<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – OpenBSD (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/openbsd.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/openbsd-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – OpenBSD (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:55 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-33306 – bcrypt-ruby is a Ruby binding for the OpenBSD bcrypt() password hashing algorith...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33306</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33306</guid>
    <pubDate>Tue, 24 Mar 2026 01:17:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33306</strong></p>
  <p>bcrypt-ruby is a Ruby binding for the OpenBSD bcrypt() password hashing algorithm. Prior to version 3.1.22, an integer overflow in the Java BCrypt implementation for JRuby can cause zero iterations in the strengthening loop.  Impacted applications must be setting the cost to 31 to see this happen. The JRuby implementation of bcrypt-ruby (`BCrypt.java`) computes the key-strengthening round count a…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33306">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-11149 – In OpenBSD 7.4 before errata 014, vmm(4) did not restore GDTR limits properly on...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-11149</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-11149</guid>
    <pubDate>Fri, 06 Dec 2024 02:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-11149</strong></p>
  <p>In OpenBSD 7.4 before errata 014, vmm(4) did not restore GDTR limits properly on Intel (VMX) CPUs.</p>
  <p><strong>CVSS:</strong> 7.9 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-11149">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-11148 – In OpenBSD 7.4 before errata 006 and OpenBSD 7.3 before errata 020, httpd(8) is ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-11148</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-11148</guid>
    <pubDate>Thu, 05 Dec 2024 20:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-11148</strong></p>
  <p>In OpenBSD 7.4 before errata 006 and OpenBSD 7.3 before errata 020, httpd(8) is vulnerable to a NULL dereference when handling a malformed fastcgi request.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-11148">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-10934 – In OpenBSD 7.5 before errata 008 and OpenBSD 7.4 before errata 021, 
avoid possi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-10934</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-10934</guid>
    <pubDate>Fri, 15 Nov 2024 20:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-10934</strong></p>
  <p>In OpenBSD 7.5 before errata 008 and OpenBSD 7.4 before errata 021,  avoid possible mbuf double free in NFS client and server implementation, do not use uninitialized variable in error handling of NFS server.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-415</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-10934">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-43688 – cron/entry.c in vixie cron before 9cc8ab1, as used in OpenBSD 7.4 and 7.5, allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-43688</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-43688</guid>
    <pubDate>Tue, 20 Aug 2024 06:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-43688</strong></p>
  <p>cron/entry.c in vixie cron before 9cc8ab1, as used in OpenBSD 7.4 and 7.5, allows a heap-based buffer underflow and memory corruption. NOTE: this issue was introduced during a May 2023 refactoring.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-43688">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-29937 – NFS in a BSD derived codebase, as used in OpenBSD through 7.4 and FreeBSD throug...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-29937</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-29937</guid>
    <pubDate>Thu, 11 Apr 2024 01:25:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-29937</strong></p>
  <p>NFS in a BSD derived codebase, as used in OpenBSD through 7.4 and FreeBSD through 14.0-RELEASE, allows remote attackers to execute arbitrary code via a bug that is unrelated to memory corruption.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-29937">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-52558 – In OpenBSD 7.4 before errata 002 and OpenBSD 7.3 before errata 019, a network bu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-52558</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-52558</guid>
    <pubDate>Fri, 01 Mar 2024 17:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-52558</strong></p>
  <p>In OpenBSD 7.4 before errata 002 and OpenBSD 7.3 before errata 019, a network buffer that had to be split at certain length that could crash the kernel after receiving specially crafted escape sequences.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-131</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-52558">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-52557 – In OpenBSD 7.3 before errata 016, npppd(8) could crash by a l2tp message which h...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-52557</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-52557</guid>
    <pubDate>Fri, 01 Mar 2024 17:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-52557</strong></p>
  <p>In OpenBSD 7.3 before errata 016, npppd(8) could crash by a l2tp message which has an AVP (Attribute-Value Pair) with wrong length.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-131</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-52557">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-35784 – A double free or use after free could occur after SSL_clear in OpenBSD 7.2 befor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-35784</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-35784</guid>
    <pubDate>Fri, 16 Jun 2023 20:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-35784</strong></p>
  <p>A double free or use after free could occur after SSL_clear in OpenBSD 7.2 before errata 026 and 7.3 before errata 004, and in LibreSSL before 3.6.3 and 3.7.x before 3.7.3. NOTE: OpenSSL is not affected.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-415</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-35784">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-46880 – x509/x509_verify.c in LibreSSL before 3.4.2, and OpenBSD before 7.0 errata 006, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-46880</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-46880</guid>
    <pubDate>Sat, 15 Apr 2023 00:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-46880</strong></p>
  <p>x509/x509_verify.c in LibreSSL before 3.4.2, and OpenBSD before 7.0 errata 006, allows authentication bypass because an error for an unverified certificate chain is sometimes discarded.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-46880">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-29323 – ascii_load_sockaddr in smtpd in OpenBSD before 7.1 errata 024 and 7.2 before err...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-29323</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-29323</guid>
    <pubDate>Tue, 04 Apr 2023 23:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-29323</strong></p>
  <p>ascii_load_sockaddr in smtpd in OpenBSD before 7.1 errata 024 and 7.2 before errata 020, and OpenSMTPD Portable before 7.0.0-portable commit f748277, can abort upon a connection from a local, scoped IPv6 address.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-29323">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-28339 – OpenDoas through 6.8.2, when TIOCSTI is available, allows privilege escalation b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-28339</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-28339</guid>
    <pubDate>Tue, 14 Mar 2023 19:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-28339</strong></p>
  <p>OpenDoas through 6.8.2, when TIOCSTI is available, allows privilege escalation because of sharing a terminal with the original session. NOTE: TIOCSTI is unavailable in OpenBSD 6.0 and later, and can be made unavailable in the Linux kernel 6.2 and later.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-28339">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-27567 – In OpenBSD 7.2, a TCP packet with destination port 0 that matches a pf divert-to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-27567</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-27567</guid>
    <pubDate>Fri, 03 Mar 2023 22:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-27567</strong></p>
  <p>In OpenBSD 7.2, a TCP packet with destination port 0 that matches a pf divert-to rule can crash the kernel.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-27567">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-27882 – slaacd in OpenBSD 6.9 and 7.0 before 2022-03-22 has an integer signedness error ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-27882</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-27882</guid>
    <pubDate>Fri, 25 Mar 2022 18:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-27882</strong></p>
  <p>slaacd in OpenBSD 6.9 and 7.0 before 2022-03-22 has an integer signedness error and resultant heap-based buffer overflow triggerable by a crafted IPv6 router advertisement. NOTE: privilege separation and pledge can prevent exploitation.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-681</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27882">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-27881 – engine.c in slaacd in OpenBSD 6.9 and 7.0 before 2022-02-21 has a buffer overflo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-27881</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-27881</guid>
    <pubDate>Fri, 25 Mar 2022 18:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-27881</strong></p>
  <p>engine.c in slaacd in OpenBSD 6.9 and 7.0 before 2022-02-21 has a buffer overflow triggerable by an IPv6 router advertisement with more than seven nameservers. NOTE: privilege separation and pledge can prevent exploitation.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27881">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2010-4816 – It was found in FreeBSD 8.0, 6.3 and 4.9, and OpenBSD 4.6 that a null pointer de...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-4816</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-4816</guid>
    <pubDate>Tue, 22 Jun 2021 14:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2010-4816</strong></p>
  <p>It was found in FreeBSD 8.0, 6.3 and 4.9, and OpenBSD 4.6 that a null pointer dereference in ftpd/popen.c may lead to remote denial of service of the ftpd service.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-4816">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-16088 – iked in OpenIKED, as used in OpenBSD through 6.7, allows authentication bypass b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-16088</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-16088</guid>
    <pubDate>Tue, 28 Jul 2020 12:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-16088</strong></p>
  <p>iked in OpenIKED, as used in OpenBSD through 6.7, allows authentication bypass because ca.c has the wrong logic for checking whether a public key matches.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-16088">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-10030 – An issue has been found in PowerDNS Recursor 4.1.0 up to and including 4.3.0. It...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-10030</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-10030</guid>
    <pubDate>Tue, 19 May 2020 16:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-10030</strong></p>
  <p>An issue has been found in PowerDNS Recursor 4.1.0 up to and including 4.3.0. It allows an attacker (with enough privileges to change the system's hostname) to cause disclosure of uninitialized memory content via a stack-based out-of-bounds read. It only occurs on systems where gethostname() does not have '\0' termination of the returned string if the hostname is larger than the supplied buffer.…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-10030">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-7247 – smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and oth...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7247</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7247</guid>
    <pubDate>Wed, 29 Jan 2020 16:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-7247</strong></p>
  <p>smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary commands as root via a crafted SMTP session, as demonstrated by shell metacharacters in a MAIL FROM field. This affects the "uncommented" default configuration. The issue exists because of an incorrect return value upon failure of input validation.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7247">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-19726 – OpenBSD through 6.6 allows local users to escalate to root because a check for L...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-19726</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-19726</guid>
    <pubDate>Thu, 12 Dec 2019 01:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-19726</strong></p>
  <p>OpenBSD through 6.6 allows local users to escalate to root because a check for LD_LIBRARY_PATH in setuid programs can be defeated by setting a very small RLIMIT_DATA resource limit. When executing chpass or passwd (which are setuid root), _dl_setup_env in ld.so tries to strip LD_LIBRARY_PATH from the environment, but fails when it cannot allocate memory. Thus, the attacker is able to execute thei…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-19726">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-14899 – A vulnerability was discovered in Linux, FreeBSD, OpenBSD, MacOS, iOS, and Andro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-14899</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-14899</guid>
    <pubDate>Wed, 11 Dec 2019 15:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-14899</strong></p>
  <p>A vulnerability was discovered in Linux, FreeBSD, OpenBSD, MacOS, iOS, and Android that allows a malicious access point, or an adjacent user, to determine if a connected user is using a VPN, make positive inferences about the websites they are visiting, and determine the correct sequence and acknowledgement numbers in use, allowing the bad actor to inject data into the TCP stream. This provides e…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-300</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-14899">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2012-1577 – lib/libc/stdlib/random.c in OpenBSD returns 0 when seeded with 0.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-1577</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-1577</guid>
    <pubDate>Tue, 10 Dec 2019 19:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2012-1577</strong></p>
  <p>lib/libc/stdlib/random.c in OpenBSD returns 0 when seeded with 0.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-335</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-1577">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-19522 – OpenBSD 6.6, in a non-default configuration where S/Key or YubiKey authenticatio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-19522</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-19522</guid>
    <pubDate>Thu, 05 Dec 2019 00:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-19522</strong></p>
  <p>OpenBSD 6.6, in a non-default configuration where S/Key or YubiKey authentication is enabled, allows local users to become root by leveraging membership in the auth group. This occurs because root's file can be written to /etc/skey or /var/db/yubikey, and need not be owned by root.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-19522">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-19521 – libc in OpenBSD 6.6 allows authentication bypass via the -schallenge username, a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-19521</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-19521</guid>
    <pubDate>Thu, 05 Dec 2019 00:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-19521</strong></p>
  <p>libc in OpenBSD 6.6 allows authentication bypass via the -schallenge username, as demonstrated by smtpd, ldapd, or radiusd. This is related to gen/auth_subr.c and gen/authenticate.c in libc (and login/login.c and xenocara/app/xenodm/greeter/verify.c).</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-19521">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-19520 – xlock in OpenBSD 6.6 allows local users to gain the privileges of the auth group...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-19520</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-19520</guid>
    <pubDate>Thu, 05 Dec 2019 00:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-19520</strong></p>
  <p>xlock in OpenBSD 6.6 allows local users to gain the privileges of the auth group by providing a LIBGL_DRIVERS_PATH environment variable, because xenocara/lib/mesa/src/loader/loader.c mishandles dlopen.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-19520">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-19519 – In OpenBSD 6.6, local users can use the su -L option to achieve any login class ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-19519</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-19519</guid>
    <pubDate>Thu, 05 Dec 2019 00:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-19519</strong></p>
  <p>In OpenBSD 6.6, local users can use the su -L option to achieve any login class (often excluding root) because there is a logic error in the main function in su/su.c.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-19519">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-15901 – An issue was discovered in slicer69 doas before 6.2 on certain platforms other t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-15901</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-15901</guid>
    <pubDate>Fri, 18 Oct 2019 16:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-15901</strong></p>
  <p>An issue was discovered in slicer69 doas before 6.2 on certain platforms other than OpenBSD. A setusercontext(3) call with flags to change the UID, primary GID, and secondary GIDs was replaced (on certain platforms: Linux and possibly NetBSD) with a single setuid(2) call. This resulted in neither changing the group id nor initializing secondary group ids.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-15901">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-15900 – An issue was discovered in slicer69 doas before 6.2 on certain platforms other t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-15900</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-15900</guid>
    <pubDate>Fri, 18 Oct 2019 16:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-15900</strong></p>
  <p>An issue was discovered in slicer69 doas before 6.2 on certain platforms other than OpenBSD. On platforms without strtonum(3), sscanf was used without checking for error cases. Instead, the uninitialized variable errstr was checked and in some cases returned success even if sscanf failed. The result was that, instead of reporting that the supplied username or group name did not exist, it would ex…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-252</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-15900">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-8460 – OpenBSD kernel version &lt;= 6.5 can be forced to create long chains of TCP SACK ho...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-8460</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-8460</guid>
    <pubDate>Mon, 26 Aug 2019 20:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-8460</strong></p>
  <p>OpenBSD kernel version <= 6.5 can be forced to create long chains of TCP SACK holes that causes very expensive calls to tcp_sack_option() for every incoming SACK packet which can lead to a denial of service.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-1049</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-8460">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-6724 – The barracudavpn component of the Barracuda VPN Client prior to version 5.0.2.7 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-6724</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-6724</guid>
    <pubDate>Thu, 21 Mar 2019 16:01:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-6724</strong></p>
  <p>The barracudavpn component of the Barracuda VPN Client prior to version 5.0.2.7 for Linux, macOS, and OpenBSD runs as a privileged process and can allow an unprivileged local attacker to load a malicious library, resulting in arbitrary code executing as root.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-426</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-6724">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-1000372 – A flaw exists in OpenBSD's implementation of the stack guard page that allows at...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-1000372</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-1000372</guid>
    <pubDate>Mon, 19 Jun 2017 16:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-1000372</strong></p>
  <p>A flaw exists in OpenBSD's implementation of the stack guard page that allows attackers to bypass it resulting in arbitrary code execution using setuid binaries such as /usr/bin/at. This affects OpenBSD 6.1 and possibly earlier versions.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-1000372">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-5850 – httpd in OpenBSD allows remote attackers to cause a denial of service (memory co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-5850</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-5850</guid>
    <pubDate>Mon, 27 Mar 2017 15:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-5850</strong></p>
  <p>httpd in OpenBSD allows remote attackers to cause a denial of service (memory consumption) via a series of requests for a large file using an HTTP Range header.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-5850">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-6241 – Integer overflow in the amap_alloc1 function in OpenBSD 5.8 and 5.9 allows local...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-6241</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-6241</guid>
    <pubDate>Tue, 07 Mar 2017 16:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-6241</strong></p>
  <p>Integer overflow in the amap_alloc1 function in OpenBSD 5.8 and 5.9 allows local users to execute arbitrary code with kernel privileges via a large size value.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6241">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-6240 – Integer truncation error in the amap_alloc function in OpenBSD 5.8 and 5.9 allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-6240</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-6240</guid>
    <pubDate>Tue, 07 Mar 2017 16:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-6240</strong></p>
  <p>Integer truncation error in the amap_alloc function in OpenBSD 5.8 and 5.9 allows local users to execute arbitrary code with kernel privileges via a large size value.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-189</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6240">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-6244 – The sys_thrsigdivert function in kern/kern_sig.c in the OpenBSD kernel 5.9 allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-6244</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-6244</guid>
    <pubDate>Tue, 07 Mar 2017 15:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-6244</strong></p>
  <p>The sys_thrsigdivert function in kern/kern_sig.c in the OpenBSD kernel 5.9 allows remote attackers to cause a denial of service (panic) via a negative "ts.tv_sec" value.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6244">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-6564 – Use-after-free vulnerability in the mm_answer_pam_free_ctx function in monitor.c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-6564</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-6564</guid>
    <pubDate>Mon, 24 Aug 2015 01:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-6564</strong></p>
  <p>Use-after-free vulnerability in the mm_answer_pam_free_ctx function in monitor.c in sshd in OpenSSH before 7.0 on non-OpenBSD platforms might allow local users to gain privileges by leveraging control of the sshd uid to send an unexpectedly early MONITOR_REQ_PAM_FREE_CTX request.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-6564">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2011-2895 – The LZW decompressor in (1) the BufCompressedFill function in fontfile/decompres...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-2895</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-2895</guid>
    <pubDate>Fri, 19 Aug 2011 17:55:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2011-2895</strong></p>
  <p>The LZW decompressor in (1) the BufCompressedFill function in fontfile/decompress.c in X.Org libXfont before 1.4.4 and (2) compress/compress.c in 4.3BSD, as used in zopen.c in OpenBSD before 3.8, FreeBSD, NetBSD 4.0.x and 5.0.x before 5.0.3 and 5.1.x before 5.1.1, FreeType 2.1.9, and other products, does not properly handle code words that are absent from the decompression table when encountered,…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-2895">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2011-1013 – Integer signedness error in the drm_modeset_ctl function in (1) drivers/gpu/drm/...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-1013</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-1013</guid>
    <pubDate>Mon, 09 May 2011 19:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2011-1013</strong></p>
  <p>Integer signedness error in the drm_modeset_ctl function in (1) drivers/gpu/drm/drm_irq.c in the Direct Rendering Manager (DRM) subsystem in the Linux kernel before 2.6.38 and (2) sys/dev/pci/drm/drm_irq.c in the kernel in OpenBSD before 4.9 allows local users to trigger out-of-bounds write operations, and consequently cause a denial of service (system crash) or possibly have unspecified other im…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-1013">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2009-0687 – The pf_test_rule function in OpenBSD Packet Filter (PF), as used in OpenBSD 4.2 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-0687</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-0687</guid>
    <pubDate>Tue, 11 Aug 2009 10:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2009-0687</strong></p>
  <p>The pf_test_rule function in OpenBSD Packet Filter (PF), as used in OpenBSD 4.2 through 4.5, NetBSD 5.0 before RC3, MirOS 10 and earlier, and MidnightBSD 0.3-current allows remote attackers to cause a denial of service (panic) via crafted IP packets that trigger a NULL pointer dereference during translation, related to an IPv4 packet with an ICMPv6 payload.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-0687">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2008-2476 – The IPv6 Neighbor Discovery Protocol (NDP) implementation in (1) FreeBSD 6.3 thr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-2476</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-2476</guid>
    <pubDate>Fri, 03 Oct 2008 15:07:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2008-2476</strong></p>
  <p>The IPv6 Neighbor Discovery Protocol (NDP) implementation in (1) FreeBSD 6.3 through 7.1, (2) OpenBSD 4.2 and 4.3, (3) NetBSD, (4) Force10 FTOS before E7.7.1.1, (5) Juniper JUNOS, and (6) Wind River VxWorks 5.x through 6.4 does not validate the origin of Neighbor Discovery messages, which allows remote attackers to cause a denial of service (loss of connectivity) or read private network traffic v…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-2476">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-4247 – ftpd in OpenBSD 4.3, FreeBSD 7.0, NetBSD 4.0, Solaris, and possibly other operat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-4247</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-4247</guid>
    <pubDate>Thu, 25 Sep 2008 19:25:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-4247</strong></p>
  <p>ftpd in OpenBSD 4.3, FreeBSD 7.0, NetBSD 4.0, Solaris, and possibly other operating systems interprets long commands from an FTP client as multiple commands, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and execute arbitrary FTP commands via a long ftp:// URI that leverages an existing session from the FTP client implementation in a web browser.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-4247">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-1057 – The ip6_check_rh0hdr function in netinet6/ip6_input.c in OpenBSD 4.2 allows atta...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-1057</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-1057</guid>
    <pubDate>Thu, 28 Feb 2008 19:44:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-1057</strong></p>
  <p>The ip6_check_rh0hdr function in netinet6/ip6_input.c in OpenBSD 4.2 allows attackers to cause a denial of service (panic) via malformed IPv6 routing headers.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-1057">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-1058 – The tcp_respond function in netinet/tcp_subr.c in OpenBSD 4.1 and 4.2 allows att...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-1058</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-1058</guid>
    <pubDate>Thu, 28 Feb 2008 19:44:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-1058</strong></p>
  <p>The tcp_respond function in netinet/tcp_subr.c in OpenBSD 4.1 and 4.2 allows attackers to cause a denial of service (panic) via crafted TCP packets.  NOTE: some of these details are obtained from third party information.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-1058">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-5365 – Stack-based buffer overflow in the cons_options function in options.c in dhcpd i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-5365</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-5365</guid>
    <pubDate>Thu, 11 Oct 2007 10:17:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-5365</strong></p>
  <p>Stack-based buffer overflow in the cons_options function in options.c in dhcpd in OpenBSD 4.0 through 4.2, and some other dhcpd implementations based on ISC dhcp-2, allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a DHCP request specifying a maximum message size smaller than the minimum IP MTU.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-5365">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-1523 – Heap-based buffer overflow in the kernel in NetBSD 3.0, certain versions of Free...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-1523</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-1523</guid>
    <pubDate>Tue, 20 Mar 2007 20:19:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-1523</strong></p>
  <p>Heap-based buffer overflow in the kernel in NetBSD 3.0, certain versions of FreeBSD and OpenBSD, and possibly other BSD derived operating systems allows local users to have an unknown impact.  NOTE: this information is based upon a vague pre-advisory with no actionable information. Details will be updated after 20070329.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-1523">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2007-1365 – Buffer overflow in kern/uipc_mbuf2.c in OpenBSD 3.9 and 4.0 allows remote attack...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-1365</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-1365</guid>
    <pubDate>Sat, 10 Mar 2007 21:19:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2007-1365</strong></p>
  <p>Buffer overflow in kern/uipc_mbuf2.c in OpenBSD 3.9 and 4.0 allows remote attackers to execute arbitrary code via fragmented IPv6 packets due to "incorrect mbuf handling for ICMP6 packets."  NOTE: this was originally reported as a denial of service.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-1365">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-6164 – The _dl_unsetenv function in loader.c in the ELF ld.so in OpenBSD 3.9 and 4.0 do...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-6164</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-6164</guid>
    <pubDate>Wed, 29 Nov 2006 01:28:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-6164</strong></p>
  <p>The _dl_unsetenv function in loader.c in the ELF ld.so in OpenBSD 3.9 and 4.0 does not properly remove duplicate environment variables, which allows local users to pass dangerous variables such as LD_PRELOAD to loading processes, which might be leveraged to gain privileges.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-6164">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2006-4304 – Buffer overflow in the sppp driver in FreeBSD 4.11 through 6.1, NetBSD 2.0 throu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-4304</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-4304</guid>
    <pubDate>Thu, 24 Aug 2006 01:04:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2006-4304</strong></p>
  <p>Buffer overflow in the sppp driver in FreeBSD 4.11 through 6.1, NetBSD 2.0 through 4.0 beta before 20060823, and OpenBSD 3.8 and 3.9 before 20060902 allows remote attackers to cause a denial of service (panic), obtain sensitive information, and possibly execute arbitrary code via crafted Link Control Protocol (LCP) packets with an option length that exceeds the overall length, which triggers the…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-4304">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2004-1799 – PF in certain OpenBSD versions, when stateful filtering is enabled, does not lim...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2004-1799</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2004-1799</guid>
    <pubDate>Fri, 31 Dec 2004 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2004-1799</strong></p>
  <p>PF in certain OpenBSD versions, when stateful filtering is enabled, does not limit packets for a session to the original interface, which allows remote attackers to bypass intended packet filters via spoofed packets to other interfaces.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2004-1799">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2004-2163 – login_radius on OpenBSD 3.2, 3.5, and possibly other versions does not verify th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2004-2163</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2004-2163</guid>
    <pubDate>Fri, 31 Dec 2004 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2004-2163</strong></p>
  <p>login_radius on OpenBSD 3.2, 3.5, and possibly other versions does not verify the shared secret in a response packet from a RADIUS server, which allows remote attackers to bypass authentication by spoofing server replies.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2004-2163">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2004-2338 – OpenBSD 3.3 and 3.4 does not properly parse Accept and Deny rules without netmas...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2004-2338</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2004-2338</guid>
    <pubDate>Fri, 31 Dec 2004 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2004-2338</strong></p>
  <p>OpenBSD 3.3 and 3.4 does not properly parse Accept and Deny rules without netmasks on big-endian 64-bit platforms such as SPARC64, which may allow remote attackers to bypass access restrictions.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2004-2338">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2004-0220 – isakmpd in OpenBSD 3.4 and earlier allows remote attackers to cause a denial of ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2004-0220</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2004-0220</guid>
    <pubDate>Tue, 04 May 2004 04:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2004-0220</strong></p>
  <p>isakmpd in OpenBSD 3.4 and earlier allows remote attackers to cause a denial of service via an ISAKMP packet with a malformed Cert Request payload, which causes an integer underflow that is used in a malloc operation that is not properly handled, as demonstrated by the Striker ISAKMP Protocol Test Suite.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2004-0220">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2002-1420 – Integer signedness error in select() on OpenBSD 3.1 and earlier allows local use...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2002-1420</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2002-1420</guid>
    <pubDate>Fri, 11 Apr 2003 04:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2002-1420</strong></p>
  <p>Integer signedness error in select() on OpenBSD 3.1 and earlier allows local users to overwrite arbitrary kernel memory via a negative value for the size parameter, which satisfies the boundary check as a signed integer, but is later used as an unsigned integer during a data copying operation.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2002-1420">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2003-0144 – Buffer overflow in the lprm command in the lprold lpr package on SuSE 7.1 throug...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2003-0144</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2003-0144</guid>
    <pubDate>Mon, 31 Mar 2003 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2003-0144</strong></p>
  <p>Buffer overflow in the lprm command in the lprold lpr package on SuSE 7.1 through 7.3, OpenBSD 3.2 and earlier, and possibly other operating systems, allows local users to gain root privileges via long command line arguments such as (1) request ID or (2) user name.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2003-0144">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2002-0766 – OpenBSD 2.9 through 3.1 allows local users to cause a denial of service (resourc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2002-0766</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2002-0766</guid>
    <pubDate>Mon, 12 Aug 2002 04:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2002-0766</strong></p>
  <p>OpenBSD 2.9 through 3.1 allows local users to cause a denial of service (resource exhaustion) and gain root privileges by filling the kernel's file descriptor table and closing file descriptors 0, 1, or 2 before executing a privileged process, which is not properly handled when OpenBSD fails to open an alternate descriptor.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2002-0766">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2002-0542 – mail in OpenBSD 2.9 and 3.0 processes a tilde (~) escape character in a message ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2002-0542</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2002-0542</guid>
    <pubDate>Wed, 03 Jul 2002 04:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2002-0542</strong></p>
  <p>mail in OpenBSD 2.9 and 3.0 processes a tilde (~) escape character in a message even when it is not in interactive mode, which could allow local users to gain root privileges via calls to mail in cron.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2002-0542">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2002-0557 – Vulnerability in OpenBSD 3.0, when using YP with netgroups in the password datab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2002-0557</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2002-0557</guid>
    <pubDate>Wed, 03 Jul 2002 04:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2002-0557</strong></p>
  <p>Vulnerability in OpenBSD 3.0, when using YP with netgroups in the password database, causes (1) rexec or (2) rsh to run another user's shell, or (3) atrun to change to a different user's directory, possibly due to memory allocation failures or an incorrect call to auth_approval().</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2002-0557">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2002-0640 – Buffer overflow in sshd in OpenSSH 2.3.1 through 3.3 may allow remote attackers ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2002-0640</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2002-0640</guid>
    <pubDate>Wed, 03 Jul 2002 04:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2002-0640</strong></p>
  <p>Buffer overflow in sshd in OpenSSH 2.3.1 through 3.3 may allow remote attackers to execute arbitrary code via a large number of responses during challenge response authentication when OpenBSD is using PAM modules with interactive keyboard authentication (PAMAuthenticationViaKbdInt).</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2002-0640">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2001-0268 – The i386_set_ldt system call in NetBSD 1.5 and earlier, and OpenBSD 2.8 and earl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2001-0268</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2001-0268</guid>
    <pubDate>Thu, 03 May 2001 04:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2001-0268</strong></p>
  <p>The i386_set_ldt system call in NetBSD 1.5 and earlier, and OpenBSD 2.8 and earlier, when the USER_LDT kernel option is enabled, does not validate a call gate target, which allows local users to gain root privileges by creating a segment call gate in the Local Descriptor Table (LDT) with a target that specifies an arbitrary kernel address.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2001-0268">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2001-0284 – Buffer overflow in IPSEC authentication mechanism for OpenBSD 2.8 and earlier al...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2001-0284</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2001-0284</guid>
    <pubDate>Thu, 03 May 2001 04:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2001-0284</strong></p>
  <p>Buffer overflow in IPSEC authentication mechanism for OpenBSD 2.8 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a malformed Authentication header (AH) IPv4 option.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2001-0284">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2000-0312 – cron in OpenBSD 2.5 allows local users to gain root privileges via an argv[] tha...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2000-0312</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2000-0312</guid>
    <pubDate>Mon, 12 Mar 2001 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2000-0312</strong></p>
  <p>cron in OpenBSD 2.5 allows local users to gain root privileges via an argv[] that is not NULL terminated, which is passed to cron's fake popen function.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2000-0312">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2000-0994 – Format string vulnerability in OpenBSD fstat program (and possibly other BSD-bas...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2000-0994</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2000-0994</guid>
    <pubDate>Tue, 19 Dec 2000 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2000-0994</strong></p>
  <p>Format string vulnerability in OpenBSD fstat program (and possibly other BSD-based operating systems) allows local users to gain root privileges via the PWD environmental variable.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2000-0994">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2000-0995 – Format string vulnerability in OpenBSD yp_passwd program (and possibly other BSD...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2000-0995</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2000-0995</guid>
    <pubDate>Tue, 19 Dec 2000 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2000-0995</strong></p>
  <p>Format string vulnerability in OpenBSD yp_passwd program (and possibly other BSD-based operating systems) allows attackers to gain root privileges a malformed name.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2000-0995">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2000-0996 – Format string vulnerability in OpenBSD su program (and possibly other BSD-based ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2000-0996</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2000-0996</guid>
    <pubDate>Tue, 19 Dec 2000 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2000-0996</strong></p>
  <p>Format string vulnerability in OpenBSD su program (and possibly other BSD-based operating systems) allows local attackers to gain root privileges via a malformed shell.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2000-0996">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2000-0997 – Format string vulnerabilities in eeprom program in OpenBSD, NetBSD, and possibly...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2000-0997</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2000-0997</guid>
    <pubDate>Tue, 19 Dec 2000 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2000-0997</strong></p>
  <p>Format string vulnerabilities in eeprom program in OpenBSD, NetBSD, and possibly other operating systems allows local attackers to gain root privileges.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2000-0997">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2000-0999 – Format string vulnerabilities in OpenBSD ssh program (and possibly other BSD-bas...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2000-0999</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2000-0999</guid>
    <pubDate>Mon, 11 Dec 2000 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2000-0999</strong></p>
  <p>Format string vulnerabilities in OpenBSD ssh program (and possibly other BSD-based operating systems) allow attackers to gain root privileges.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2000-0999">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2000-1010 – Format string vulnerability in talkd in OpenBSD and possibly other BSD-based OSe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2000-1010</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2000-1010</guid>
    <pubDate>Mon, 11 Dec 2000 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2000-1010</strong></p>
  <p>Format string vulnerability in talkd in OpenBSD and possibly other BSD-based OSes allows remote attackers to execute arbitrary commands via a user name that contains format characters.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2000-1010">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-1999-0798 – Buffer overflow in bootpd on OpenBSD, FreeBSD, and Linux systems via a malformed...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-1999-0798</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-1999-0798</guid>
    <pubDate>Fri, 04 Dec 1998 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-1999-0798</strong></p>
  <p>Buffer overflow in bootpd on OpenBSD, FreeBSD, and Linux systems via a malformed header type.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-1999-0798">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-1999-0062 – The chpass command in OpenBSD allows a local user to gain root access through fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-1999-0062</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-1999-0062</guid>
    <pubDate>Mon, 03 Aug 1998 04:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-1999-0062</strong></p>
  <p>The chpass command in OpenBSD allows a local user to gain root access through file descriptor leakage.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-1999-0062">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
