Vulnerabilities > Openbsd > Openbsd > 2.6

DATE CVE VULNERABILITY TITLE RISK
2001-05-03 CVE-2001-0284 Denial-Of-Service vulnerability in OpenBSD
Buffer overflow in IPSEC authentication mechanism for OpenBSD 2.8 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a malformed Authentication header (AH) IPv4 option.
network
low complexity
openbsd
critical
10.0
2001-05-03 CVE-2001-0268 The i386_set_ldt system call in NetBSD 1.5 and earlier, and OpenBSD 2.8 and earlier, when the USER_LDT kernel option is enabled, does not validate a call gate target, which allows local users to gain root privileges by creating a segment call gate in the Local Descriptor Table (LDT) with a target that specifies an arbitrary kernel address.
local
low complexity
netbsd openbsd
7.2
2001-03-12 CVE-2000-0313 Unspecified vulnerability in Openbsd 2.6
Vulnerability in OpenBSD 2.6 allows a local user to change interface media configurations.
local
low complexity
openbsd
4.6
2001-02-12 CVE-2001-0053 One-byte buffer overflow in replydirname function in BSD-based ftpd allows remote attackers to gain root privileges.
network
low complexity
david-madore netbsd openbsd
critical
10.0
2000-12-19 CVE-2000-0997 Format string vulnerabilities in eeprom program in OpenBSD, NetBSD, and possibly other operating systems allows local attackers to gain root privileges.
local
low complexity
netbsd openbsd
7.2
2000-12-19 CVE-2000-0994 Unspecified vulnerability in Openbsd
Format string vulnerability in OpenBSD fstat program (and possibly other BSD-based operating systems) allows local users to gain root privileges via the PWD environmental variable.
local
low complexity
openbsd
7.2
2000-12-19 CVE-2000-0993 Format string vulnerability in pw_error function in BSD libutil library allows local users to gain root privileges via a malformed password in commands such as chpass or passwd.
local
low complexity
freebsd netbsd openbsd
7.2
2000-12-19 CVE-2000-0914 Unspecified vulnerability in Openbsd
OpenBSD 2.6 and earlier allows remote attackers to cause a denial of service by flooding the server with ARP requests.
network
low complexity
openbsd
5.0
2000-12-11 CVE-2000-1010 Format string vulnerability in talkd in OpenBSD and possibly other BSD-based OSes allows remote attackers to execute arbitrary commands via a user name that contains format characters.
network
low complexity
openbsd redhat
critical
10.0
2000-12-11 CVE-2000-1004 Unspecified vulnerability in Openbsd
Format string vulnerability in OpenBSD photurisd allows local users to execute arbitrary commands via a configuration file directory name that contains formatting characters.
local
low complexity
openbsd
4.6