Vulnerabilities > Openbsd > Openbsd > 3.0

DATE CVE VULNERABILITY TITLE RISK
2002-11-29 CVE-2002-1221 Denial Of Service vulnerability in ISC BIND 8 Invalid Expiry Time
BIND 8.x through 8.3.3 allows remote attackers to cause a denial of service (crash) via SIG RR elements with invalid expiry times, which are removed from the internal BIND database and later cause a null dereference.
network
low complexity
isc freebsd openbsd
5.0
2002-11-29 CVE-2002-1220 Denial of Service vulnerability in ISC BIND OPT Record Large UDP
BIND 8.3.x through 8.3.3 allows remote attackers to cause a denial of service (termination due to assertion failure) via a request for a subdomain that does not exist, with an OPT resource record with a large UDP payload size.
network
low complexity
isc freebsd openbsd
5.0
2002-11-29 CVE-2002-1219 Buffer Overflow vulnerability in ISC BIND SIG Cached Resource Record
Buffer overflow in named in BIND 4 versions 4.9.10 and earlier, and 8 versions 8.3.3 and earlier, allows remote attackers to execute arbitrary code via a certain DNS server response containing SIG resource records (RR).
network
low complexity
isc freebsd openbsd
7.5
2002-08-12 CVE-2002-0766 Unspecified vulnerability in Openbsd 2.9/3.0/3.1
OpenBSD 2.9 through 3.1 allows local users to cause a denial of service (resource exhaustion) and gain root privileges by filling the kernel's file descriptor table and closing file descriptors 0, 1, or 2 before executing a privileged process, which is not properly handled when OpenBSD fails to open an alternate descriptor.
local
low complexity
openbsd
7.2
2002-07-03 CVE-2002-0557 Unspecified vulnerability in Openbsd 3.0
Vulnerability in OpenBSD 3.0, when using YP with netgroups in the password database, causes (1) rexec or (2) rsh to run another user's shell, or (3) atrun to change to a different user's directory, possibly due to memory allocation failures or an incorrect call to auth_approval().
network
low complexity
openbsd
7.5
2002-07-03 CVE-2002-0542 Unspecified vulnerability in Openbsd 2.9/3.0
mail in OpenBSD 2.9 and 3.0 processes a tilde (~) escape character in a message even when it is not in interactive mode, which could allow local users to gain root privileges via calls to mail in cron.
local
low complexity
openbsd
7.2
2001-12-31 CVE-2001-1559 NULL Pointer Dereference vulnerability in Openbsd 2.9/3.0
The uipc system calls (uipc_syscalls.c) in OpenBSD 2.9 and 3.0 provide user mode return instead of versus rval kernel mode values to the fdrelease function, which allows local users to cause a denial of service and trigger a null dereference.
local
low complexity
openbsd CWE-476
5.5
2001-11-13 CVE-2001-1415 Local Security vulnerability in Openbsd 2.9/3.0
vi.recover in OpenBSD before 3.1 allows local users to remove arbitrary zero-byte files such as device nodes.
local
low complexity
openbsd
4.6