<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – NetBSD (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/netbsd.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/netbsd-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – NetBSD (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:45 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-7258 – In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7258</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7258</guid>
    <pubDate>Sun, 10 May 2026 05:16:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7258</strong></p>
  <p>In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, some functions, including urldecode(), pass signed char to ctype functions (like isxdigit()). On the systems with default signed char and optimized table-lookup ctype functions - such as NetBSD - this can lead to accessing array with negative offset, which can trigger a denial of service.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7258">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-45198 – ftpd before "NetBSD-ftpd 20230930" can leak information about the host filesyste...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-45198</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-45198</guid>
    <pubDate>Thu, 05 Oct 2023 05:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-45198</strong></p>
  <p>ftpd before "NetBSD-ftpd 20230930" can leak information about the host filesystem before authentication via an MLSD or MLST command. tnftpd (the portable version of NetBSD ftpd) before 20231001 is also vulnerable.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-45198">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-45489 – In NetBSD through 9.2, the IPv6 Flow Label generation algorithm employs a weak c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-45489</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-45489</guid>
    <pubDate>Sat, 25 Dec 2021 02:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-45489</strong></p>
  <p>In NetBSD through 9.2, the IPv6 Flow Label generation algorithm employs a weak cryptographic PRNG.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-338</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-45489">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-45488 – In NetBSD through 9.2, there is an information leak in the TCP ISN (ISS) generat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-45488</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-45488</guid>
    <pubDate>Sat, 25 Dec 2021 02:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-45488</strong></p>
  <p>In NetBSD through 9.2, there is an information leak in the TCP ISN (ISS) generation algorithm.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-330</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-45488">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-45487 – In NetBSD through 9.2, the IPv4 ID generation algorithm does not use appropriate...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-45487</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-45487</guid>
    <pubDate>Sat, 25 Dec 2021 02:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-45487</strong></p>
  <p>In NetBSD through 9.2, the IPv4 ID generation algorithm does not use appropriate cryptographic measures.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-330</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-45487">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-45484 – In NetBSD through 9.2, the IPv6 fragment ID generation algorithm employs a weak ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-45484</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-45484</guid>
    <pubDate>Sat, 25 Dec 2021 02:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-45484</strong></p>
  <p>In NetBSD through 9.2, the IPv6 fragment ID generation algorithm employs a weak cryptographic PRNG.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-338</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-45484">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2012-5365 – The IPv6 implementation in FreeBSD and NetBSD (unknown versions, year 2012 and e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-5365</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-5365</guid>
    <pubDate>Thu, 20 Feb 2020 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2012-5365</strong></p>
  <p>The IPv6 implementation in FreeBSD and NetBSD (unknown versions, year 2012 and earlier) allows remote attackers to cause a denial of service via a flood of ICMPv6 Router Advertisement packets containing multiple Routing entries.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-5365">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2012-5363 – The IPv6 implementation in FreeBSD and NetBSD (unknown versions, year 2012 and e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-5363</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-5363</guid>
    <pubDate>Thu, 20 Feb 2020 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2012-5363</strong></p>
  <p>The IPv6 implementation in FreeBSD and NetBSD (unknown versions, year 2012 and earlier) allows remote attackers to cause a denial of service via a flood of ICMPv6 Neighbor Solicitation messages, a different vulnerability than CVE-2011-2393.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-5363">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2011-2480 – Information Disclosure vulnerability in the 802.11 stack, as used in FreeBSD bef...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-2480</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-2480</guid>
    <pubDate>Wed, 27 Nov 2019 19:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2011-2480</strong></p>
  <p>Information Disclosure vulnerability in the 802.11 stack, as used in FreeBSD before 8.2 and NetBSD when using certain non-x86 architectures. A signedness error in the IEEE80211_IOC_CHANINFO ioctl allows a local unprivileged user to cause the kernel to copy large amounts of kernel memory back to the user, disclosing potentially sensitive information.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-2480">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-15901 – An issue was discovered in slicer69 doas before 6.2 on certain platforms other t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-15901</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-15901</guid>
    <pubDate>Fri, 18 Oct 2019 16:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-15901</strong></p>
  <p>An issue was discovered in slicer69 doas before 6.2 on certain platforms other than OpenBSD. A setusercontext(3) call with flags to change the UID, primary GID, and secondary GIDs was replaced (on certain platforms: Linux and possibly NetBSD) with a single setuid(2) call. This resulted in neither changing the group id nor initializing secondary group ids.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-15901">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-1000378 – The NetBSD qsort() function is recursive, and not randomized, an attacker can co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-1000378</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-1000378</guid>
    <pubDate>Mon, 19 Jun 2017 16:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-1000378</strong></p>
  <p>The NetBSD qsort() function is recursive, and not randomized, an attacker can construct a pathological input array of N elements that causes qsort() to deterministically recurse N/4 times. This allows attackers to consume arbitrary amounts of stack memory and manipulate stack memory to assist in arbitrary code execution attacks. This affects NetBSD 7.1 and possibly earlier versions.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-1000378">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-1000375 – NetBSD maps the run-time link-editor ld.so directly below the stack region, even...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-1000375</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-1000375</guid>
    <pubDate>Mon, 19 Jun 2017 16:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-1000375</strong></p>
  <p>NetBSD maps the run-time link-editor ld.so directly below the stack region, even if ASLR is enabled, this allows attackers to more easily manipulate memory leading to arbitrary code execution. This affects NetBSD 7.1 and possibly earlier versions.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-1000375">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-1000374 – A flaw exists in NetBSD's implementation of the stack guard page that allows att...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-1000374</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-1000374</guid>
    <pubDate>Mon, 19 Jun 2017 16:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-1000374</strong></p>
  <p>A flaw exists in NetBSD's implementation of the stack guard page that allows attackers to bypass it resulting in arbitrary code execution using certain setuid binaries. This affects NetBSD 7.1 and possibly earlier versions.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-1000374">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-8283 – dpkg-source in dpkg 1.3.0 through 1.18.23 is able to use a non-GNU patch program...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-8283</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-8283</guid>
    <pubDate>Wed, 26 Apr 2017 05:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-8283</strong></p>
  <p>dpkg-source in dpkg 1.3.0 through 1.18.23 is able to use a non-GNU patch program and does not offer a protection mechanism for blank-indented diff hunks, which allows remote attackers to conduct directory traversal attacks via a crafted Debian source package, as demonstrated by use of dpkg-source on NetBSD.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-8283">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-6253 – mail.local in NetBSD versions 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-6253</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-6253</guid>
    <pubDate>Fri, 20 Jan 2017 15:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-6253</strong></p>
  <p>mail.local in NetBSD versions 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows local users to change ownership of or append data to arbitrary files on the target system via a symlink attack on the user mailbox.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6253">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2015-8212 – CGI handling flaw in bozohttpd in NetBSD 6.0 through 6.0.6, 6.1 through 6.1.5, a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-8212</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-8212</guid>
    <pubDate>Thu, 19 Jan 2017 20:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2015-8212</strong></p>
  <p>CGI handling flaw in bozohttpd in NetBSD 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows remote attackers to execute arbitrary code via crafted arguments, which are handled by a non-CGI aware program.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-8212">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2014-8517 – The fetch_url function in usr.bin/ftp/fetch.c in tnftp, as used in NetBSD 5.1 th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-8517</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-8517</guid>
    <pubDate>Mon, 17 Nov 2014 16:59:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2014-8517</strong></p>
  <p>The fetch_url function in usr.bin/ftp/fetch.c in tnftp, as used in NetBSD 5.1 through 5.1.4, 5.2 through 5.2.2, 6.0 through 6.0.6, and 6.1 through 6.1.5 allows remote attackers to execute arbitrary commands via a | (pipe) character at the end of an HTTP redirect.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-8517">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2012-0217 – The x86-64 kernel system-call functionality in Xen 4.1.2 and earlier, as used in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-0217</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-0217</guid>
    <pubDate>Tue, 12 Jun 2012 22:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2012-0217</strong></p>
  <p>The x86-64 kernel system-call functionality in Xen 4.1.2 and earlier, as used in Citrix XenServer 6.0.2 and earlier and other products; Oracle Solaris 11 and earlier; illumos before r13724; Joyent SmartOS before 20120614T184600Z; FreeBSD before 9.0-RELEASE-p3; NetBSD 6.0 Beta and earlier; Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1; and possibly other operating systems,…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-0217">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2011-2393 – The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in FreeBSD...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-2393</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-2393</guid>
    <pubDate>Thu, 02 Feb 2012 17:55:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2011-2393</strong></p>
  <p>The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in FreeBSD, NetBSD, and possibly other BSD-based operating systems allows remote attackers to cause a denial of service (CPU consumption and device hang) by sending many Router Advertisement (RA) messages with different source addresses, a similar vulnerability to CVE-2010-4670.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-2393">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2011-2895 – The LZW decompressor in (1) the BufCompressedFill function in fontfile/decompres...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-2895</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-2895</guid>
    <pubDate>Fri, 19 Aug 2011 17:55:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2011-2895</strong></p>
  <p>The LZW decompressor in (1) the BufCompressedFill function in fontfile/decompress.c in X.Org libXfont before 1.4.4 and (2) compress/compress.c in 4.3BSD, as used in zopen.c in OpenBSD before 3.8, FreeBSD, NetBSD 4.0.x and 5.0.x before 5.0.3 and 5.1.x before 5.1.1, FreeType 2.1.9, and other products, does not properly handle code words that are absent from the decompression table when encountered,…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-2895">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2009-0687 – The pf_test_rule function in OpenBSD Packet Filter (PF), as used in OpenBSD 4.2 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-0687</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-0687</guid>
    <pubDate>Tue, 11 Aug 2009 10:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2009-0687</strong></p>
  <p>The pf_test_rule function in OpenBSD Packet Filter (PF), as used in OpenBSD 4.2 through 4.5, NetBSD 5.0 before RC3, MirOS 10 and earlier, and MidnightBSD 0.3-current allows remote attackers to cause a denial of service (panic) via crafted IP packets that trigger a NULL pointer dereference during translation, related to an IPv4 packet with an ICMPv6 payload.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-0687">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2008-2476 – The IPv6 Neighbor Discovery Protocol (NDP) implementation in (1) FreeBSD 6.3 thr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-2476</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-2476</guid>
    <pubDate>Fri, 03 Oct 2008 15:07:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2008-2476</strong></p>
  <p>The IPv6 Neighbor Discovery Protocol (NDP) implementation in (1) FreeBSD 6.3 through 7.1, (2) OpenBSD 4.2 and 4.3, (3) NetBSD, (4) Force10 FTOS before E7.7.1.1, (5) Juniper JUNOS, and (6) Wind River VxWorks 5.x through 6.4 does not validate the origin of Neighbor Discovery messages, which allows remote attackers to cause a denial of service (loss of connectivity) or read private network traffic v…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-2476">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-4247 – ftpd in OpenBSD 4.3, FreeBSD 7.0, NetBSD 4.0, Solaris, and possibly other operat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-4247</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-4247</guid>
    <pubDate>Thu, 25 Sep 2008 19:25:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-4247</strong></p>
  <p>ftpd in OpenBSD 4.3, FreeBSD 7.0, NetBSD 4.0, Solaris, and possibly other operating systems interprets long commands from an FTP client as multiple commands, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and execute arbitrary FTP commands via a long ftp:// URI that leverages an existing session from the FTP client implementation in a web browser.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-4247">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2008-3584 – NetBSD 3.0, 3.1, and 4.0, when a pppoe instance exists, does not properly check ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-3584</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-3584</guid>
    <pubDate>Thu, 11 Sep 2008 21:06:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2008-3584</strong></p>
  <p>NetBSD 3.0, 3.1, and 4.0, when a pppoe instance exists, does not properly check the length of a PPPoE packet tag, which allows remote attackers to cause a denial of service (system crash) via a crafted PPPoE packet.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-3584">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-2464 – The mld_input function in sys/netinet6/mld6.c in the kernel in NetBSD 4.0, FreeB...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-2464</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-2464</guid>
    <pubDate>Thu, 11 Sep 2008 01:10:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-2464</strong></p>
  <p>The mld_input function in sys/netinet6/mld6.c in the kernel in NetBSD 4.0, FreeBSD, and KAME, when INET6 is enabled, allows remote attackers to cause a denial of service (divide-by-zero error and panic) via a malformed ICMPv6 Multicast Listener Discovery (MLD) query with a certain Maximum Response Delay value.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-189</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-2464">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-3530 – sys/netinet6/icmp6.c in the kernel in FreeBSD 6.3 through 7.1, NetBSD 3.0 throug...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-3530</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-3530</guid>
    <pubDate>Fri, 05 Sep 2008 16:08:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-3530</strong></p>
  <p>sys/netinet6/icmp6.c in the kernel in FreeBSD 6.3 through 7.1, NetBSD 3.0 through 4.0, and possibly other operating systems does not properly check the proposed new MTU in an ICMPv6 Packet Too Big Message, which allows remote attackers to cause a denial of service (panic) via a crafted Packet Too Big Message.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-3530">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-1391 – Multiple integer overflows in libc in NetBSD 4.x, FreeBSD 6.x and 7.x, and proba...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-1391</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-1391</guid>
    <pubDate>Thu, 27 Mar 2008 17:44:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-1391</strong></p>
  <p>Multiple integer overflows in libc in NetBSD 4.x, FreeBSD 6.x and 7.x, and probably other BSD and Apple Mac OS platforms allow context-dependent attackers to execute arbitrary code via large values of certain integer fields in the format argument to (1) the strfmon function in lib/libc/stdlib/strfmon.c, related to the GET_NUMBER macro; and (2) the printf function, related to left_prec and right_p…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-189</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-1391">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2008-1335 – The ipsec4_get_ulp function in the kernel in NetBSD 2.0 through 3.1 and NetBSD-c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-1335</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-1335</guid>
    <pubDate>Thu, 13 Mar 2008 18:44:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2008-1335</strong></p>
  <p>The ipsec4_get_ulp function in the kernel in NetBSD 2.0 through 3.1 and NetBSD-current before 20071028, when the fast_ipsec subsystem is enabled, allows remote attackers to bypass the IPsec policy by sending packets from a source machine with a different endianness than the destination machine, a different vulnerability than CVE-2006-0905.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-1335">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-1523 – Heap-based buffer overflow in the kernel in NetBSD 3.0, certain versions of Free...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-1523</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-1523</guid>
    <pubDate>Tue, 20 Mar 2007 20:19:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-1523</strong></p>
  <p>Heap-based buffer overflow in the kernel in NetBSD 3.0, certain versions of FreeBSD and OpenBSD, and possibly other BSD derived operating systems allows local users to have an unknown impact.  NOTE: this information is based upon a vague pre-advisory with no actionable information. Details will be updated after 20070329.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-1523">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2006-6652 – Buffer overflow in the glob implementation (glob.c) in libc in NetBSD-current be...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-6652</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-6652</guid>
    <pubDate>Wed, 20 Dec 2006 02:28:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2006-6652</strong></p>
  <p>Buffer overflow in the glob implementation (glob.c) in libc in NetBSD-current before 20050914, NetBSD 2.* and 3.* before 20061203, and Apple Mac OS X before 2007-004, as used by the FTP daemon and tnftpd, allows remote authenticated users to execute arbitrary code via a long pathname that results from path expansion.</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-6652">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-6165 – ld.so in FreeBSD, NetBSD, and possibly other BSD distributions does not remove c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-6165</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-6165</guid>
    <pubDate>Wed, 29 Nov 2006 01:28:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-6165</strong></p>
  <p>ld.so in FreeBSD, NetBSD, and possibly other BSD distributions does not remove certain harmful environment variables, which allows local users to gain privileges by passing certain environment variables to loading processes.  NOTE: this issue has been disputed by a third party, stating that it is the responsibility of the application to properly sanitize the environment</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-6165">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-6014 – The NetBSD-current kernel before 20061028 does not properly perform bounds check...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-6014</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-6014</guid>
    <pubDate>Tue, 21 Nov 2006 23:07:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-6014</strong></p>
  <p>The NetBSD-current kernel before 20061028 does not properly perform bounds checking of an unspecified userspace parameter in the ptrace system call during a PT_DUMPCORE request, which allows local users to have an unknown impact.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-6014">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2006-4304 – Buffer overflow in the sppp driver in FreeBSD 4.11 through 6.1, NetBSD 2.0 throu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-4304</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-4304</guid>
    <pubDate>Thu, 24 Aug 2006 01:04:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2006-4304</strong></p>
  <p>Buffer overflow in the sppp driver in FreeBSD 4.11 through 6.1, NetBSD 2.0 through 4.0 beta before 20060823, and OpenBSD 3.8 and 3.9 before 20060902 allows remote attackers to cause a denial of service (panic), obtain sensitive information, and possibly execute arbitrary code via crafted Link Control Protocol (LCP) packets with an option length that exceeds the overall length, which triggers the…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-4304">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-0905 – A "programming error" in fast_ipsec in FreeBSD 4.8-RELEASE through 6.1-STABLE an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-0905</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-0905</guid>
    <pubDate>Thu, 23 Mar 2006 11:06:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-0905</strong></p>
  <p>A "programming error" in fast_ipsec in FreeBSD 4.8-RELEASE through 6.1-STABLE and NetBSD 2 through 3 does not properly update the sequence number associated with a Security Association, which allows packets to pass sequence number checks and allows remote attackers to capture IPSec packets and conduct replay attacks.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-0905">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2005-4741 – NetBSD 1.6, NetBSD 2.0 through 2.1, and NetBSD-current before 20051031 allows lo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2005-4741</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2005-4741</guid>
    <pubDate>Sat, 31 Dec 2005 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2005-4741</strong></p>
  <p>NetBSD 1.6, NetBSD 2.0 through 2.1, and NetBSD-current before 20051031 allows local users to gain privileges by attaching a debugger to a setuid/setgid (P_SUGID) process that performs an exec without a reset of real credentials.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2005-4741">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2005-4776 – Integer overflow in the FreeBSD compatibility code (freebsd_misc.c) in NetBSD-cu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2005-4776</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2005-4776</guid>
    <pubDate>Sat, 31 Dec 2005 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2005-4776</strong></p>
  <p>Integer overflow in the FreeBSD compatibility code (freebsd_misc.c) in NetBSD-current, NetBSD-3, NetBSD-2.0, and NetBSD-2 before 20050913; and NetBSD-1.6 before 20050914; allows local users to cause a denial of service (heap corruption or system crash) and possibly gain root privileges.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2005-4776">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2004-2012 – The systrace_exit function in the systrace utility for NetBSD-current and 2.0 be...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2004-2012</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2004-2012</guid>
    <pubDate>Fri, 31 Dec 2004 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2004-2012</strong></p>
  <p>The systrace_exit function in the systrace utility for NetBSD-current and 2.0 before April 16, 2004, and certain FreeBSD ports, does not verify the owner of the /dec/systrace connection before setting euid to 0, which allows local users to gain root privileges.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2004-2012">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2004-1374 – Multiple buffer overflows in NetBSD kernel may allow local users to execute arbi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2004-1374</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2004-1374</guid>
    <pubDate>Sat, 18 Dec 2004 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2004-1374</strong></p>
  <p>Multiple buffer overflows in NetBSD kernel may allow local users to execute arbitrary code and gain privileges.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2004-1374">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2002-1500 – Buffer overflow in (1) mrinfo, (2) mtrace, and (3) pppd in NetBSD 1.4.x through ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2002-1500</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2002-1500</guid>
    <pubDate>Wed, 02 Apr 2003 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2002-1500</strong></p>
  <p>Buffer overflow in (1) mrinfo, (2) mtrace, and (3) pppd in NetBSD 1.4.x through 1.6 allows local users to gain privileges by executing the programs after filling the file descriptor tables, which produces file descriptors larger than FD_SETSIZE, which are not checked by FD_SET().</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2002-1500">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2002-1194 – Buffer overflow in talkd on NetBSD 1.6 and earlier, and possibly other operating...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2002-1194</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2002-1194</guid>
    <pubDate>Mon, 28 Oct 2002 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2002-1194</strong></p>
  <p>Buffer overflow in talkd on NetBSD 1.6 and earlier, and possibly other operating systems, may allow remote attackers to execute arbitrary code via a long inbound message.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2002-1194">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2002-0414 – KAME-derived implementations of IPsec on NetBSD 1.5.2, FreeBSD 4.5, and other op...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2002-0414</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2002-0414</guid>
    <pubDate>Mon, 12 Aug 2002 04:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2002-0414</strong></p>
  <p>KAME-derived implementations of IPsec on NetBSD 1.5.2, FreeBSD 4.5, and other operating systems, does not properly consult the Security Policy Database (SPD), which could cause a Security Gateway (SG) that does not use Encapsulating Security Payload (ESP) to forward forged IPv4 packets.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2002-0414">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2001-0734 – Hitachi Super-H architecture in NetBSD 1.5 and 1.4.1 allows a local user to gain...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2001-0734</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2001-0734</guid>
    <pubDate>Thu, 18 Oct 2001 04:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2001-0734</strong></p>
  <p>Hitachi Super-H architecture in NetBSD 1.5 and 1.4.1 allows a local user to gain privileges via modified Status Register contents, which are not properly handled by (1) the sigreturn system call or (2) the process_write_regs kernel routine.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2001-0734">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2001-1091 – The (1) dump and (2) dump_lfs commands in NetBSD 1.4.x through 1.5.1 do not prop...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2001-1091</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2001-1091</guid>
    <pubDate>Thu, 23 Aug 2001 04:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2001-1091</strong></p>
  <p>The (1) dump and (2) dump_lfs commands in NetBSD 1.4.x through 1.5.1 do not properly drop privileges, which could allow local users to gain privileges via the RCMD_CMD environment variable.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2001-1091">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2001-0268 – The i386_set_ldt system call in NetBSD 1.5 and earlier, and OpenBSD 2.8 and earl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2001-0268</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2001-0268</guid>
    <pubDate>Thu, 03 May 2001 04:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2001-0268</strong></p>
  <p>The i386_set_ldt system call in NetBSD 1.5 and earlier, and OpenBSD 2.8 and earlier, when the USER_LDT kernel option is enabled, does not validate a call gate target, which allows local users to gain root privileges by creating a segment call gate in the Local Descriptor Table (LDT) with a target that specifies an arbitrary kernel address.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2001-0268">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2001-0094 – Buffer overflow in kdc_reply_cipher of libkrb (Kerberos 4 authentication library...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2001-0094</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2001-0094</guid>
    <pubDate>Mon, 12 Feb 2001 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2001-0094</strong></p>
  <p>Buffer overflow in kdc_reply_cipher of libkrb (Kerberos 4 authentication library) in NetBSD 1.5 and FreeBSD 4.2 and earlier, as used in Kerberised applications such as telnetd and login, allows local users to gain root privileges.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2001-0094">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2000-0952 – global.cgi CGI program in Global 3.55 and earlier on NetBSD allows remote attack...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2000-0952</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2000-0952</guid>
    <pubDate>Tue, 19 Dec 2000 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2000-0952</strong></p>
  <p>global.cgi CGI program in Global 3.55 and earlier on NetBSD allows remote attackers to execute arbitrary commands via shell metacharacters.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2000-0952">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2000-0997 – Format string vulnerabilities in eeprom program in OpenBSD, NetBSD, and possibly...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2000-0997</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2000-0997</guid>
    <pubDate>Tue, 19 Dec 2000 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2000-0997</strong></p>
  <p>Format string vulnerabilities in eeprom program in OpenBSD, NetBSD, and possibly other operating systems allows local attackers to gain root privileges.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2000-0997">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2000-0157 – NetBSD ptrace call on VAX allows local users to gain privileges by modifying the...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2000-0157</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2000-0157</guid>
    <pubDate>Tue, 01 Feb 2000 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2000-0157</strong></p>
  <p>NetBSD ptrace call on VAX allows local users to gain privileges by modifying the PSL contents in the debugging process.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2000-0157">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-1999-0466 – The SVR4 /dev/wabi special device file in NetBSD 1.3.3 and earlier allows a loca...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-1999-0466</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-1999-0466</guid>
    <pubDate>Wed, 21 Apr 1999 04:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-1999-0466</strong></p>
  <p>The SVR4 /dev/wabi special device file in NetBSD 1.3.3 and earlier allows a local user to read or write arbitrary files on the disk associated with that device.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-1999-0466">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
