<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – NetBSD</title>
  <link>https://cvedaily.com/pages/tags/netbsd.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/netbsd.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – NetBSD</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:45 +0000</lastBuildDate>
  <item>
    <title>[Medium] CVE-2026-32849 – NetBSD prior to commit ec8451e contains a signed integer overflow vulnerability ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32849</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32849</guid>
    <pubDate>Mon, 18 May 2026 18:17:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-32849</strong></p>
  <p>NetBSD prior to commit ec8451e contains a signed integer overflow vulnerability in the cryptodev_op() function in sys/opencrypto/cryptodev.c where the local variable iov_len is declared as a signed int but assigned from an unsigned cop->dst_len value, causing undefined behavior when cop->dst_len exceeds INT_MAX. A local attacker with access to /dev/crypto and a compression session type can exploi…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32849">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-32848 – NetBSD prior to commit ec8451e contains a race condition vulnerability in crypto...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32848</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32848</guid>
    <pubDate>Mon, 18 May 2026 18:17:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-32848</strong></p>
  <p>NetBSD prior to commit ec8451e contains a race condition vulnerability in cryptodev_op() within the opencrypto subsystem that allows local attackers to trigger a double-free condition by concurrently issuing CIOCCRYPT operations on the same session identifier on SMP systems. Attackers can exploit mutable per-operation state embedded in the csession struct to corrupt kernel heap memory.</p>
  <p><strong>CVSS:</strong> 4.7 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32848">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7258 – In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7258</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7258</guid>
    <pubDate>Sun, 10 May 2026 05:16:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7258</strong></p>
  <p>In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, some functions, including urldecode(), pass signed char to ctype functions (like isxdigit()). On the systems with default signed char and optimized table-lookup ctype functions - such as NetBSD - this can lead to accessing array with negative offset, which can trigger a denial of service.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7258">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-45198 – ftpd before "NetBSD-ftpd 20230930" can leak information about the host filesyste...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-45198</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-45198</guid>
    <pubDate>Thu, 05 Oct 2023 05:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-45198</strong></p>
  <p>ftpd before "NetBSD-ftpd 20230930" can leak information about the host filesystem before authentication via an MLSD or MLST command. tnftpd (the portable version of NetBSD ftpd) before 20231001 is also vulnerable.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-45198">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-45489 – In NetBSD through 9.2, the IPv6 Flow Label generation algorithm employs a weak c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-45489</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-45489</guid>
    <pubDate>Sat, 25 Dec 2021 02:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-45489</strong></p>
  <p>In NetBSD through 9.2, the IPv6 Flow Label generation algorithm employs a weak cryptographic PRNG.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-338</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-45489">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-45488 – In NetBSD through 9.2, there is an information leak in the TCP ISN (ISS) generat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-45488</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-45488</guid>
    <pubDate>Sat, 25 Dec 2021 02:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-45488</strong></p>
  <p>In NetBSD through 9.2, there is an information leak in the TCP ISN (ISS) generation algorithm.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-330</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-45488">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-45487 – In NetBSD through 9.2, the IPv4 ID generation algorithm does not use appropriate...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-45487</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-45487</guid>
    <pubDate>Sat, 25 Dec 2021 02:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-45487</strong></p>
  <p>In NetBSD through 9.2, the IPv4 ID generation algorithm does not use appropriate cryptographic measures.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-330</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-45487">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-45484 – In NetBSD through 9.2, the IPv6 fragment ID generation algorithm employs a weak ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-45484</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-45484</guid>
    <pubDate>Sat, 25 Dec 2021 02:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-45484</strong></p>
  <p>In NetBSD through 9.2, the IPv6 fragment ID generation algorithm employs a weak cryptographic PRNG.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-338</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-45484">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-26139 – An issue was discovered in the kernel in NetBSD 7.1. An Access Point (AP) forwar...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-26139</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-26139</guid>
    <pubDate>Tue, 11 May 2021 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-26139</strong></p>
  <p>An issue was discovered in the kernel in NetBSD 7.1. An Access Point (AP) forwards EAPOL frames to other clients even though the sender has not yet successfully authenticated to the AP. This might be abused in projected Wi-Fi networks to launch denial-of-service attacks against connected clients and makes it easier to exploit other vulnerabilities in connected clients.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-26139">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-29568 – An issue was discovered in Xen through 4.14.x. Some OSes (such as Linux, FreeBSD...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-29568</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-29568</guid>
    <pubDate>Tue, 15 Dec 2020 17:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-29568</strong></p>
  <p>An issue was discovered in Xen through 4.14.x. Some OSes (such as Linux, FreeBSD, and NetBSD) are processing watch events using a single thread. If the events are received faster than the thread is able to handle, they will get queued. As the queue is unbounded, a guest may be able to trigger an OOM in the backend. All systems with a FreeBSD, Linux, or NetBSD (any version) dom0 are vulnerable.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-29568">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2012-5365 – The IPv6 implementation in FreeBSD and NetBSD (unknown versions, year 2012 and e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-5365</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-5365</guid>
    <pubDate>Thu, 20 Feb 2020 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2012-5365</strong></p>
  <p>The IPv6 implementation in FreeBSD and NetBSD (unknown versions, year 2012 and earlier) allows remote attackers to cause a denial of service via a flood of ICMPv6 Router Advertisement packets containing multiple Routing entries.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-5365">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2012-5363 – The IPv6 implementation in FreeBSD and NetBSD (unknown versions, year 2012 and e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-5363</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-5363</guid>
    <pubDate>Thu, 20 Feb 2020 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2012-5363</strong></p>
  <p>The IPv6 implementation in FreeBSD and NetBSD (unknown versions, year 2012 and earlier) allows remote attackers to cause a denial of service via a flood of ICMPv6 Neighbor Solicitation messages, a different vulnerability than CVE-2011-2393.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-5363">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2011-2480 – Information Disclosure vulnerability in the 802.11 stack, as used in FreeBSD bef...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-2480</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-2480</guid>
    <pubDate>Wed, 27 Nov 2019 19:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2011-2480</strong></p>
  <p>Information Disclosure vulnerability in the 802.11 stack, as used in FreeBSD before 8.2 and NetBSD when using certain non-x86 architectures. A signedness error in the IEEE80211_IOC_CHANINFO ioctl allows a local unprivileged user to cause the kernel to copy large amounts of kernel memory back to the user, disclosing potentially sensitive information.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-2480">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-15901 – An issue was discovered in slicer69 doas before 6.2 on certain platforms other t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-15901</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-15901</guid>
    <pubDate>Fri, 18 Oct 2019 16:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-15901</strong></p>
  <p>An issue was discovered in slicer69 doas before 6.2 on certain platforms other than OpenBSD. A setusercontext(3) call with flags to change the UID, primary GID, and secondary GIDs was replaced (on certain platforms: Linux and possibly NetBSD) with a single setuid(2) call. This resulted in neither changing the group id nor initializing secondary group ids.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-15901">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2017-17080 – elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-17080</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-17080</guid>
    <pubDate>Thu, 30 Nov 2017 21:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2017-17080</strong></p>
  <p>elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, does not validate sizes of core notes, which allows remote attackers to cause a denial of service (bfd_getl32 heap-based buffer over-read and application crash) via a crafted object file, related to elfcore_grok_netbsd_procinfo, elfcore_grok_openbsd_procinfo, and elfcore_grok_nto_status.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-17080">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-1000378 – The NetBSD qsort() function is recursive, and not randomized, an attacker can co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-1000378</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-1000378</guid>
    <pubDate>Mon, 19 Jun 2017 16:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-1000378</strong></p>
  <p>The NetBSD qsort() function is recursive, and not randomized, an attacker can construct a pathological input array of N elements that causes qsort() to deterministically recurse N/4 times. This allows attackers to consume arbitrary amounts of stack memory and manipulate stack memory to assist in arbitrary code execution attacks. This affects NetBSD 7.1 and possibly earlier versions.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-1000378">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-1000375 – NetBSD maps the run-time link-editor ld.so directly below the stack region, even...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-1000375</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-1000375</guid>
    <pubDate>Mon, 19 Jun 2017 16:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-1000375</strong></p>
  <p>NetBSD maps the run-time link-editor ld.so directly below the stack region, even if ASLR is enabled, this allows attackers to more easily manipulate memory leading to arbitrary code execution. This affects NetBSD 7.1 and possibly earlier versions.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-1000375">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-1000374 – A flaw exists in NetBSD's implementation of the stack guard page that allows att...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-1000374</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-1000374</guid>
    <pubDate>Mon, 19 Jun 2017 16:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-1000374</strong></p>
  <p>A flaw exists in NetBSD's implementation of the stack guard page that allows attackers to bypass it resulting in arbitrary code execution using certain setuid binaries. This affects NetBSD 7.1 and possibly earlier versions.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-1000374">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-8283 – dpkg-source in dpkg 1.3.0 through 1.18.23 is able to use a non-GNU patch program...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-8283</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-8283</guid>
    <pubDate>Wed, 26 Apr 2017 05:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-8283</strong></p>
  <p>dpkg-source in dpkg 1.3.0 through 1.18.23 is able to use a non-GNU patch program and does not offer a protection mechanism for blank-indented diff hunks, which allows remote attackers to conduct directory traversal attacks via a crafted Debian source package, as demonstrated by use of dpkg-source on NetBSD.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-8283">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-6253 – mail.local in NetBSD versions 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-6253</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-6253</guid>
    <pubDate>Fri, 20 Jan 2017 15:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-6253</strong></p>
  <p>mail.local in NetBSD versions 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows local users to change ownership of or append data to arbitrary files on the target system via a symlink attack on the user mailbox.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6253">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2015-8212 – CGI handling flaw in bozohttpd in NetBSD 6.0 through 6.0.6, 6.1 through 6.1.5, a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-8212</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-8212</guid>
    <pubDate>Thu, 19 Jan 2017 20:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2015-8212</strong></p>
  <p>CGI handling flaw in bozohttpd in NetBSD 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows remote attackers to execute arbitrary code via crafted arguments, which are handled by a non-CGI aware program.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-8212">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2015-2305 – Integer overflow in the regcomp implementation in the Henry Spencer BSD regex li...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-2305</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-2305</guid>
    <pubDate>Mon, 30 Mar 2015 10:59:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2015-2305</strong></p>
  <p>Integer overflow in the regcomp implementation in the Henry Spencer BSD regex library (aka rxspencer) alpha3.8.g5 on 32-bit platforms, as used in NetBSD through 6.1.5 and other products, might allow context-dependent attackers to execute arbitrary code via a large regular expression that leads to a heap-based buffer overflow.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-2305">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2014-7250 – The TCP stack in 4.3BSD Net/2, as used in FreeBSD 5.4, NetBSD possibly 2.0, and ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-7250</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-7250</guid>
    <pubDate>Fri, 12 Dec 2014 03:03:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2014-7250</strong></p>
  <p>The TCP stack in 4.3BSD Net/2, as used in FreeBSD 5.4, NetBSD possibly 2.0, and OpenBSD possibly 3.6, does not properly implement the session timer, which allows remote attackers to cause a denial of service (resource consumption) via crafted packets.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-7250">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2014-8517 – The fetch_url function in usr.bin/ftp/fetch.c in tnftp, as used in NetBSD 5.1 th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-8517</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-8517</guid>
    <pubDate>Mon, 17 Nov 2014 16:59:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2014-8517</strong></p>
  <p>The fetch_url function in usr.bin/ftp/fetch.c in tnftp, as used in NetBSD 5.1 through 5.1.4, 5.2 through 5.2.2, 6.0 through 6.0.6, and 6.1 through 6.1.5 allows remote attackers to execute arbitrary commands via a | (pipe) character at the end of an HTTP redirect.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-8517">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2014-5384 – The VIQR module in the iconv implementation in FreeBSD 10.0 before p6 and NetBSD...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-5384</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-5384</guid>
    <pubDate>Thu, 21 Aug 2014 22:55:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2014-5384</strong></p>
  <p>The VIQR module in the iconv implementation in FreeBSD 10.0 before p6 and NetBSD allows context-dependent attackers to cause a denial of service (out-of-bounds array access) via a crafted argument to the iconv_open function.  NOTE: this issue was SPLIT from CVE-2014-3951 per ADT2 due to different vulnerability types.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-5384">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2014-3951 – The HZ module in the iconv implementation in FreeBSD 10.0 before p6 and NetBSD a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-3951</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-3951</guid>
    <pubDate>Thu, 21 Aug 2014 22:55:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2014-3951</strong></p>
  <p>The HZ module in the iconv implementation in FreeBSD 10.0 before p6 and NetBSD allows context-dependent attackers to cause a denial of service (NULL pointer dereference) via a crafted argument to the iconv_open function.  NOTE: this issue was SPLIT per ADT2 due to different vulnerability types. CVE-2014-5384 is used for the NULL pointer dereference.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-3951">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2014-5015 – bozotic HTTP server (aka bozohttpd) before 20140708, as used in NetBSD, truncate...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-5015</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-5015</guid>
    <pubDate>Thu, 24 Jul 2014 14:55:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2014-5015</strong></p>
  <p>bozotic HTTP server (aka bozohttpd) before 20140708, as used in NetBSD, truncates paths when checking .htpasswd restrictions, which allows remote attackers to bypass the HTTP authentication scheme and access restrictions via a long path.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-5015">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2007-6754 – The ipalloc function in libc/stdlib/malloc.c in jemalloc in libc for FreeBSD 6.4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-6754</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-6754</guid>
    <pubDate>Wed, 25 Jul 2012 19:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2007-6754</strong></p>
  <p>The ipalloc function in libc/stdlib/malloc.c in jemalloc in libc for FreeBSD 6.4 and NetBSD does not properly allocate memory, which makes it easier for context-dependent attackers to perform memory-related attacks such as buffer overflows via a large size value, related to "integer rounding and overflow" errors.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-189</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-6754">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2006-7252 – Integer overflow in the calloc function in libc/stdlib/malloc.c in jemalloc in l...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-7252</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-7252</guid>
    <pubDate>Wed, 25 Jul 2012 19:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2006-7252</strong></p>
  <p>Integer overflow in the calloc function in libc/stdlib/malloc.c in jemalloc in libc for FreeBSD 6.4 and NetBSD makes it easier for context-dependent attackers to perform memory-related attacks such as buffer overflows via a large size value, which triggers a memory allocation of one byte.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-189</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-7252">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2012-0217 – The x86-64 kernel system-call functionality in Xen 4.1.2 and earlier, as used in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-0217</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-0217</guid>
    <pubDate>Tue, 12 Jun 2012 22:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2012-0217</strong></p>
  <p>The x86-64 kernel system-call functionality in Xen 4.1.2 and earlier, as used in Citrix XenServer 6.0.2 and earlier and other products; Oracle Solaris 11 and earlier; illumos before r13724; Joyent SmartOS before 20120614T184600Z; FreeBSD before 9.0-RELEASE-p3; NetBSD 6.0 Beta and earlier; Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1; and possibly other operating systems,…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-0217">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2011-2393 – The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in FreeBSD...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-2393</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-2393</guid>
    <pubDate>Thu, 02 Feb 2012 17:55:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2011-2393</strong></p>
  <p>The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in FreeBSD, NetBSD, and possibly other BSD-based operating systems allows remote attackers to cause a denial of service (CPU consumption and device hang) by sending many Router Advertisement (RA) messages with different source addresses, a similar vulnerability to CVE-2010-4670.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-2393">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2011-2895 – The LZW decompressor in (1) the BufCompressedFill function in fontfile/decompres...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-2895</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-2895</guid>
    <pubDate>Fri, 19 Aug 2011 17:55:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2011-2895</strong></p>
  <p>The LZW decompressor in (1) the BufCompressedFill function in fontfile/decompress.c in X.Org libXfont before 1.4.4 and (2) compress/compress.c in 4.3BSD, as used in zopen.c in OpenBSD before 3.8, FreeBSD, NetBSD 4.0.x and 5.0.x before 5.0.3 and 5.1.x before 5.1.1, FreeType 2.1.9, and other products, does not properly handle code words that are absent from the decompression table when encountered,…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-2895">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2011-0418 – The glob implementation in Pure-FTPd before 1.0.32, and in libc in NetBSD 5.1, d...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-0418</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-0418</guid>
    <pubDate>Tue, 24 May 2011 23:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2011-0418</strong></p>
  <p>The glob implementation in Pure-FTPd before 1.0.32, and in libc in NetBSD 5.1, does not properly expand expressions containing curly brackets, which allows remote authenticated users to cause a denial of service (memory consumption) via a crafted FTP STAT command.</p>
  <p><strong>CVSS:</strong> 4.0 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-0418">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2011-1920 – The make include files in NetBSD before 1.6.2, as used in pmake 1.111 and other ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-1920</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-1920</guid>
    <pubDate>Mon, 23 May 2011 22:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2011-1920</strong></p>
  <p>The make include files in NetBSD before 1.6.2, as used in pmake 1.111 and other products, allow local users to overwrite arbitrary files via a symlink attack on a /tmp/_depend##### temporary file, related to (1) bsd.lib.mk and (2) bsd.prog.mk.</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-1920">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2011-0419 – Stack consumption vulnerability in the fnmatch implementation in apr_fnmatch.c i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-0419</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-0419</guid>
    <pubDate>Mon, 16 May 2011 17:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2011-0419</strong></p>
  <p>Stack consumption vulnerability in the fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library before 1.4.3 and the Apache HTTP Server before 2.2.18, and in fnmatch.c in libc in NetBSD 5.1, OpenBSD 4.8, FreeBSD, Apple Mac OS X 10.6, Oracle Solaris 10, and Android, allows context-dependent attackers to cause a denial of service (CPU and memory consumption) via *? seque…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-0419">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2011-1547 – Multiple stack consumption vulnerabilities in the kernel in NetBSD 4.0, 5.0 befo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-1547</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-1547</guid>
    <pubDate>Mon, 09 May 2011 19:55:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2011-1547</strong></p>
  <p>Multiple stack consumption vulnerabilities in the kernel in NetBSD 4.0, 5.0 before 5.0.3, and 5.1 before 5.1.1, when IPsec is enabled, allow remote attackers to cause a denial of service (memory corruption and panic) or possibly have unspecified other impact via a crafted (1) IPv4 or (2) IPv6 packet with nested IPComp headers.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-1547">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2010-4755 – The (1) remote_glob function in sftp-glob.c and the (2) process_put function in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-4755</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-4755</guid>
    <pubDate>Wed, 02 Mar 2011 20:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2010-4755</strong></p>
  <p>The (1) remote_glob function in sftp-glob.c and the (2) process_put function in sftp.c in OpenSSH 5.8 and earlier, as used in FreeBSD 7.3 and 8.1, NetBSD 5.0.2, OpenBSD 4.7, and other products, allow remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in SSH_FXP_STAT…</p>
  <p><strong>CVSS:</strong> 4.0 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-4755">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2010-4754 – The glob implementation in libc in FreeBSD 7.3 and 8.1, NetBSD 5.0.2, and OpenBS...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-4754</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-4754</guid>
    <pubDate>Wed, 02 Mar 2011 20:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2010-4754</strong></p>
  <p>The glob implementation in libc in FreeBSD 7.3 and 8.1, NetBSD 5.0.2, and OpenBSD 4.7, and Libsystem in Apple Mac OS X before 10.6.8, allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-…</p>
  <p><strong>CVSS:</strong> 4.0 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-4754">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2010-2530 – Multiple integer signedness errors in smb_subr.c in the netsmb module in the ker...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-2530</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-2530</guid>
    <pubDate>Wed, 29 Sep 2010 17:00:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2010-2530</strong></p>
  <p>Multiple integer signedness errors in smb_subr.c in the netsmb module in the kernel in NetBSD 5.0.2 and earlier, FreeBSD, and Apple Mac OS X allow local users to cause a denial of service (panic) via a negative size value in a /dev/nsmb ioctl operation, as demonstrated by a (1) SMBIOC_LOOKUP or (2) SMBIOC_OPENSESSION ioctl call.</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-189</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-2530">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2010-3014 – The Coda filesystem kernel module, as used in NetBSD and FreeBSD, when Coda is l...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-3014</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-3014</guid>
    <pubDate>Fri, 20 Aug 2010 20:00:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2010-3014</strong></p>
  <p>The Coda filesystem kernel module, as used in NetBSD and FreeBSD, when Coda is loaded and Venus is running with /coda mounted, allows local users to read sensitive heap memory via a large out_size value in a ViceIoctl struct to a Coda ioctl, which triggers a buffer over-read.</p>
  <p><strong>CVSS:</strong> 1.2 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-3014">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2010-0561 – Integer signedness error in NetBSD 4.0, 5.0, and NetBSD-current before 2010-01-2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-0561</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-0561</guid>
    <pubDate>Mon, 08 Feb 2010 21:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2010-0561</strong></p>
  <p>Integer signedness error in NetBSD 4.0, 5.0, and NetBSD-current before 2010-01-21 allows local users to cause a denial of service (kernel panic) via a negative mixer index number being passed to (1) the azalia_query_devinfo function in the azalia audio driver (src/sys/dev/pci/azalia.c) or (2) the hdaudio_afg_query_devinfo function in the hdaudio audio driver (src/sys/dev/pci/hdaudio/hdaudio_afg.c…</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-189</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-0561">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2009-2793 – The kernel in NetBSD, probably 5.0.1 and earlier, on x86 platforms does not prop...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-2793</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-2793</guid>
    <pubDate>Fri, 18 Sep 2009 22:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2009-2793</strong></p>
  <p>The kernel in NetBSD, probably 5.0.1 and earlier, on x86 platforms does not properly handle a pre-commit failure of the iret instruction, which might allow local users to gain privileges via vectors related to a tempEIP pseudocode variable that is outside of the code-segment limits.</p>
  <p><strong>CVSS:</strong> 4.6 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-2793">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2009-0687 – The pf_test_rule function in OpenBSD Packet Filter (PF), as used in OpenBSD 4.2 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-0687</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-0687</guid>
    <pubDate>Tue, 11 Aug 2009 10:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2009-0687</strong></p>
  <p>The pf_test_rule function in OpenBSD Packet Filter (PF), as used in OpenBSD 4.2 through 4.5, NetBSD 5.0 before RC3, MirOS 10 and earlier, and MidnightBSD 0.3-current allows remote attackers to cause a denial of service (panic) via crafted IP packets that trigger a NULL pointer dereference during translation, related to an IPv4 packet with an ICMPv6 payload.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-0687">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2009-2483 – libprop/prop_object.c in proplib in NetBSD 4.0 and 4.0.1 allows local users to c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-2483</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-2483</guid>
    <pubDate>Thu, 16 Jul 2009 16:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2009-2483</strong></p>
  <p>libprop/prop_object.c in proplib in NetBSD 4.0 and 4.0.1 allows local users to cause a denial of service (NULL pointer dereference and kernel panic) via a malformed externalized plist (XML form) containing an undefined element.</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-189</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-2483">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2009-2482 – The pam_unix module in OpenPAM in NetBSD 4.0 before 4.0.2 and 5.0 before 5.0.1 a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-2482</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-2482</guid>
    <pubDate>Thu, 16 Jul 2009 16:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2009-2482</strong></p>
  <p>The pam_unix module in OpenPAM in NetBSD 4.0 before 4.0.2 and 5.0 before 5.0.1 allows local users to change the current root password if it is already known, even when they are not in the wheel group.</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-2482">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2009-0689 – Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-0689</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-0689</guid>
    <pubDate>Wed, 01 Jul 2009 13:00:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2009-0689</strong></p>
  <p>Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the (2) gdtoa (aka new dtoa) implementation in gdtoa/misc.c in libc, as used in multiple operating systems and products including in FreeBSD 6.4 and 7.2, NetBSD 5.0, OpenBSD 4.5, Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4, K-Meleon 1.5.3, SeaMonkey 1.1.8, and other products, allows context-dependent attac…</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-0689">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2008-2476 – The IPv6 Neighbor Discovery Protocol (NDP) implementation in (1) FreeBSD 6.3 thr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-2476</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-2476</guid>
    <pubDate>Fri, 03 Oct 2008 15:07:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2008-2476</strong></p>
  <p>The IPv6 Neighbor Discovery Protocol (NDP) implementation in (1) FreeBSD 6.3 through 7.1, (2) OpenBSD 4.2 and 4.3, (3) NetBSD, (4) Force10 FTOS before E7.7.1.1, (5) Juniper JUNOS, and (6) Wind River VxWorks 5.x through 6.4 does not validate the origin of Neighbor Discovery messages, which allows remote attackers to cause a denial of service (loss of connectivity) or read private network traffic v…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-2476">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-4247 – ftpd in OpenBSD 4.3, FreeBSD 7.0, NetBSD 4.0, Solaris, and possibly other operat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-4247</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-4247</guid>
    <pubDate>Thu, 25 Sep 2008 19:25:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-4247</strong></p>
  <p>ftpd in OpenBSD 4.3, FreeBSD 7.0, NetBSD 4.0, Solaris, and possibly other operating systems interprets long commands from an FTP client as multiple commands, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and execute arbitrary FTP commands via a long ftp:// URI that leverages an existing session from the FTP client implementation in a web browser.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-4247">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2008-3584 – NetBSD 3.0, 3.1, and 4.0, when a pppoe instance exists, does not properly check ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-3584</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-3584</guid>
    <pubDate>Thu, 11 Sep 2008 21:06:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2008-3584</strong></p>
  <p>NetBSD 3.0, 3.1, and 4.0, when a pppoe instance exists, does not properly check the length of a PPPoE packet tag, which allows remote attackers to cause a denial of service (system crash) via a crafted PPPoE packet.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-3584">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-2464 – The mld_input function in sys/netinet6/mld6.c in the kernel in NetBSD 4.0, FreeB...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-2464</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-2464</guid>
    <pubDate>Thu, 11 Sep 2008 01:10:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-2464</strong></p>
  <p>The mld_input function in sys/netinet6/mld6.c in the kernel in NetBSD 4.0, FreeBSD, and KAME, when INET6 is enabled, allows remote attackers to cause a denial of service (divide-by-zero error and panic) via a malformed ICMPv6 Multicast Listener Discovery (MLD) query with a certain Maximum Response Delay value.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-189</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-2464">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-3530 – sys/netinet6/icmp6.c in the kernel in FreeBSD 6.3 through 7.1, NetBSD 3.0 throug...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-3530</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-3530</guid>
    <pubDate>Fri, 05 Sep 2008 16:08:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-3530</strong></p>
  <p>sys/netinet6/icmp6.c in the kernel in FreeBSD 6.3 through 7.1, NetBSD 3.0 through 4.0, and possibly other operating systems does not properly check the proposed new MTU in an ICMPv6 Packet Too Big Message, which allows remote attackers to cause a denial of service (panic) via a crafted Packet Too Big Message.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-3530">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-1391 – Multiple integer overflows in libc in NetBSD 4.x, FreeBSD 6.x and 7.x, and proba...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-1391</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-1391</guid>
    <pubDate>Thu, 27 Mar 2008 17:44:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-1391</strong></p>
  <p>Multiple integer overflows in libc in NetBSD 4.x, FreeBSD 6.x and 7.x, and probably other BSD and Apple Mac OS platforms allow context-dependent attackers to execute arbitrary code via large values of certain integer fields in the format argument to (1) the strfmon function in lib/libc/stdlib/strfmon.c, related to the GET_NUMBER macro; and (2) the printf function, related to left_prec and right_p…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-189</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-1391">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2008-1335 – The ipsec4_get_ulp function in the kernel in NetBSD 2.0 through 3.1 and NetBSD-c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-1335</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-1335</guid>
    <pubDate>Thu, 13 Mar 2008 18:44:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2008-1335</strong></p>
  <p>The ipsec4_get_ulp function in the kernel in NetBSD 2.0 through 3.1 and NetBSD-current before 20071028, when the fast_ipsec subsystem is enabled, allows remote attackers to bypass the IPsec policy by sending packets from a source machine with a different endianness than the destination machine, a different vulnerability than CVE-2006-0905.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-1335">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2008-1215 – Stack-based buffer overflow in the command_Expand_Interpret function in command...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-1215</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-1215</guid>
    <pubDate>Sun, 09 Mar 2008 02:44:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2008-1215</strong></p>
  <p>Stack-based buffer overflow in the command_Expand_Interpret function in command.c in ppp (aka user-ppp), as distributed in FreeBSD 6.3 and 7.0, OpenBSD 4.1 and 4.2, and the net/userppp package for NetBSD, allows local users to gain privileges via long commands containing "~" characters.</p>
  <p><strong>CVSS:</strong> 4.6 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-1215">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2008-1148 – A certain pseudo-random number generator (PRNG) algorithm that uses ADD with 0 r...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-1148</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-1148</guid>
    <pubDate>Tue, 04 Mar 2008 23:44:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2008-1148</strong></p>
  <p>A certain pseudo-random number generator (PRNG) algorithm that uses ADD with 0 random hops (aka "Algorithm A0"), as used in OpenBSD 3.5 through 4.2 and NetBSD 1.6.2 through 4.0, allows remote attackers to guess sensitive values such as (1) DNS transaction IDs or (2) IP fragmentation IDs by observing a sequence of previously generated values.  NOTE: this issue can be leveraged for attacks such as…</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-1148">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2007-3654 – The display driver allocattr functions in NetBSD 3.0 through 4.0_BETA2, and NetB...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-3654</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-3654</guid>
    <pubDate>Mon, 17 Sep 2007 17:17:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2007-3654</strong></p>
  <p>The display driver allocattr functions in NetBSD 3.0 through 4.0_BETA2, and NetBSD-current before 20070728, allow local users to cause a denial of service (panic) via a (1) negative or (2) large value in an ioctl call, as demonstrated by the vga_allocattr function.</p>
  <p><strong>CVSS:</strong> 2.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-3654">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2007-4305 – Multiple race conditions in the (1) Sudo monitor mode and (2) Sysjail policies i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-4305</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-4305</guid>
    <pubDate>Mon, 13 Aug 2007 21:17:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2007-4305</strong></p>
  <p>Multiple race conditions in the (1) Sudo monitor mode and (2) Sysjail policies in Systrace on NetBSD and OpenBSD allow local users to defeat system call interposition, and consequently bypass access control policy and auditing.</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-4305">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2007-1677 – Multiple buffer overflows in the ISO network protocol support in the NetBSD kern...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-1677</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-1677</guid>
    <pubDate>Fri, 30 Mar 2007 00:19:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2007-1677</strong></p>
  <p>Multiple buffer overflows in the ISO network protocol support in the NetBSD kernel 2.0 through 4.0_BETA2, and NetBSD-current before 20070329, allow local users to execute arbitrary code via long parameters to certain functions, as demonstrated by a long sockaddr structure argument to the clnp_route function.</p>
  <p><strong>CVSS:</strong> 6.6 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-1677">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-1523 – Heap-based buffer overflow in the kernel in NetBSD 3.0, certain versions of Free...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-1523</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-1523</guid>
    <pubDate>Tue, 20 Mar 2007 20:19:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-1523</strong></p>
  <p>Heap-based buffer overflow in the kernel in NetBSD 3.0, certain versions of FreeBSD and OpenBSD, and possibly other BSD derived operating systems allows local users to have an unknown impact.  NOTE: this information is based upon a vague pre-advisory with no actionable information. Details will be updated after 20070329.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-1523">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2007-1273 – Integer overflow in the ktruser function in NetBSD-current before 20061022, NetB...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-1273</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-1273</guid>
    <pubDate>Sat, 10 Mar 2007 20:19:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2007-1273</strong></p>
  <p>Integer overflow in the ktruser function in NetBSD-current before 20061022, NetBSD 3 and 3-0 before 20061024, and NetBSD 2 before 20070209, when the kernel is built with the COMPAT_FREEBSD or COMPAT_DARWIN option, allows local users to cause a denial of service and possibly gain privileges.</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-1273">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2006-6730 – OpenBSD and NetBSD permit usermode code to kill the display server and write to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-6730</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-6730</guid>
    <pubDate>Tue, 26 Dec 2006 23:28:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2006-6730</strong></p>
  <p>OpenBSD and NetBSD permit usermode code to kill the display server and write to the X.Org /dev/xf86 device, which allows local users with root privileges to reduce securelevel by replacing the System Management Mode (SMM) handler via a write to an SMRAM address within /dev/xf86 (aka the video card memory-mapped I/O range), and then launching the new handler via a System Management Interrupt (SMI)…</p>
  <p><strong>CVSS:</strong> 6.6 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-6730">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2006-6652 – Buffer overflow in the glob implementation (glob.c) in libc in NetBSD-current be...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-6652</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-6652</guid>
    <pubDate>Wed, 20 Dec 2006 02:28:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2006-6652</strong></p>
  <p>Buffer overflow in the glob implementation (glob.c) in libc in NetBSD-current before 20050914, NetBSD 2.* and 3.* before 20061203, and Apple Mac OS X before 2007-004, as used by the FTP daemon and tnftpd, allows remote authenticated users to execute arbitrary code via a long pathname that results from path expansion.</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-6652">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2006-6653 – The accept function in NetBSD-current before 20061023, NetBSD 3.0 and 3.0.1 befo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-6653</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-6653</guid>
    <pubDate>Wed, 20 Dec 2006 02:28:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2006-6653</strong></p>
  <p>The accept function in NetBSD-current before 20061023, NetBSD 3.0 and 3.0.1 before 20061024, and NetBSD 2.x before 20061029 allows local users to cause a denial of service (socket consumption) via an invalid (1) name or (2) namelen parameter, which may result in the socket never being closed (aka "a dangling socket").</p>
  <p><strong>CVSS:</strong> 1.7 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-6653">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2006-6654 – The sendmsg function in NetBSD-current before 20061023, NetBSD 3.0 and 3.0.1 bef...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-6654</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-6654</guid>
    <pubDate>Wed, 20 Dec 2006 02:28:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2006-6654</strong></p>
  <p>The sendmsg function in NetBSD-current before 20061023, NetBSD 3.0 and 3.0.1 before 20061024, and NetBSD 2.x before 20061029, when run on a 64-bit architecture, allows attackers to cause a denial of service (kernel panic) via an invalid msg_controllen parameter to the sendit function.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-6654">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2006-6655 – The procfs implementation in NetBSD-current before 20061023, NetBSD 3.0 and 3.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-6655</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-6655</guid>
    <pubDate>Wed, 20 Dec 2006 02:28:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2006-6655</strong></p>
  <p>The procfs implementation in NetBSD-current before 20061023, NetBSD 3.0 and 3.0.1 before 20061024, and NetBSD 2.x before 20061029 allows local users to cause a denial of service (kernel panic) by attempting to access /emul/linux/proc/0/stat on a procfs filesystem that was mounted with mount_procfs -o linux, which results in a NULL pointer dereference.</p>
  <p><strong>CVSS:</strong> 1.7 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-6655">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2006-6656 – Unspecified vulnerability in ptrace in NetBSD-current before 20061027, NetBSD 3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-6656</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-6656</guid>
    <pubDate>Wed, 20 Dec 2006 02:28:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2006-6656</strong></p>
  <p>Unspecified vulnerability in ptrace in NetBSD-current before 20061027, NetBSD 3.0 and 3.0.1 before 20061027, and NetBSD 2.x before 20061119 allows local users to read kernel memory and obtain sensitive information via certain manipulations of a PT_LWPINFO request, which leads to a memory leak and information leak.</p>
  <p><strong>CVSS:</strong> 2.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-6656">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2006-6657 – The if_clone_list function in NetBSD-current before 20061027, NetBSD 3.0 and 3.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-6657</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-6657</guid>
    <pubDate>Wed, 20 Dec 2006 02:28:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2006-6657</strong></p>
  <p>The if_clone_list function in NetBSD-current before 20061027, NetBSD 3.0 and 3.0.1 before 20061027, and NetBSD 2.x before 20061119 allows local users to read potentially sensitive, uninitialized stack memory via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 2.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-6657">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2006-6397 – Integer overflow in banner/banner.c in FreeBSD, NetBSD, and OpenBSD might allow ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-6397</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-6397</guid>
    <pubDate>Fri, 08 Dec 2006 01:28:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2006-6397</strong></p>
  <p>Integer overflow in banner/banner.c in FreeBSD, NetBSD, and OpenBSD might allow local users to modify memory via a long banner.  NOTE: CVE and multiple third parties dispute this issue. Since banner is not setuid, an exploit would not cross privilege boundaries in normal operations. This issue is not a vulnerability</p>
  <p><strong>CVSS:</strong> 4.4 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-6397">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-6165 – ld.so in FreeBSD, NetBSD, and possibly other BSD distributions does not remove c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-6165</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-6165</guid>
    <pubDate>Wed, 29 Nov 2006 01:28:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-6165</strong></p>
  <p>ld.so in FreeBSD, NetBSD, and possibly other BSD distributions does not remove certain harmful environment variables, which allows local users to gain privileges by passing certain environment variables to loading processes.  NOTE: this issue has been disputed by a third party, stating that it is the responsibility of the application to properly sanitize the environment</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-6165">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2006-6013 – Integer signedness error in the fw_ioctl (FW_IOCTL) function in the FireWire (IE...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-6013</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-6013</guid>
    <pubDate>Tue, 21 Nov 2006 23:07:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2006-6013</strong></p>
  <p>Integer signedness error in the fw_ioctl (FW_IOCTL) function in the FireWire (IEEE-1394) drivers (dev/firewire/fwdev.c) in various BSD kernels, including DragonFlyBSD, FreeBSD 5.5, MidnightBSD 0.1-CURRENT before 20061115, NetBSD-current before 20061116, NetBSD-4 before 20061203, and TrustedBSD, allows local users to read arbitrary memory contents via certain negative values of crom_buf->len in an…</p>
  <p><strong>CVSS:</strong> 2.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-6013">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-6014 – The NetBSD-current kernel before 20061028 does not properly perform bounds check...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-6014</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-6014</guid>
    <pubDate>Tue, 21 Nov 2006 23:07:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-6014</strong></p>
  <p>The NetBSD-current kernel before 20061028 does not properly perform bounds checking of an unspecified userspace parameter in the ptrace system call during a PT_DUMPCORE request, which allows local users to have an unknown impact.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-6014">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2006-5214 – Race condition in the Xsession script, as used by X Display Manager (xdm) in Net...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-5214</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-5214</guid>
    <pubDate>Tue, 10 Oct 2006 04:06:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2006-5214</strong></p>
  <p>Race condition in the Xsession script, as used by X Display Manager (xdm) in NetBSD before 20060212, X.Org before 20060225, and Solaris 8 through 10 before 20061006, causes a user's Xsession errors file to have weak permissions before a chmod is performed, which allows local users to read Xsession errors files of other users.</p>
  <p><strong>CVSS:</strong> 1.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-5214">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2006-5215 – The Xsession script, as used by X Display Manager (xdm) in NetBSD before 2006021...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-5215</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-5215</guid>
    <pubDate>Tue, 10 Oct 2006 04:06:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2006-5215</strong></p>
  <p>The Xsession script, as used by X Display Manager (xdm) in NetBSD before 20060212, X.Org before 20060317, and Solaris 8 through 10 before 20061006, allows local users to overwrite arbitrary files, or read another user's Xsession errors file, via a symlink attack on a /tmp/xses-$USER file.</p>
  <p><strong>CVSS:</strong> 2.6 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-5215">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2006-5218 – Integer overflow in the systrace_preprepl function (STRIOCREPLACE) in systrace i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-5218</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-5218</guid>
    <pubDate>Tue, 10 Oct 2006 04:06:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2006-5218</strong></p>
  <p>Integer overflow in the systrace_preprepl function (STRIOCREPLACE) in systrace in OpenBSD 3.9 and NetBSD 3 allows local users to cause a denial of service (crash), gain privileges, or read arbitrary kernel memory via large numeric arguments to the systrace ioctl.</p>
  <p><strong>CVSS:</strong> 4.6 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-5218">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2006-4304 – Buffer overflow in the sppp driver in FreeBSD 4.11 through 6.1, NetBSD 2.0 throu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-4304</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-4304</guid>
    <pubDate>Thu, 24 Aug 2006 01:04:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2006-4304</strong></p>
  <p>Buffer overflow in the sppp driver in FreeBSD 4.11 through 6.1, NetBSD 2.0 through 4.0 beta before 20060823, and OpenBSD 3.8 and 3.9 before 20060902 allows remote attackers to cause a denial of service (panic), obtain sensitive information, and possibly execute arbitrary code via crafted Link Control Protocol (LCP) packets with an option length that exceeds the overall length, which triggers the…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-4304">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2006-3202 – The ip6_savecontrol function in NetBSD 2.0 through 3.0, under certain configurat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-3202</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-3202</guid>
    <pubDate>Fri, 23 Jun 2006 20:06:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2006-3202</strong></p>
  <p>The ip6_savecontrol function in NetBSD 2.0 through 3.0, under certain configurations, does not check to see if IPv4-mapped sockets are being used before processing IPv6 socket options, which allows local users to cause a denial of service (crash) by creating an IPv4-mapped IPv6 socket with the SO_TIMESTAMP socket option set, then sending an IPv4 packet through the socket.</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-3202">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2006-2205 – The audio_write function in NetBSD 3.0 allows local users to cause a denial of s...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-2205</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-2205</guid>
    <pubDate>Fri, 05 May 2006 12:46:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2006-2205</strong></p>
  <p>The audio_write function in NetBSD 3.0 allows local users to cause a denial of service (kernel crash) by using the audiosetinfo ioctl to change the sample rate of an audio device.</p>
  <p><strong>CVSS:</strong> 2.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-2205">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2006-1833 – Intel RNG Driver in NetBSD 1.6 through 3.0 may incorrectly detect the presence o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-1833</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-1833</guid>
    <pubDate>Wed, 19 Apr 2006 16:06:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2006-1833</strong></p>
  <p>Intel RNG Driver in NetBSD 1.6 through 3.0 may incorrectly detect the presence of the pchb interface, which will cause it to always generate the same random number, which allows remote attackers to more easily crack encryption keys generated from the interface.</p>
  <p><strong>CVSS:</strong> 2.6 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-1833">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2006-1797 – The kernel in NetBSD-current before September 28, 2005 allows local users to cau...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-1797</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-1797</guid>
    <pubDate>Tue, 18 Apr 2006 10:02:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2006-1797</strong></p>
  <p>The kernel in NetBSD-current before September 28, 2005 allows local users to cause a denial of service (system crash) by using the SIOCGIFALIAS ioctl to gather information on a non-existent alias of a network interface, which causes a NULL pointer dereference.</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-1797">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2006-1814 – NetBSD 1.6, 2.0, 2.1 and 3.0 allows local users to cause a denial of service (me...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-1814</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-1814</guid>
    <pubDate>Tue, 18 Apr 2006 10:02:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2006-1814</strong></p>
  <p>NetBSD 1.6, 2.0, 2.1 and 3.0 allows local users to cause a denial of service (memory exhaustion) by using the sysctl system call to lock a large buffer into physical memory.</p>
  <p><strong>CVSS:</strong> 2.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-1814">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2006-1646 – The Internet Key Exchange version 1 (IKEv1) implementation (isakmp_agg.c) in the...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-1646</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-1646</guid>
    <pubDate>Thu, 06 Apr 2006 10:04:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2006-1646</strong></p>
  <p>The Internet Key Exchange version 1 (IKEv1) implementation (isakmp_agg.c) in the Shoichi Sakane KAME Project racoon, as used by NetBSD 1.6, 2.x before 20060119, certain FreeBSD releases, and possibly other distributions of BSD or Linux operating systems, when running in aggressive mode, allows remote attackers to cause a denial of service (daemon crash) via crafted IKE packets, as demonstrated by…</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-1646">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2006-1587 – NetBSD 1.6 up to 3.0, when a user has "set record" in .mailrc with the default u...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-1587</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-1587</guid>
    <pubDate>Mon, 03 Apr 2006 10:04:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2006-1587</strong></p>
  <p>NetBSD 1.6 up to 3.0, when a user has "set record" in .mailrc with the default umask set, creates the record file with 0644 permissions, which allows local users to read the record file.</p>
  <p><strong>CVSS:</strong> 2.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-1587">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2006-1588 – The bridge ioctl (if_bridge code) in NetBSD 1.6 through 3.0 does not clear sensi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-1588</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-1588</guid>
    <pubDate>Mon, 03 Apr 2006 10:04:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2006-1588</strong></p>
  <p>The bridge ioctl (if_bridge code) in NetBSD 1.6 through 3.0 does not clear sensitive memory before copying ioctl results to the requesting process, which allows local users to obtain portions of kernel memory.</p>
  <p><strong>CVSS:</strong> 2.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-1588">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2006-1589 – The elf_load_file function in NetBSD 2.0 through 3.0 allows local users to cause...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-1589</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-1589</guid>
    <pubDate>Mon, 03 Apr 2006 10:04:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2006-1589</strong></p>
  <p>The elf_load_file function in NetBSD 2.0 through 3.0 allows local users to cause a denial of service (kernel crash) via an ELF interpreter that does not have a PT_LOAD section in its header, which triggers a null dereference.</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-1589">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-0905 – A "programming error" in fast_ipsec in FreeBSD 4.8-RELEASE through 6.1-STABLE an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-0905</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-0905</guid>
    <pubDate>Thu, 23 Mar 2006 11:06:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-0905</strong></p>
  <p>A "programming error" in fast_ipsec in FreeBSD 4.8-RELEASE through 6.1-STABLE and NetBSD 2 through 3 does not properly update the sequence number associated with a Security Association, which allows packets to pass sequence number checks and allows remote attackers to capture IPSec packets and conduct replay attacks.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-0905">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2006-0145 – The kernfs_xread function in kernfs in NetBSD 1.6 through 2.1, and OpenBSD 3.8, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-0145</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-0145</guid>
    <pubDate>Mon, 09 Jan 2006 23:03:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2006-0145</strong></p>
  <p>The kernfs_xread function in kernfs in NetBSD 1.6 through 2.1, and OpenBSD 3.8, does not properly validate file offsets against negative 32-bit values that occur as a result of truncation, which allows local users to read arbitrary kernel memory and gain privileges via the lseek system call.</p>
  <p><strong>CVSS:</strong> 4.6 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-0145">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2005-4352 – The securelevels implementation in NetBSD 2.1 and earlier, and Linux 2.6.15 and ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2005-4352</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2005-4352</guid>
    <pubDate>Sat, 31 Dec 2005 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2005-4352</strong></p>
  <p>The securelevels implementation in NetBSD 2.1 and earlier, and Linux 2.6.15 and earlier, allows local users to bypass time setting restrictions and set the clock backwards by setting the clock ahead to the maximum unixtime value (19 Jan 2038), which then wraps around to the minimum value (13 Dec 1901), which can then be set ahead to the desired time, aka "settimeofday() time wrap."</p>
  <p><strong>CVSS:</strong> 2.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2005-4352">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2005-4691 – imake in NetBSD before 2.0.3, NetBSD-current before 12 September 2005, certain v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2005-4691</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2005-4691</guid>
    <pubDate>Sat, 31 Dec 2005 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2005-4691</strong></p>
  <p>imake in NetBSD before 2.0.3, NetBSD-current before 12 September 2005, certain versions of X.Org, and certain versions of XFree86 allows local users to overwrite arbitrary files via a symlink attack on the temporary file for the file.0 target, which is used for a pre-formatted manual page.</p>
  <p><strong>CVSS:</strong> 2.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2005-4691">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2005-4733 – NetBSD 2.0 before 20050316 and NetBSD-current before 20050112 allow local users ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2005-4733</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2005-4733</guid>
    <pubDate>Sat, 31 Dec 2005 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2005-4733</strong></p>
  <p>NetBSD 2.0 before 20050316 and NetBSD-current before 20050112 allow local users to cause a denial of service (infinite loop and system hang) by calling the F_CLOSEM fcntl with a parameter value of 0.</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2005-4733">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2005-4741 – NetBSD 1.6, NetBSD 2.0 through 2.1, and NetBSD-current before 20051031 allows lo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2005-4741</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2005-4741</guid>
    <pubDate>Sat, 31 Dec 2005 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2005-4741</strong></p>
  <p>NetBSD 1.6, NetBSD 2.0 through 2.1, and NetBSD-current before 20051031 allows local users to gain privileges by attaching a debugger to a setuid/setgid (P_SUGID) process that performs an exec without a reset of real credentials.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2005-4741">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2005-4776 – Integer overflow in the FreeBSD compatibility code (freebsd_misc.c) in NetBSD-cu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2005-4776</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2005-4776</guid>
    <pubDate>Sat, 31 Dec 2005 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2005-4776</strong></p>
  <p>Integer overflow in the FreeBSD compatibility code (freebsd_misc.c) in NetBSD-current, NetBSD-3, NetBSD-2.0, and NetBSD-2 before 20050913; and NetBSD-1.6 before 20050914; allows local users to cause a denial of service (heap corruption or system crash) and possibly gain root privileges.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2005-4776">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2005-4779 – verifiedexecioctl in verified_exec.c in NetBSD 2.0.2 calls NDINIT with UIO_USERS...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2005-4779</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2005-4779</guid>
    <pubDate>Sat, 31 Dec 2005 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2005-4779</strong></p>
  <p>verifiedexecioctl in verified_exec.c in NetBSD 2.0.2 calls NDINIT with UIO_USERSPACE rather than UID_SYSSPACE, which removes the functionality of the verified exec kernel subsystem and might allow local users to execute Trojan horse programs.</p>
  <p><strong>CVSS:</strong> 3.6 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2005-4779">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2005-4782 – NetBSD 2.0 before 2.0.4, 2.1 before 2.1.1, and 3, when the kernel is compiled wi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2005-4782</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2005-4782</guid>
    <pubDate>Sat, 31 Dec 2005 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2005-4782</strong></p>
  <p>NetBSD 2.0 before 2.0.4, 2.1 before 2.1.1, and 3, when the kernel is compiled with "options DIAGNOSTIC," allows local users to cause a denial of service (kernel assertion panic) via a negative linger time in the SO_LINGER socket option.</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2005-4782">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2005-4783 – kernfs_xread in kernfs_vnops.c in NetBSD before 20050831 does not check for a ne...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2005-4783</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2005-4783</guid>
    <pubDate>Sat, 31 Dec 2005 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2005-4783</strong></p>
  <p>kernfs_xread in kernfs_vnops.c in NetBSD before 20050831 does not check for a negative offset when reading the message buffer, which allows local users to read arbitrary kernel memory.</p>
  <p><strong>CVSS:</strong> 2.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2005-4783">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2005-2134 – The (1) clcs and (2) emuxki drivers in NetBSD 1.6 through 2.0.2 allow local user...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2005-2134</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2005-2134</guid>
    <pubDate>Tue, 05 Jul 2005 04:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2005-2134</strong></p>
  <p>The (1) clcs and (2) emuxki drivers in NetBSD 1.6 through 2.0.2 allow local users to cause a denial of service (kernel crash) by using the set-parameters ioctl on an audio device to change the block size and set the pause state to "unpaused" in the same ioctl, which causes a divide-by-zero error.</p>
  <p><strong>CVSS:</strong> 2.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2005-2134">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2005-0869 – phpSysInfo 2.3 allows remote attackers to obtain sensitive information via a dir...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2005-0869</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2005-0869</guid>
    <pubDate>Mon, 02 May 2005 04:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2005-0869</strong></p>
  <p>phpSysInfo 2.3 allows remote attackers to obtain sensitive information via a direct request to (1) class.OpenBSD.inc.php, (2) class.NetBSD.inc.php, (3) class.FreeBSD.inc.php, (4) class.Darwin.inc.php, (5) XPath.class.php, (6) system_header.php, or (7) system_footer.php, which reveal the path in a PHP error message.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2005-0869">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2004-2012 – The systrace_exit function in the systrace utility for NetBSD-current and 2.0 be...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2004-2012</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2004-2012</guid>
    <pubDate>Fri, 31 Dec 2004 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2004-2012</strong></p>
  <p>The systrace_exit function in the systrace utility for NetBSD-current and 2.0 before April 16, 2004, and certain FreeBSD ports, does not verify the owner of the /dec/systrace connection before setting euid to 0, which allows local users to gain root privileges.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2004-2012">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2004-1374 – Multiple buffer overflows in NetBSD kernel may allow local users to execute arbi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2004-1374</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2004-1374</guid>
    <pubDate>Sat, 18 Dec 2004 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2004-1374</strong></p>
  <p>Multiple buffer overflows in NetBSD kernel may allow local users to execute arbitrary code and gain privileges.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2004-1374">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2004-1323 – Multiple syscalls in the compat subsystem for NetBSD before 2.0 allow local user...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2004-1323</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2004-1323</guid>
    <pubDate>Thu, 16 Dec 2004 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2004-1323</strong></p>
  <p>Multiple syscalls in the compat subsystem for NetBSD before 2.0 allow local users to cause a denial of service (kernel crash) via a large signal number to (1) xxx_sys_kill, (2) xxx_sys_sigaction, and possibly other translation functions.</p>
  <p><strong>CVSS:</strong> 2.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2004-1323">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2004-0257 – OpenBSD 3.4 and NetBSD 1.6 and 1.6.1 allow remote attackers to cause a denial of...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2004-0257</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2004-0257</guid>
    <pubDate>Tue, 23 Nov 2004 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2004-0257</strong></p>
  <p>OpenBSD 3.4 and NetBSD 1.6 and 1.6.1 allow remote attackers to cause a denial of service (crash) by sending an IPv6 packet with a small MTU to a listening port and then issuing a TCP connect to that port.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2004-0257">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
