Vulnerabilities > Netbsd > Netbsd > 3.99.15

DATE CVE VULNERABILITY TITLE RISK
2009-09-18 CVE-2009-2793 Permissions, Privileges, and Access Controls vulnerability in Netbsd
The kernel in NetBSD, probably 5.0.1 and earlier, on x86 platforms does not properly handle a pre-commit failure of the iret instruction, which might allow local users to gain privileges via vectors related to a tempEIP pseudocode variable that is outside of the code-segment limits.
local
low complexity
netbsd CWE-264
4.6
2006-10-10 CVE-2006-5215 Local Security vulnerability in NetBSD
The Xsession script, as used by X Display Manager (xdm) in NetBSD before 20060212, X.Org before 20060317, and Solaris 8 through 10 before 20061006, allows local users to overwrite arbitrary files, or read another user's Xsession errors file, via a symlink attack on a /tmp/xses-$USER file.
local
high complexity
x-org netbsd sun
2.6
2006-10-10 CVE-2006-5214 Race condition in the Xsession script, as used by X Display Manager (xdm) in NetBSD before 20060212, X.Org before 20060225, and Solaris 8 through 10 before 20061006, causes a user's Xsession errors file to have weak permissions before a chmod is performed, which allows local users to read Xsession errors files of other users.
local
high complexity
netbsd sun
1.2