Vulnerabilities > Netbsd > Netbsd > 1.6

DATE CVE VULNERABILITY TITLE RISK
2002-11-04 CVE-2002-0666 Denial of Service vulnerability in Multiple Vendor IPSec Implementation
IPSEC implementations including (1) FreeS/WAN and (2) KAME do not properly calculate the length of authentication data, which allows remote attackers to cause a denial of service (kernel panic) via spoofed, short Encapsulating Security Payload (ESP) packets, which result in integer signedness errors.
5.0
2002-10-28 CVE-2002-1194 Buffer Overflow vulnerability in NetBSD talkd
Buffer overflow in talkd on NetBSD 1.6 and earlier, and possibly other operating systems, may allow remote attackers to execute arbitrary code via a long inbound message.
network
low complexity
netbsd
7.5
2002-10-28 CVE-2002-1192 Local Buffer Overflow vulnerability in Rogue
Multiple buffer overflows in rogue on NetBSD 1.6 and earlier, FreeBSD 4.6, and possibly other operating systems, allows local users to gain "games" group privileges via malformed entries in a game save file.
local
low complexity
rogue netbsd
4.6
2002-10-11 CVE-2002-1165 Sendmail Consortium's Restricted Shell (SMRSH) in Sendmail 8.12.6, 8.11.6-15, and possibly other versions after 8.11 from 5/19/1998, allows attackers to bypass the intended restrictions of smrsh by inserting additional commands after (1) "||" sequences or (2) "/" characters, which are not properly filtered or verified.
local
low complexity
sendmail netbsd
4.6