<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – OpenBSD</title>
  <link>https://cvedaily.com/pages/tags/openbsd.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/openbsd.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – OpenBSD</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:55 +0000</lastBuildDate>
  <item>
    <title>[Medium] CVE-2026-41285 – In OpenBSD through 7.8, the slaacd and rad daemons have an infinite loop when th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41285</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41285</guid>
    <pubDate>Tue, 21 Apr 2026 00:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-41285</strong></p>
  <p>In OpenBSD through 7.8, the slaacd and rad daemons have an infinite loop when they receive a crafted ICMPv6 Neighbor Discovery (ND) option (over a local network) with length zero, because of an "nd_opt_len * 8 - 2" expression with no preceding check for whether nd_opt_len is zero.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-1284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41285">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33306 – bcrypt-ruby is a Ruby binding for the OpenBSD bcrypt() password hashing algorith...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33306</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33306</guid>
    <pubDate>Tue, 24 Mar 2026 01:17:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33306</strong></p>
  <p>bcrypt-ruby is a Ruby binding for the OpenBSD bcrypt() password hashing algorithm. Prior to version 3.1.22, an integer overflow in the Java BCrypt implementation for JRuby can cause zero iterations in the strengthening loop.  Impacted applications must be setting the cost to 31 to see this happen. The JRuby implementation of bcrypt-ruby (`BCrypt.java`) computes the key-strengthening round count a…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33306">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-67901 – openrsync through 0.5.0, as used in OpenBSD through 7.8 and on other platforms, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-67901</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-67901</guid>
    <pubDate>Mon, 15 Dec 2025 00:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-67901</strong></p>
  <p>openrsync through 0.5.0, as used in OpenBSD through 7.8 and on other platforms, allows a client to cause a server SIGSEGV by specifying a length of zero for block data, because the relationship between p->rem and p->len is not checked.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-1284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-67901">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Unknown] CVE-2023-53715 – In the Linux kernel, the following vulnerability has been resolved:

wifi: brcmf...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-53715</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-53715</guid>
    <pubDate>Wed, 22 Oct 2025 14:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk unknown">Unknown</span> CVE-2023-53715</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  wifi: brcmfmac: cfg80211: Pass the PMK in binary instead of hex  Apparently the hex passphrase mechanism does not work on newer chips/firmware (e.g. BCM4387). It seems there was a simple way of passing it in binary all along, so use that and avoid the hexification.  OpenBSD has been doing it like this from the beginning, so this…</p>
  <p><strong>CVSS:</strong> N/A · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-53715">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-30334 – In OpenBSD 7.6 before errata 006 and OpenBSD 7.5 before errata 015, traffic sent...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30334</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30334</guid>
    <pubDate>Thu, 20 Mar 2025 21:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-30334</strong></p>
  <p>In OpenBSD 7.6 before errata 006 and OpenBSD 7.5 before errata 015, traffic sent over wg(4) could result in kernel crash.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-131</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30334">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-11149 – In OpenBSD 7.4 before errata 014, vmm(4) did not restore GDTR limits properly on...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-11149</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-11149</guid>
    <pubDate>Fri, 06 Dec 2024 02:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-11149</strong></p>
  <p>In OpenBSD 7.4 before errata 014, vmm(4) did not restore GDTR limits properly on Intel (VMX) CPUs.</p>
  <p><strong>CVSS:</strong> 7.9 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-11149">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-11148 – In OpenBSD 7.4 before errata 006 and OpenBSD 7.3 before errata 020, httpd(8) is ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-11148</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-11148</guid>
    <pubDate>Thu, 05 Dec 2024 20:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-11148</strong></p>
  <p>In OpenBSD 7.4 before errata 006 and OpenBSD 7.3 before errata 020, httpd(8) is vulnerable to a NULL dereference when handling a malformed fastcgi request.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-11148">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-10933 – In OpenBSD 7.5 before errata 009 and OpenBSD 7.4 before errata 022, exclude any ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-10933</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-10933</guid>
    <pubDate>Thu, 05 Dec 2024 20:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-10933</strong></p>
  <p>In OpenBSD 7.5 before errata 009 and OpenBSD 7.4 before errata 022, exclude any '/' in readdir name validation to avoid unexpected directory traversal on untrusted file systems.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-10933">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-10934 – In OpenBSD 7.5 before errata 008 and OpenBSD 7.4 before errata 021, 
avoid possi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-10934</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-10934</guid>
    <pubDate>Fri, 15 Nov 2024 20:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-10934</strong></p>
  <p>In OpenBSD 7.5 before errata 008 and OpenBSD 7.4 before errata 021,  avoid possible mbuf double free in NFS client and server implementation, do not use uninitialized variable in error handling of NFS server.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-415</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-10934">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-43688 – cron/entry.c in vixie cron before 9cc8ab1, as used in OpenBSD 7.4 and 7.5, allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-43688</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-43688</guid>
    <pubDate>Tue, 20 Aug 2024 06:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-43688</strong></p>
  <p>cron/entry.c in vixie cron before 9cc8ab1, as used in OpenBSD 7.4 and 7.5, allows a heap-based buffer underflow and memory corruption. NOTE: this issue was introduced during a May 2023 refactoring.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-43688">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2021-35000 – OpenBSD Kernel Multicast Routing Uninitialized Memory Information Disclosure Vul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-35000</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-35000</guid>
    <pubDate>Tue, 07 May 2024 23:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2021-35000</strong></p>
  <p>OpenBSD Kernel Multicast Routing Uninitialized Memory Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installations of OpenBSD Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.  The specific flaw exists within the implementation…</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-35000">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-34999 – OpenBSD Kernel Multicast Routing Uninitialized Memory Information Disclosure Vul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-34999</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-34999</guid>
    <pubDate>Tue, 07 May 2024 23:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-34999</strong></p>
  <p>OpenBSD Kernel Multicast Routing Uninitialized Memory Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installations of OpenBSD Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.  The specific flaw exists within the implementation…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-34999">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-29937 – NFS in a BSD derived codebase, as used in OpenBSD through 7.4 and FreeBSD throug...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-29937</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-29937</guid>
    <pubDate>Thu, 11 Apr 2024 01:25:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-29937</strong></p>
  <p>NFS in a BSD derived codebase, as used in OpenBSD through 7.4 and FreeBSD through 14.0-RELEASE, allows remote attackers to execute arbitrary code via a bug that is unrelated to memory corruption.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-29937">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-52558 – In OpenBSD 7.4 before errata 002 and OpenBSD 7.3 before errata 019, a network bu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-52558</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-52558</guid>
    <pubDate>Fri, 01 Mar 2024 17:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-52558</strong></p>
  <p>In OpenBSD 7.4 before errata 002 and OpenBSD 7.3 before errata 019, a network buffer that had to be split at certain length that could crash the kernel after receiving specially crafted escape sequences.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-131</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-52558">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-52557 – In OpenBSD 7.3 before errata 016, npppd(8) could crash by a l2tp message which h...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-52557</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-52557</guid>
    <pubDate>Fri, 01 Mar 2024 17:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-52557</strong></p>
  <p>In OpenBSD 7.3 before errata 016, npppd(8) could crash by a l2tp message which has an AVP (Attribute-Value Pair) with wrong length.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-131</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-52557">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-52556 – In OpenBSD 7.4 before errata 009, a race condition between pf(4)'s processing of...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-52556</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-52556</guid>
    <pubDate>Fri, 01 Mar 2024 17:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-52556</strong></p>
  <p>In OpenBSD 7.4 before errata 009, a race condition between pf(4)'s processing of packets and expiration of packet states may cause a kernel panic.</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-52556">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-38283 – In OpenBGPD before 8.1, incorrect handling of BGP update data (length of path at...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-38283</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-38283</guid>
    <pubDate>Tue, 29 Aug 2023 16:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-38283</strong></p>
  <p>In OpenBGPD before 8.1, incorrect handling of BGP update data (length of path attributes) set by a potentially distant remote actor may cause the system to incorrectly reset a session. This is fixed in OpenBSD 7.3 errata 006.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-754</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-38283">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-40216 – OpenBSD 7.3 before errata 014 is missing an argument-count bounds check in conso...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-40216</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-40216</guid>
    <pubDate>Thu, 10 Aug 2023 16:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-40216</strong></p>
  <p>OpenBSD 7.3 before errata 014 is missing an argument-count bounds check in console terminal emulation. This could cause incorrect memory access and a kernel crash after receiving crafted DCS or CSI terminal escape sequences.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-40216">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-35784 – A double free or use after free could occur after SSL_clear in OpenBSD 7.2 befor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-35784</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-35784</guid>
    <pubDate>Fri, 16 Jun 2023 20:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-35784</strong></p>
  <p>A double free or use after free could occur after SSL_clear in OpenBSD 7.2 before errata 026 and 7.3 before errata 004, and in LibreSSL before 3.6.3 and 3.7.x before 3.7.3. NOTE: OpenSSL is not affected.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-415</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-35784">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-46880 – x509/x509_verify.c in LibreSSL before 3.4.2, and OpenBSD before 7.0 errata 006, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-46880</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-46880</guid>
    <pubDate>Sat, 15 Apr 2023 00:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-46880</strong></p>
  <p>x509/x509_verify.c in LibreSSL before 3.4.2, and OpenBSD before 7.0 errata 006, allows authentication bypass because an error for an unverified certificate chain is sometimes discarded.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-46880">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-48437 – An issue was discovered in x509/x509_verify.c in LibreSSL before 3.6.1, and in O...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-48437</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-48437</guid>
    <pubDate>Wed, 12 Apr 2023 05:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-48437</strong></p>
  <p>An issue was discovered in x509/x509_verify.c in LibreSSL before 3.6.1, and in OpenBSD before 7.2 errata 001. x509_verify_ctx_add_chain does not store errors that occur during leaf certificate verification, and therefore an incorrect error is returned. This behavior occurs when there is an installed verification callback that instructs the verifier to continue upon detecting an invalid certificat…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-48437">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-29323 – ascii_load_sockaddr in smtpd in OpenBSD before 7.1 errata 024 and 7.2 before err...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-29323</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-29323</guid>
    <pubDate>Tue, 04 Apr 2023 23:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-29323</strong></p>
  <p>ascii_load_sockaddr in smtpd in OpenBSD before 7.1 errata 024 and 7.2 before errata 020, and OpenSMTPD Portable before 7.0.0-portable commit f748277, can abort upon a connection from a local, scoped IPv6 address.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-29323">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-28339 – OpenDoas through 6.8.2, when TIOCSTI is available, allows privilege escalation b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-28339</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-28339</guid>
    <pubDate>Tue, 14 Mar 2023 19:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-28339</strong></p>
  <p>OpenDoas through 6.8.2, when TIOCSTI is available, allows privilege escalation because of sharing a terminal with the original session. NOTE: TIOCSTI is unavailable in OpenBSD 6.0 and later, and can be made unavailable in the Linux kernel 6.2 and later.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-28339">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-27567 – In OpenBSD 7.2, a TCP packet with destination port 0 that matches a pf divert-to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-27567</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-27567</guid>
    <pubDate>Fri, 03 Mar 2023 22:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-27567</strong></p>
  <p>In OpenBSD 7.2, a TCP packet with destination port 0 that matches a pf divert-to rule can crash the kernel.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-27567">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-27882 – slaacd in OpenBSD 6.9 and 7.0 before 2022-03-22 has an integer signedness error ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-27882</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-27882</guid>
    <pubDate>Fri, 25 Mar 2022 18:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-27882</strong></p>
  <p>slaacd in OpenBSD 6.9 and 7.0 before 2022-03-22 has an integer signedness error and resultant heap-based buffer overflow triggerable by a crafted IPv6 router advertisement. NOTE: privilege separation and pledge can prevent exploitation.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-681</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27882">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-27881 – engine.c in slaacd in OpenBSD 6.9 and 7.0 before 2022-02-21 has a buffer overflo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-27881</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-27881</guid>
    <pubDate>Fri, 25 Mar 2022 18:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-27881</strong></p>
  <p>engine.c in slaacd in OpenBSD 6.9 and 7.0 before 2022-02-21 has a buffer overflow triggerable by an IPv6 router advertisement with more than seven nameservers. NOTE: privilege separation and pledge can prevent exploitation.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27881">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2010-4816 – It was found in FreeBSD 8.0, 6.3 and 4.9, and OpenBSD 4.6 that a null pointer de...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-4816</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-4816</guid>
    <pubDate>Tue, 22 Jun 2021 14:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2010-4816</strong></p>
  <p>It was found in FreeBSD 8.0, 6.3 and 4.9, and OpenBSD 4.6 that a null pointer dereference in ftpd/popen.c may lead to remote denial of service of the ftpd service.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-4816">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-26142 – An issue was discovered in the kernel in OpenBSD 6.6. The WEP, WPA, WPA2, and WP...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-26142</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-26142</guid>
    <pubDate>Tue, 11 May 2021 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-26142</strong></p>
  <p>An issue was discovered in the kernel in OpenBSD 6.6. The WEP, WPA, WPA2, and WPA3 implementations treat fragmented frames as full frames. An adversary can abuse this to inject arbitrary network packets, independent of the network configuration.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-26142">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-16088 – iked in OpenIKED, as used in OpenBSD through 6.7, allows authentication bypass b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-16088</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-16088</guid>
    <pubDate>Tue, 28 Jul 2020 12:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-16088</strong></p>
  <p>iked in OpenIKED, as used in OpenBSD through 6.7, allows authentication bypass because ca.c has the wrong logic for checking whether a public key matches.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-16088">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-10030 – An issue has been found in PowerDNS Recursor 4.1.0 up to and including 4.3.0. It...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-10030</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-10030</guid>
    <pubDate>Tue, 19 May 2020 16:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-10030</strong></p>
  <p>An issue has been found in PowerDNS Recursor 4.1.0 up to and including 4.3.0. It allows an attacker (with enough privileges to change the system's hostname) to cause disclosure of uninitialized memory content via a stack-based out-of-bounds read. It only occurs on systems where gethostname() does not have '\0' termination of the returned string if the hostname is larger than the supplied buffer.…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-10030">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-7247 – smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and oth...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7247</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7247</guid>
    <pubDate>Wed, 29 Jan 2020 16:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-7247</strong></p>
  <p>smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary commands as root via a crafted SMTP session, as demonstrated by shell metacharacters in a MAIL FROM field. This affects the "uncommented" default configuration. The issue exists because of an incorrect return value upon failure of input validation.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7247">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-19726 – OpenBSD through 6.6 allows local users to escalate to root because a check for L...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-19726</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-19726</guid>
    <pubDate>Thu, 12 Dec 2019 01:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-19726</strong></p>
  <p>OpenBSD through 6.6 allows local users to escalate to root because a check for LD_LIBRARY_PATH in setuid programs can be defeated by setting a very small RLIMIT_DATA resource limit. When executing chpass or passwd (which are setuid root), _dl_setup_env in ld.so tries to strip LD_LIBRARY_PATH from the environment, but fails when it cannot allocate memory. Thus, the attacker is able to execute thei…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-19726">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-14899 – A vulnerability was discovered in Linux, FreeBSD, OpenBSD, MacOS, iOS, and Andro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-14899</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-14899</guid>
    <pubDate>Wed, 11 Dec 2019 15:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-14899</strong></p>
  <p>A vulnerability was discovered in Linux, FreeBSD, OpenBSD, MacOS, iOS, and Android that allows a malicious access point, or an adjacent user, to determine if a connected user is using a VPN, make positive inferences about the websites they are visiting, and determine the correct sequence and acknowledgement numbers in use, allowing the bad actor to inject data into the TCP stream. This provides e…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-300</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-14899">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2012-1577 – lib/libc/stdlib/random.c in OpenBSD returns 0 when seeded with 0.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-1577</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-1577</guid>
    <pubDate>Tue, 10 Dec 2019 19:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2012-1577</strong></p>
  <p>lib/libc/stdlib/random.c in OpenBSD returns 0 when seeded with 0.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-335</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-1577">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-19522 – OpenBSD 6.6, in a non-default configuration where S/Key or YubiKey authenticatio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-19522</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-19522</guid>
    <pubDate>Thu, 05 Dec 2019 00:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-19522</strong></p>
  <p>OpenBSD 6.6, in a non-default configuration where S/Key or YubiKey authentication is enabled, allows local users to become root by leveraging membership in the auth group. This occurs because root's file can be written to /etc/skey or /var/db/yubikey, and need not be owned by root.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-19522">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-19521 – libc in OpenBSD 6.6 allows authentication bypass via the -schallenge username, a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-19521</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-19521</guid>
    <pubDate>Thu, 05 Dec 2019 00:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-19521</strong></p>
  <p>libc in OpenBSD 6.6 allows authentication bypass via the -schallenge username, as demonstrated by smtpd, ldapd, or radiusd. This is related to gen/auth_subr.c and gen/authenticate.c in libc (and login/login.c and xenocara/app/xenodm/greeter/verify.c).</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-19521">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-19520 – xlock in OpenBSD 6.6 allows local users to gain the privileges of the auth group...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-19520</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-19520</guid>
    <pubDate>Thu, 05 Dec 2019 00:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-19520</strong></p>
  <p>xlock in OpenBSD 6.6 allows local users to gain the privileges of the auth group by providing a LIBGL_DRIVERS_PATH environment variable, because xenocara/lib/mesa/src/loader/loader.c mishandles dlopen.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-19520">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-19519 – In OpenBSD 6.6, local users can use the su -L option to achieve any login class ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-19519</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-19519</guid>
    <pubDate>Thu, 05 Dec 2019 00:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-19519</strong></p>
  <p>In OpenBSD 6.6, local users can use the su -L option to achieve any login class (often excluding root) because there is a logic error in the main function in su/su.c.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-19519">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-15901 – An issue was discovered in slicer69 doas before 6.2 on certain platforms other t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-15901</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-15901</guid>
    <pubDate>Fri, 18 Oct 2019 16:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-15901</strong></p>
  <p>An issue was discovered in slicer69 doas before 6.2 on certain platforms other than OpenBSD. A setusercontext(3) call with flags to change the UID, primary GID, and secondary GIDs was replaced (on certain platforms: Linux and possibly NetBSD) with a single setuid(2) call. This resulted in neither changing the group id nor initializing secondary group ids.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-15901">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-15900 – An issue was discovered in slicer69 doas before 6.2 on certain platforms other t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-15900</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-15900</guid>
    <pubDate>Fri, 18 Oct 2019 16:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-15900</strong></p>
  <p>An issue was discovered in slicer69 doas before 6.2 on certain platforms other than OpenBSD. On platforms without strtonum(3), sscanf was used without checking for error cases. Instead, the uninitialized variable errstr was checked and in some cases returned success even if sscanf failed. The result was that, instead of reporting that the supplied username or group name did not exist, it would ex…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-252</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-15900">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-8460 – OpenBSD kernel version &lt;= 6.5 can be forced to create long chains of TCP SACK ho...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-8460</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-8460</guid>
    <pubDate>Mon, 26 Aug 2019 20:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-8460</strong></p>
  <p>OpenBSD kernel version <= 6.5 can be forced to create long chains of TCP SACK holes that causes very expensive calls to tcp_sack_option() for every incoming SACK packet which can lead to a denial of service.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-1049</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-8460">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-6724 – The barracudavpn component of the Barracuda VPN Client prior to version 5.0.2.7 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-6724</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-6724</guid>
    <pubDate>Thu, 21 Mar 2019 16:01:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-6724</strong></p>
  <p>The barracudavpn component of the Barracuda VPN Client prior to version 5.0.2.7 for Linux, macOS, and OpenBSD runs as a privileged process and can allow an unprivileged local attacker to load a malicious library, resulting in arbitrary code executing as root.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-426</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-6724">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-14775 – tss_alloc in sys/arch/i386/i386/gdt.c in OpenBSD 6.2 and 6.3 has a Local Denial ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-14775</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-14775</guid>
    <pubDate>Wed, 01 Aug 2018 06:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-14775</strong></p>
  <p>tss_alloc in sys/arch/i386/i386/gdt.c in OpenBSD 6.2 and 6.3 has a Local Denial of Service (system crash) due to incorrect I/O port access control on the i386 architecture.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-14775">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2017-17080 – elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-17080</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-17080</guid>
    <pubDate>Thu, 30 Nov 2017 21:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2017-17080</strong></p>
  <p>elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, does not validate sizes of core notes, which allows remote attackers to cause a denial of service (bfd_getl32 heap-based buffer over-read and application crash) via a crafted object file, related to elfcore_grok_netbsd_procinfo, elfcore_grok_openbsd_procinfo, and elfcore_grok_nto_status.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-17080">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2017-1000373 – The OpenBSD qsort() function is recursive, and not randomized, an attacker can c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-1000373</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-1000373</guid>
    <pubDate>Mon, 19 Jun 2017 16:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2017-1000373</strong></p>
  <p>The OpenBSD qsort() function is recursive, and not randomized, an attacker can construct a pathological input array of N elements that causes qsort() to deterministically recurse N/4 times. This allows attackers to consume arbitrary amounts of stack memory and manipulate stack memory to assist in arbitrary code execution attacks. This affects OpenBSD 6.1 and possibly earlier versions.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-1000373">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-1000372 – A flaw exists in OpenBSD's implementation of the stack guard page that allows at...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-1000372</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-1000372</guid>
    <pubDate>Mon, 19 Jun 2017 16:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-1000372</strong></p>
  <p>A flaw exists in OpenBSD's implementation of the stack guard page that allows attackers to bypass it resulting in arbitrary code execution using setuid binaries such as /usr/bin/at. This affects OpenBSD 6.1 and possibly earlier versions.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-1000372">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-5850 – httpd in OpenBSD allows remote attackers to cause a denial of service (memory co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-5850</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-5850</guid>
    <pubDate>Mon, 27 Mar 2017 15:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-5850</strong></p>
  <p>httpd in OpenBSD allows remote attackers to cause a denial of service (memory consumption) via a series of requests for a large file using an HTTP Range header.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-5850">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-6522 – Integer overflow in the uvm_map_isavail function in uvm/uvm_map.c in OpenBSD 5.9...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-6522</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-6522</guid>
    <pubDate>Tue, 07 Mar 2017 16:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-6522</strong></p>
  <p>Integer overflow in the uvm_map_isavail function in uvm/uvm_map.c in OpenBSD 5.9 allows local users to cause a denial of service (kernel panic) via a crafted mmap call, which triggers the new mapping to overlap with an existing mapping.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6522">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-6350 – OpenBSD 5.8 and 5.9 allows local users to cause a denial of service (NULL pointe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-6350</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-6350</guid>
    <pubDate>Tue, 07 Mar 2017 16:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-6350</strong></p>
  <p>OpenBSD 5.8 and 5.9 allows local users to cause a denial of service (NULL pointer dereference and panic) via a sysctl call with a path starting with 10,9.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6350">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-6247 – OpenBSD 5.8 and 5.9 allows certain local users to cause a denial of service (ker...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-6247</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-6247</guid>
    <pubDate>Tue, 07 Mar 2017 16:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-6247</strong></p>
  <p>OpenBSD 5.8 and 5.9 allows certain local users to cause a denial of service (kernel panic) by unmounting a filesystem with an open vnode on the mnt_vnodelist.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6247">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-6246 – OpenBSD 5.8 and 5.9 allows certain local users with kern.usermount privileges to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-6246</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-6246</guid>
    <pubDate>Tue, 07 Mar 2017 16:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-6246</strong></p>
  <p>OpenBSD 5.8 and 5.9 allows certain local users with kern.usermount privileges to cause a denial of service (kernel panic) by mounting a tmpfs with a VNOVAL in the (1) username, (2) groupname, or (3) device name of the root node.</p>
  <p><strong>CVSS:</strong> 4.4 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6246">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-6245 – OpenBSD 5.8 and 5.9 allows local users to cause a denial of service (kernel pani...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-6245</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-6245</guid>
    <pubDate>Tue, 07 Mar 2017 16:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-6245</strong></p>
  <p>OpenBSD 5.8 and 5.9 allows local users to cause a denial of service (kernel panic) via a large size in a getdents system call.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6245">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-6243 – thrsleep in kern/kern_synch.c in OpenBSD 5.8 and 5.9 allows local users to cause...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-6243</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-6243</guid>
    <pubDate>Tue, 07 Mar 2017 16:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-6243</strong></p>
  <p>thrsleep in kern/kern_synch.c in OpenBSD 5.8 and 5.9 allows local users to cause a denial of service (kernel panic) via a crafted value in the tsp parameter of the __thrsleep system call.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6243">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-6242 – OpenBSD 5.8 and 5.9 allows local users to cause a denial of service (assertion f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-6242</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-6242</guid>
    <pubDate>Tue, 07 Mar 2017 16:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-6242</strong></p>
  <p>OpenBSD 5.8 and 5.9 allows local users to cause a denial of service (assertion failure and kernel panic) via a large ident value in a kevent system call.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-189</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6242">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-6241 – Integer overflow in the amap_alloc1 function in OpenBSD 5.8 and 5.9 allows local...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-6241</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-6241</guid>
    <pubDate>Tue, 07 Mar 2017 16:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-6241</strong></p>
  <p>Integer overflow in the amap_alloc1 function in OpenBSD 5.8 and 5.9 allows local users to execute arbitrary code with kernel privileges via a large size value.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6241">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-6240 – Integer truncation error in the amap_alloc function in OpenBSD 5.8 and 5.9 allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-6240</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-6240</guid>
    <pubDate>Tue, 07 Mar 2017 16:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-6240</strong></p>
  <p>Integer truncation error in the amap_alloc function in OpenBSD 5.8 and 5.9 allows local users to execute arbitrary code with kernel privileges via a large size value.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-189</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6240">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-6239 – The mmap extension __MAP_NOFAULT in OpenBSD 5.8 and 5.9 allows attackers to caus...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-6239</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-6239</guid>
    <pubDate>Tue, 07 Mar 2017 16:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-6239</strong></p>
  <p>The mmap extension __MAP_NOFAULT in OpenBSD 5.8 and 5.9 allows attackers to cause a denial of service (kernel panic and crash) via a large size value.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6239">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-6244 – The sys_thrsigdivert function in kern/kern_sig.c in the OpenBSD kernel 5.9 allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-6244</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-6244</guid>
    <pubDate>Tue, 07 Mar 2017 15:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-6244</strong></p>
  <p>The sys_thrsigdivert function in kern/kern_sig.c in the OpenBSD kernel 5.9 allows remote attackers to cause a denial of service (panic) via a negative "ts.tv_sec" value.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6244">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2015-8100 – The net-snmp package in OpenBSD through 5.8 uses 0644 permissions for snmpd.conf...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-8100</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-8100</guid>
    <pubDate>Tue, 10 Nov 2015 03:59:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2015-8100</strong></p>
  <p>The net-snmp package in OpenBSD through 5.8 uses 0644 permissions for snmpd.conf, which allows local users to obtain sensitive community information by reading this file.</p>
  <p><strong>CVSS:</strong> 2.1 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-8100">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-6564 – Use-after-free vulnerability in the mm_answer_pam_free_ctx function in monitor.c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-6564</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-6564</guid>
    <pubDate>Mon, 24 Aug 2015 01:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-6564</strong></p>
  <p>Use-after-free vulnerability in the mm_answer_pam_free_ctx function in monitor.c in sshd in OpenSSH before 7.0 on non-OpenBSD platforms might allow local users to gain privileges by leveraging control of the sshd uid to send an unexpectedly early MONITOR_REQ_PAM_FREE_CTX request.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-6564">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2015-6563 – The monitor component in sshd in OpenSSH before 7.0 on non-OpenBSD platforms acc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-6563</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-6563</guid>
    <pubDate>Mon, 24 Aug 2015 01:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2015-6563</strong></p>
  <p>The monitor component in sshd in OpenSSH before 7.0 on non-OpenBSD platforms accepts extraneous username data in MONITOR_REQ_PAM_INIT_CTX requests, which allows local users to conduct impersonation attacks by leveraging any SSH login access in conjunction with control of the sshd uid to send a crafted MONITOR_REQ_PWNAM request, related to monitor.c and monitor_wrap.c.</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-6563">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2014-7250 – The TCP stack in 4.3BSD Net/2, as used in FreeBSD 5.4, NetBSD possibly 2.0, and ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-7250</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-7250</guid>
    <pubDate>Fri, 12 Dec 2014 03:03:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2014-7250</strong></p>
  <p>The TCP stack in 4.3BSD Net/2, as used in FreeBSD 5.4, NetBSD possibly 2.0, and OpenBSD possibly 3.6, does not properly implement the session timer, which allows remote attackers to cause a denial of service (resource consumption) via crafted packets.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-7250">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2013-3951 – sys/openbsd/stack_protector.c in libc in Apple iOS 6.1.3 and Mac OS X 10.8.x doe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-3951</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-3951</guid>
    <pubDate>Wed, 05 Jun 2013 14:39:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2013-3951</strong></p>
  <p>sys/openbsd/stack_protector.c in libc in Apple iOS 6.1.3 and Mac OS X 10.8.x does not properly parse the Apple strings employed in the user-space stack-cookie implementation, which allows local users to bypass cookie randomization by executing a program with a call-path beginning with the stack-guard= substring, as demonstrated by an iOS untethering attack or an attack against a setuid Mac OS X p…</p>
  <p><strong>CVSS:</strong> 4.6 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-3951">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2011-2895 – The LZW decompressor in (1) the BufCompressedFill function in fontfile/decompres...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-2895</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-2895</guid>
    <pubDate>Fri, 19 Aug 2011 17:55:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2011-2895</strong></p>
  <p>The LZW decompressor in (1) the BufCompressedFill function in fontfile/decompress.c in X.Org libXfont before 1.4.4 and (2) compress/compress.c in 4.3BSD, as used in zopen.c in OpenBSD before 3.8, FreeBSD, NetBSD 4.0.x and 5.0.x before 5.0.3 and 5.1.x before 5.1.1, FreeType 2.1.9, and other products, does not properly handle code words that are absent from the decompression table when encountered,…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-2895">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2011-2168 – Multiple integer overflows in the glob implementation in libc in OpenBSD before ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-2168</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-2168</guid>
    <pubDate>Tue, 24 May 2011 23:55:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2011-2168</strong></p>
  <p>Multiple integer overflows in the glob implementation in libc in OpenBSD before 4.9 might allow context-dependent attackers to have an unspecified impact via a crafted string, related to the GLOB_APPEND and GLOB_DOOFFS flags, a different issue than CVE-2011-0418.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-189</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-2168">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2011-0419 – Stack consumption vulnerability in the fnmatch implementation in apr_fnmatch.c i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-0419</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-0419</guid>
    <pubDate>Mon, 16 May 2011 17:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2011-0419</strong></p>
  <p>Stack consumption vulnerability in the fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library before 1.4.3 and the Apache HTTP Server before 2.2.18, and in fnmatch.c in libc in NetBSD 5.1, OpenBSD 4.8, FreeBSD, Apple Mac OS X 10.6, Oracle Solaris 10, and Android, allows context-dependent attackers to cause a denial of service (CPU and memory consumption) via *? seque…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-0419">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2011-1013 – Integer signedness error in the drm_modeset_ctl function in (1) drivers/gpu/drm/...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-1013</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-1013</guid>
    <pubDate>Mon, 09 May 2011 19:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2011-1013</strong></p>
  <p>Integer signedness error in the drm_modeset_ctl function in (1) drivers/gpu/drm/drm_irq.c in the Direct Rendering Manager (DRM) subsystem in the Linux kernel before 2.6.38 and (2) sys/dev/pci/drm/drm_irq.c in the kernel in OpenBSD before 4.9 allows local users to trigger out-of-bounds write operations, and consequently cause a denial of service (system crash) or possibly have unspecified other im…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-1013">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2010-4755 – The (1) remote_glob function in sftp-glob.c and the (2) process_put function in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-4755</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-4755</guid>
    <pubDate>Wed, 02 Mar 2011 20:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2010-4755</strong></p>
  <p>The (1) remote_glob function in sftp-glob.c and the (2) process_put function in sftp.c in OpenSSH 5.8 and earlier, as used in FreeBSD 7.3 and 8.1, NetBSD 5.0.2, OpenBSD 4.7, and other products, allow remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in SSH_FXP_STAT…</p>
  <p><strong>CVSS:</strong> 4.0 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-4755">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2010-4754 – The glob implementation in libc in FreeBSD 7.3 and 8.1, NetBSD 5.0.2, and OpenBS...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-4754</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-4754</guid>
    <pubDate>Wed, 02 Mar 2011 20:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2010-4754</strong></p>
  <p>The glob implementation in libc in FreeBSD 7.3 and 8.1, NetBSD 5.0.2, and OpenBSD 4.7, and Libsystem in Apple Mac OS X before 10.6.8, allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-…</p>
  <p><strong>CVSS:</strong> 4.0 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-4754">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2009-3572 – OpenBSD 4.4, 4.5, and 4.6, when running on an i386 kernel, does not properly han...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-3572</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-3572</guid>
    <pubDate>Tue, 06 Oct 2009 20:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2009-3572</strong></p>
  <p>OpenBSD 4.4, 4.5, and 4.6, when running on an i386 kernel, does not properly handle XMM exceptions, which allows local users to cause a denial of service (kernel panic) via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-3572">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2009-0687 – The pf_test_rule function in OpenBSD Packet Filter (PF), as used in OpenBSD 4.2 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-0687</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-0687</guid>
    <pubDate>Tue, 11 Aug 2009 10:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2009-0687</strong></p>
  <p>The pf_test_rule function in OpenBSD Packet Filter (PF), as used in OpenBSD 4.2 through 4.5, NetBSD 5.0 before RC3, MirOS 10 and earlier, and MidnightBSD 0.3-current allows remote attackers to cause a denial of service (panic) via crafted IP packets that trigger a NULL pointer dereference during translation, related to an IPv4 packet with an ICMPv6 payload.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-0687">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2009-0689 – Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-0689</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-0689</guid>
    <pubDate>Wed, 01 Jul 2009 13:00:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2009-0689</strong></p>
  <p>Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the (2) gdtoa (aka new dtoa) implementation in gdtoa/misc.c in libc, as used in multiple operating systems and products including in FreeBSD 6.4 and 7.2, NetBSD 5.0, OpenBSD 4.5, Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4, K-Meleon 1.5.3, SeaMonkey 1.1.8, and other products, allows context-dependent attac…</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-0689">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2009-0537 – Integer overflow in the fts_build function in fts.c in libc in (1) OpenBSD 4.4 a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-0537</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-0537</guid>
    <pubDate>Mon, 09 Mar 2009 21:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2009-0537</strong></p>
  <p>Integer overflow in the fts_build function in fts.c in libc in (1) OpenBSD 4.4 and earlier and (2) Microsoft Interix 6.0 build 10.0.6030.0 allows context-dependent attackers to cause a denial of service (application crash) via a deep directory tree, related to the fts_level structure member, as demonstrated by (a) du, (b) rm, (c) chmod, and (d) chgrp on OpenBSD; and (e) SearchIndexer.exe on Vista…</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-189</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-0537">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2009-0780 – The aspath_prepend function in rde_attr.c in bgpd in OpenBSD 4.3 and 4.4 allows ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-0780</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-0780</guid>
    <pubDate>Wed, 04 Mar 2009 11:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2009-0780</strong></p>
  <p>The aspath_prepend function in rde_attr.c in bgpd in OpenBSD 4.3 and 4.4 allows remote attackers to cause a denial of service (application crash) via an Autonomous System (AS) advertisement containing a long AS path.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-0780">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2008-3831 – The i915 driver in (1) drivers/char/drm/i915_dma.c in the Linux kernel 2.6.24 on...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-3831</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-3831</guid>
    <pubDate>Mon, 20 Oct 2008 17:59:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2008-3831</strong></p>
  <p>The i915 driver in (1) drivers/char/drm/i915_dma.c in the Linux kernel 2.6.24 on Debian GNU/Linux and (2) sys/dev/pci/drm/i915_drv.c in OpenBSD does not restrict the DRM_I915_HWS_ADDR ioctl to the Direct Rendering Manager (DRM) master, which allows local users to cause a denial of service (memory corruption) via a crafted ioctl call, related to absence of the DRM_MASTER and DRM_ROOT_ONLY flags in…</p>
  <p><strong>CVSS:</strong> 4.7 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-3831">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2008-2476 – The IPv6 Neighbor Discovery Protocol (NDP) implementation in (1) FreeBSD 6.3 thr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-2476</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-2476</guid>
    <pubDate>Fri, 03 Oct 2008 15:07:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2008-2476</strong></p>
  <p>The IPv6 Neighbor Discovery Protocol (NDP) implementation in (1) FreeBSD 6.3 through 7.1, (2) OpenBSD 4.2 and 4.3, (3) NetBSD, (4) Force10 FTOS before E7.7.1.1, (5) Juniper JUNOS, and (6) Wind River VxWorks 5.x through 6.4 does not validate the origin of Neighbor Discovery messages, which allows remote attackers to cause a denial of service (loss of connectivity) or read private network traffic v…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-2476">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-4247 – ftpd in OpenBSD 4.3, FreeBSD 7.0, NetBSD 4.0, Solaris, and possibly other operat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-4247</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-4247</guid>
    <pubDate>Thu, 25 Sep 2008 19:25:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-4247</strong></p>
  <p>ftpd in OpenBSD 4.3, FreeBSD 7.0, NetBSD 4.0, Solaris, and possibly other operating systems interprets long commands from an FTP client as multiple commands, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and execute arbitrary FTP commands via a long ftp:// URI that leverages an existing session from the FTP client implementation in a web browser.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-4247">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2008-1215 – Stack-based buffer overflow in the command_Expand_Interpret function in command...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-1215</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-1215</guid>
    <pubDate>Sun, 09 Mar 2008 02:44:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2008-1215</strong></p>
  <p>Stack-based buffer overflow in the command_Expand_Interpret function in command.c in ppp (aka user-ppp), as distributed in FreeBSD 6.3 and 7.0, OpenBSD 4.1 and 4.2, and the net/userppp package for NetBSD, allows local users to gain privileges via long commands containing "~" characters.</p>
  <p><strong>CVSS:</strong> 4.6 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-1215">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2008-1146 – A certain pseudo-random number generator (PRNG) algorithm that uses XOR and 3-bi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-1146</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-1146</guid>
    <pubDate>Tue, 04 Mar 2008 23:44:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2008-1146</strong></p>
  <p>A certain pseudo-random number generator (PRNG) algorithm that uses XOR and 3-bit random hops (aka "Algorithm X3"), as used in OpenBSD 2.8 through 4.2, allows remote attackers to guess sensitive values such as DNS transaction IDs by observing a sequence of previously generated values.  NOTE: this issue can be leveraged for attacks such as DNS cache poisoning against OpenBSD's modification of BIND.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-1146">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2008-1147 – A certain pseudo-random number generator (PRNG) algorithm that uses XOR and 2-bi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-1147</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-1147</guid>
    <pubDate>Tue, 04 Mar 2008 23:44:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2008-1147</strong></p>
  <p>A certain pseudo-random number generator (PRNG) algorithm that uses XOR and 2-bit random hops (aka "Algorithm X2"), as used in OpenBSD 2.6 through 3.4, Mac OS X 10 through 10.5.1, FreeBSD 4.4 through 7.0, and DragonFlyBSD 1.0 through 1.10.1, allows remote attackers to guess sensitive values such as IP fragmentation IDs by observing a sequence of previously generated values.  NOTE: this issue can…</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-1147">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2008-1148 – A certain pseudo-random number generator (PRNG) algorithm that uses ADD with 0 r...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-1148</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-1148</guid>
    <pubDate>Tue, 04 Mar 2008 23:44:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2008-1148</strong></p>
  <p>A certain pseudo-random number generator (PRNG) algorithm that uses ADD with 0 random hops (aka "Algorithm A0"), as used in OpenBSD 3.5 through 4.2 and NetBSD 1.6.2 through 4.0, allows remote attackers to guess sensitive values such as (1) DNS transaction IDs or (2) IP fragmentation IDs by observing a sequence of previously generated values.  NOTE: this issue can be leveraged for attacks such as…</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-1148">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-1057 – The ip6_check_rh0hdr function in netinet6/ip6_input.c in OpenBSD 4.2 allows atta...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-1057</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-1057</guid>
    <pubDate>Thu, 28 Feb 2008 19:44:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-1057</strong></p>
  <p>The ip6_check_rh0hdr function in netinet6/ip6_input.c in OpenBSD 4.2 allows attackers to cause a denial of service (panic) via malformed IPv6 routing headers.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-1057">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-1058 – The tcp_respond function in netinet/tcp_subr.c in OpenBSD 4.1 and 4.2 allows att...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-1058</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-1058</guid>
    <pubDate>Thu, 28 Feb 2008 19:44:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-1058</strong></p>
  <p>The tcp_respond function in netinet/tcp_subr.c in OpenBSD 4.1 and 4.2 allows attackers to cause a denial of service (panic) via crafted TCP packets.  NOTE: some of these details are obtained from third party information.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-1058">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2007-6700 – Cross-site scripting (XSS) vulnerability in cgi-bin/bgplg in the web interface f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-6700</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-6700</guid>
    <pubDate>Tue, 05 Feb 2008 02:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2007-6700</strong></p>
  <p>Cross-site scripting (XSS) vulnerability in cgi-bin/bgplg in the web interface for the BGPD daemon in OpenBSD 4.1 allows remote attackers to inject arbitrary web script or HTML via the cmd parameter.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-6700">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2008-0384 – OpenBSD 4.2 allows local users to cause a denial of service (kernel panic) by ca...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-0384</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-0384</guid>
    <pubDate>Tue, 22 Jan 2008 20:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2008-0384</strong></p>
  <p>OpenBSD 4.2 allows local users to cause a denial of service (kernel panic) by calling the SIOCGIFRTLABEL IOCTL on an interface that does not have a route label, which triggers a NULL pointer dereference when the return value from the rtlabel_id2name function is not checked.</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-0384">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-5365 – Stack-based buffer overflow in the cons_options function in options.c in dhcpd i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-5365</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-5365</guid>
    <pubDate>Thu, 11 Oct 2007 10:17:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-5365</strong></p>
  <p>Stack-based buffer overflow in the cons_options function in options.c in dhcpd in OpenBSD 4.0 through 4.2, and some other dhcpd implementations based on ISC dhcp-2, allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a DHCP request specifying a maximum message size smaller than the minimum IP MTU.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-5365">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2007-4305 – Multiple race conditions in the (1) Sudo monitor mode and (2) Sysjail policies i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-4305</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-4305</guid>
    <pubDate>Mon, 13 Aug 2007 21:17:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2007-4305</strong></p>
  <p>Multiple race conditions in the (1) Sudo monitor mode and (2) Sysjail policies in Systrace on NetBSD and OpenBSD allow local users to defeat system call interposition, and consequently bypass access control policy and auditing.</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-4305">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2006-7215 – The Intel Core 2 Extreme processor X6800 and Core 2 Duo desktop processor E6000 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-7215</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-7215</guid>
    <pubDate>Tue, 03 Jul 2007 21:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2006-7215</strong></p>
  <p>The Intel Core 2 Extreme processor X6800 and Core 2 Duo desktop processor E6000 and E4000 incorrectly set the memory page Access (A) bit for a page in certain circumstances involving proximity of the code segment limit to the end of a code page, which has unknown impact and attack vectors on certain operating systems other than OpenBSD, aka AI90.</p>
  <p><strong>CVSS:</strong> 2.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-7215">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-1523 – Heap-based buffer overflow in the kernel in NetBSD 3.0, certain versions of Free...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-1523</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-1523</guid>
    <pubDate>Tue, 20 Mar 2007 20:19:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-1523</strong></p>
  <p>Heap-based buffer overflow in the kernel in NetBSD 3.0, certain versions of FreeBSD and OpenBSD, and possibly other BSD derived operating systems allows local users to have an unknown impact.  NOTE: this information is based upon a vague pre-advisory with no actionable information. Details will be updated after 20070329.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-1523">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2007-1365 – Buffer overflow in kern/uipc_mbuf2.c in OpenBSD 3.9 and 4.0 allows remote attack...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-1365</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-1365</guid>
    <pubDate>Sat, 10 Mar 2007 21:19:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2007-1365</strong></p>
  <p>Buffer overflow in kern/uipc_mbuf2.c in OpenBSD 3.9 and 4.0 allows remote attackers to execute arbitrary code via fragmented IPv6 packets due to "incorrect mbuf handling for ICMP6 packets."  NOTE: this was originally reported as a denial of service.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-1365">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2007-0343 – OpenBSD before 20070116 allows remote attackers to cause a denial of service (in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-0343</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-0343</guid>
    <pubDate>Thu, 18 Jan 2007 02:28:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2007-0343</strong></p>
  <p>OpenBSD before 20070116 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via certain IPv6 ICMP (aka ICMP6) echo request packets.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-0343">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2007-0085 – Unspecified vulnerability in sys/dev/pci/vga_pci.c in the VGA graphics driver fo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-0085</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-0085</guid>
    <pubDate>Fri, 05 Jan 2007 11:28:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2007-0085</strong></p>
  <p>Unspecified vulnerability in sys/dev/pci/vga_pci.c in the VGA graphics driver for wscons in OpenBSD 3.9 and 4.0, when the kernel is compiled with the PCIAGP option and a non-AGP device is being used, allows local users to gain privileges via unspecified vectors, possibly related to agp_ioctl NULL pointer reference.</p>
  <p><strong>CVSS:</strong> 6.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-0085">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2006-6730 – OpenBSD and NetBSD permit usermode code to kill the display server and write to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-6730</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-6730</guid>
    <pubDate>Tue, 26 Dec 2006 23:28:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2006-6730</strong></p>
  <p>OpenBSD and NetBSD permit usermode code to kill the display server and write to the X.Org /dev/xf86 device, which allows local users with root privileges to reduce securelevel by replacing the System Management Mode (SMM) handler via a write to an SMRAM address within /dev/xf86 (aka the video card memory-mapped I/O range), and then launching the new handler via a System Management Interrupt (SMI)…</p>
  <p><strong>CVSS:</strong> 6.6 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-6730">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2006-6397 – Integer overflow in banner/banner.c in FreeBSD, NetBSD, and OpenBSD might allow ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-6397</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-6397</guid>
    <pubDate>Fri, 08 Dec 2006 01:28:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2006-6397</strong></p>
  <p>Integer overflow in banner/banner.c in FreeBSD, NetBSD, and OpenBSD might allow local users to modify memory via a long banner.  NOTE: CVE and multiple third parties dispute this issue. Since banner is not setuid, an exploit would not cross privilege boundaries in normal operations. This issue is not a vulnerability</p>
  <p><strong>CVSS:</strong> 4.4 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-6397">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-6164 – The _dl_unsetenv function in loader.c in the ELF ld.so in OpenBSD 3.9 and 4.0 do...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-6164</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-6164</guid>
    <pubDate>Wed, 29 Nov 2006 01:28:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-6164</strong></p>
  <p>The _dl_unsetenv function in loader.c in the ELF ld.so in OpenBSD 3.9 and 4.0 does not properly remove duplicate environment variables, which allows local users to pass dangerous variables such as LD_PRELOAD to loading processes, which might be leveraged to gain privileges.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-6164">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2006-5550 – The kernel in FreeBSD 6.1 and OpenBSD 4.0 allows local users to cause a denial o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-5550</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-5550</guid>
    <pubDate>Thu, 26 Oct 2006 17:07:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2006-5550</strong></p>
  <p>The kernel in FreeBSD 6.1 and OpenBSD 4.0 allows local users to cause a denial of service via unspecified vectors involving certain ioctl requests to /dev/crypto.</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-5550">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2006-5218 – Integer overflow in the systrace_preprepl function (STRIOCREPLACE) in systrace i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-5218</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-5218</guid>
    <pubDate>Tue, 10 Oct 2006 04:06:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2006-5218</strong></p>
  <p>Integer overflow in the systrace_preprepl function (STRIOCREPLACE) in systrace in OpenBSD 3.9 and NetBSD 3 allows local users to cause a denial of service (crash), gain privileges, or read arbitrary kernel memory via large numeric arguments to the systrace ioctl.</p>
  <p><strong>CVSS:</strong> 4.6 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-5218">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2006-4435 – OpenBSD 3.8, 3.9, and possibly earlier versions allows context-dependent attacke...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-4435</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-4435</guid>
    <pubDate>Tue, 29 Aug 2006 00:04:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2006-4435</strong></p>
  <p>OpenBSD 3.8, 3.9, and possibly earlier versions allows context-dependent attackers to cause a denial of service (kernel panic) by allocating more semaphores than the default.</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-4435">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2006-4436 – isakmpd in OpenBSD 3.8, 3.9, and possibly earlier versions, creates Security Ass...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-4436</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-4436</guid>
    <pubDate>Tue, 29 Aug 2006 00:04:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2006-4436</strong></p>
  <p>isakmpd in OpenBSD 3.8, 3.9, and possibly earlier versions, creates Security Associations (SA) with a replay window of size 0 when isakmpd acts as a responder during SA negotiation, which allows remote attackers to replay IPSec packets and bypass the replay protection.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-4436">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2006-4304 – Buffer overflow in the sppp driver in FreeBSD 4.11 through 6.1, NetBSD 2.0 throu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-4304</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-4304</guid>
    <pubDate>Thu, 24 Aug 2006 01:04:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2006-4304</strong></p>
  <p>Buffer overflow in the sppp driver in FreeBSD 4.11 through 6.1, NetBSD 2.0 through 4.0 beta before 20060823, and OpenBSD 3.8 and 3.9 before 20060902 allows remote attackers to cause a denial of service (panic), obtain sensitive information, and possibly execute arbitrary code via crafted Link Control Protocol (LCP) packets with an option length that exceeds the overall length, which triggers the…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-4304">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
