers to gain root privileges. • ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.7/common/028_format_strings.patch •

CVSS: 7.5EPSS: 1%CPEs: 23EXPL: 0

30 Dec 1999 — ip_input.c in BSD-derived TCP/IP implementations allows remote attackers to cause a denial of service (crash or hang) via crafted packets. ip_input.c en implementaciones de TCP/IP derivadas de BSD permiten a atacantes remotos causar una denegación de servicio (cuelgue o caída) mediante paquetes artesanales. • http://www.openbsd.org/errata23.html#tcpfix • CWE-20: Improper Input Validation •

CVSS: 7.2EPSS: 0%CPEs: 27EXPL: 2

09 Aug 1999 — The BSD profil system call allows a local user to modify the internal data space of a program via profiling and execve. • https://www.exploit-db.com/exploits/19447 •

CVSS: 10.0EPSS: 0%CPEs: 9EXPL: 0

04 Dec 1998 — Buffer overflow in bootpd on OpenBSD, FreeBSD, and Linux systems via a malformed header type. • http://marc.info/?l=bugtraq&m=91278867118128&w=2 •