Vulnerabilities > Netbsd > Netbsd

DATE CVE VULNERABILITY TITLE RISK
2003-03-18 CVE-2003-0102 Local Stack Overflow Code Execution vulnerability in File
Buffer overflow in tryelf() in readelf.c of the file command allows attackers to execute arbitrary code as the user running file, possibly via a large entity size value in an ELF header (elfhdr.e_shentsize).
local
low complexity
file netbsd
4.6
2003-01-17 CVE-2003-0001 Information Exposure vulnerability in multiple products
Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote attackers to obtain information from previous packets or kernel memory by using malformed packets, as demonstrated by Etherleak.
network
low complexity
freebsd linux microsoft netbsd CWE-200
5.0
2002-12-31 CVE-2002-2092 Race condition in exec in OpenBSD 4.0 and earlier, NetBSD 1.5.2 and earlier, and FreeBSD 4.4 and earlier allows local users to gain privileges by attaching a debugger to a process before the kernel has determined that the process is setuid or setgid.
local
high complexity
freebsd netbsd openbsd
3.7
2002-12-31 CVE-2002-1915 Improper Locking vulnerability in multiple products
tip on multiple BSD-based operating systems allows local users to cause a denial of service (execution prevention) by using flock() to lock the /var/log/acculog file.
local
low complexity
openbsd netbsd freebsd CWE-667
5.5
2002-11-04 CVE-2002-0666 Denial of Service vulnerability in Multiple Vendor IPSec Implementation
IPSEC implementations including (1) FreeS/WAN and (2) KAME do not properly calculate the length of authentication data, which allows remote attackers to cause a denial of service (kernel panic) via spoofed, short Encapsulating Security Payload (ESP) packets, which result in integer signedness errors.
5.0
2002-10-28 CVE-2002-1194 Buffer Overflow vulnerability in NetBSD talkd
Buffer overflow in talkd on NetBSD 1.6 and earlier, and possibly other operating systems, may allow remote attackers to execute arbitrary code via a long inbound message.
network
low complexity
netbsd
7.5
2002-10-28 CVE-2002-1192 Local Buffer Overflow vulnerability in Rogue
Multiple buffer overflows in rogue on NetBSD 1.6 and earlier, FreeBSD 4.6, and possibly other operating systems, allows local users to gain "games" group privileges via malformed entries in a game save file.
local
low complexity
rogue netbsd
4.6
2002-10-11 CVE-2002-1165 Sendmail Consortium's Restricted Shell (SMRSH) in Sendmail 8.12.6, 8.11.6-15, and possibly other versions after 8.11 from 5/19/1998, allows attackers to bypass the intended restrictions of smrsh by inserting additional commands after (1) "||" sequences or (2) "/" characters, which are not properly filtered or verified.
local
low complexity
sendmail netbsd
4.6
2002-08-12 CVE-2002-0414 KAME-derived implementations of IPsec on NetBSD 1.5.2, FreeBSD 4.5, and other operating systems, does not properly consult the Security Policy Database (SPD), which could cause a Security Gateway (SG) that does not use Encapsulating Security Payload (ESP) to forward forged IPv4 packets.
network
low complexity
freebsd netbsd openbsd
7.5
2002-08-12 CVE-2000-1208 Format string vulnerability in startprinting() function of printjob.c in BSD-based lpr lpd package may allow local users to gain privileges via an improper syslog call that uses format strings from the checkremote() call.
local
low complexity
immunix netbsd openbsd redhat
7.2