Vulnerabilities > Netbsd > Netbsd > 5.1

DATE CVE VULNERABILITY TITLE RISK
2014-10-15 CVE-2014-3566 Cryptographic Issues vulnerability in multiple products
The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue.
3.4
2014-07-24 CVE-2014-5015 Permissions, Privileges, and Access Controls vulnerability in multiple products
bozotic HTTP server (aka bozohttpd) before 20140708, as used in NetBSD, truncates paths when checking .htpasswd restrictions, which allows remote attackers to bypass the HTTP authentication scheme and access restrictions via a long path.
network
low complexity
eterna netbsd CWE-264
5.0
2011-05-24 CVE-2011-0418 Improper Input Validation vulnerability in multiple products
The glob implementation in Pure-FTPd before 1.0.32, and in libc in NetBSD 5.1, does not properly expand expressions containing curly brackets, which allows remote authenticated users to cause a denial of service (memory consumption) via a crafted FTP STAT command.
network
low complexity
pureftpd netbsd CWE-20
4.0
2011-05-09 CVE-2011-1547 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Netbsd
Multiple stack consumption vulnerabilities in the kernel in NetBSD 4.0, 5.0 before 5.0.3, and 5.1 before 5.1.1, when IPsec is enabled, allow remote attackers to cause a denial of service (memory corruption and panic) or possibly have unspecified other impact via a crafted (1) IPv4 or (2) IPv6 packet with nested IPComp headers.
network
netbsd CWE-119
6.8
2006-10-10 CVE-2006-5215 Local Security vulnerability in NetBSD
The Xsession script, as used by X Display Manager (xdm) in NetBSD before 20060212, X.Org before 20060317, and Solaris 8 through 10 before 20061006, allows local users to overwrite arbitrary files, or read another user's Xsession errors file, via a symlink attack on a /tmp/xses-$USER file.
local
high complexity
x-org netbsd sun
2.6