Vulnerabilities > Openbsd

DATE CVE VULNERABILITY TITLE RISK
2017-03-07 CVE-2016-6522 Integer Overflow or Wraparound vulnerability in Openbsd 5.9
Integer overflow in the uvm_map_isavail function in uvm/uvm_map.c in OpenBSD 5.9 allows local users to cause a denial of service (kernel panic) via a crafted mmap call, which triggers the new mapping to overlap with an existing mapping.
local
low complexity
openbsd CWE-190
4.9
2017-03-07 CVE-2016-6350 NULL Pointer Dereference vulnerability in Openbsd 5.8/5.9
OpenBSD 5.8 and 5.9 allows local users to cause a denial of service (NULL pointer dereference and panic) via a sysctl call with a path starting with 10,9.
local
low complexity
openbsd CWE-476
4.9
2017-03-07 CVE-2016-6247 Improper Input Validation vulnerability in Openbsd 5.8/5.9
OpenBSD 5.8 and 5.9 allows certain local users to cause a denial of service (kernel panic) by unmounting a filesystem with an open vnode on the mnt_vnodelist.
local
low complexity
openbsd CWE-20
4.9
2017-03-07 CVE-2016-6246 Improper Input Validation vulnerability in Openbsd 5.8/5.9
OpenBSD 5.8 and 5.9 allows certain local users with kern.usermount privileges to cause a denial of service (kernel panic) by mounting a tmpfs with a VNOVAL in the (1) username, (2) groupname, or (3) device name of the root node.
local
low complexity
openbsd CWE-20
4.9
2017-03-07 CVE-2016-6245 Memory Corruption and Denial of Service vulnerability in Openbsd 5.8/5.9
OpenBSD 5.8 and 5.9 allows local users to cause a denial of service (kernel panic) via a large size in a getdents system call.
local
low complexity
openbsd
4.9
2017-03-07 CVE-2016-6243 Improper Input Validation vulnerability in Openbsd 5.8/5.9
thrsleep in kern/kern_synch.c in OpenBSD 5.8 and 5.9 allows local users to cause a denial of service (kernel panic) via a crafted value in the tsp parameter of the __thrsleep system call.
local
low complexity
openbsd CWE-20
4.9
2017-03-07 CVE-2016-6242 Numeric Errors vulnerability in Openbsd 5.8/5.9
OpenBSD 5.8 and 5.9 allows local users to cause a denial of service (assertion failure and kernel panic) via a large ident value in a kevent system call.
local
low complexity
openbsd CWE-189
4.9
2017-03-07 CVE-2016-6241 Integer Overflow or Wraparound vulnerability in Openbsd 5.8/5.9
Integer overflow in the amap_alloc1 function in OpenBSD 5.8 and 5.9 allows local users to execute arbitrary code with kernel privileges via a large size value.
local
low complexity
openbsd CWE-190
7.2
2017-03-07 CVE-2016-6240 Numeric Errors vulnerability in Openbsd 5.8/5.9
Integer truncation error in the amap_alloc function in OpenBSD 5.8 and 5.9 allows local users to execute arbitrary code with kernel privileges via a large size value.
local
low complexity
openbsd CWE-189
7.2
2017-03-07 CVE-2016-6239 Improper Input Validation vulnerability in Openbsd 5.8/5.9
The mmap extension __MAP_NOFAULT in OpenBSD 5.8 and 5.9 allows attackers to cause a denial of service (kernel panic and crash) via a large size value.
local
low complexity
openbsd CWE-20
4.9