Vulnerabilities > Openbsd > Openbsd > High

DATE CVE VULNERABILITY TITLE RISK
2004-02-03 CVE-2004-1082 mod_digest_apple for Apache 1.3.31 and 1.3.32 on Mac OS X Server does not properly verify the nonce of a client response, which allows remote attackers to replay credentials.
network
low complexity
apache apple avaya hp ibm openbsd sco sun
7.5
2003-10-06 CVE-2003-0681 Buffer Overflow vulnerability in Sendmail Ruleset Parsing
A "potential buffer overflow in ruleset parsing" for Sendmail 8.12.9, when using the nonstandard rulesets (1) recipient (2), final, or (3) mailer-specific envelope recipients, has unknown consequences.
network
low complexity
sendmail apple gentoo hp ibm netbsd openbsd turbolinux
7.5
2003-04-11 CVE-2002-1420 Buffer Overflow vulnerability in OpenBSD select()
Integer signedness error in select() on OpenBSD 3.1 and earlier allows local users to overwrite arbitrary kernel memory via a negative value for the size parameter, which satisfies the boundary check as a signed integer, but is later used as an unsigned integer during a data copying operation.
local
low complexity
openbsd
7.2
2003-03-31 CVE-2003-0144 Local Buffer Overflow vulnerability in Multiple Vendor LPRM
Buffer overflow in the lprm command in the lprold lpr package on SuSE 7.1 through 7.3, OpenBSD 3.2 and earlier, and possibly other operating systems, allows local users to gain root privileges via long command line arguments such as (1) request ID or (2) user name.
local
low complexity
lprold bsd freebsd openbsd
7.2
2003-03-25 CVE-2003-0028 Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via certain integer values in length fields, a different vulnerability than CVE-2002-0391.
network
low complexity
gnu mit openafs sgi cray freebsd hp ibm openbsd sun
7.5
2002-11-29 CVE-2002-1219 Buffer Overflow vulnerability in ISC BIND SIG Cached Resource Record
Buffer overflow in named in BIND 4 versions 4.9.10 and earlier, and 8 versions 8.3.3 and earlier, allows remote attackers to execute arbitrary code via a certain DNS server response containing SIG resource records (RR).
network
low complexity
isc freebsd openbsd
7.5
2002-08-12 CVE-2002-0766 Unspecified vulnerability in Openbsd 2.9/3.0/3.1
OpenBSD 2.9 through 3.1 allows local users to cause a denial of service (resource exhaustion) and gain root privileges by filling the kernel's file descriptor table and closing file descriptors 0, 1, or 2 before executing a privileged process, which is not properly handled when OpenBSD fails to open an alternate descriptor.
local
low complexity
openbsd
7.2
2002-08-12 CVE-2002-0765 Authentication Implementation Error vulnerability in Openbsd and Openssh
sshd in OpenSSH 3.2.2, when using YP with netgroups and under certain conditions, may allow users to successfully authenticate and log in with another user's password.
network
low complexity
openbsd
7.5
2002-08-12 CVE-2002-0414 KAME-derived implementations of IPsec on NetBSD 1.5.2, FreeBSD 4.5, and other operating systems, does not properly consult the Security Policy Database (SPD), which could cause a Security Gateway (SG) that does not use Encapsulating Security Payload (ESP) to forward forged IPv4 packets.
network
low complexity
freebsd netbsd openbsd
7.5
2002-08-12 CVE-2000-1208 Format string vulnerability in startprinting() function of printjob.c in BSD-based lpr lpd package may allow local users to gain privileges via an improper syslog call that uses format strings from the checkremote() call.
local
low complexity
immunix netbsd openbsd redhat
7.2