Vulnerabilities > Openbsd > Medium

DATE CVE VULNERABILITY TITLE RISK
2004-11-23 CVE-2004-0257 Remote Denial Of Service vulnerability in BSD ICMPV6 Handling Routines
OpenBSD 3.4 and NetBSD 1.6 and 1.6.1 allow remote attackers to cause a denial of service (crash) by sending an IPv6 packet with a small MTU to a listening port and then issuing a TCP connect to that port.
network
low complexity
netbsd openbsd
5.0
2004-11-23 CVE-2004-0081 OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test Tool. 5.0
2004-08-31 CVE-2004-1653 Remote Security vulnerability in OpenSSH
The default configuration for OpenSSH enables AllowTcpForwarding, which could allow remote authenticated users to perform a port bounce, when configured with an anonymous access program such as AnonCVS.
network
low complexity
openbsd
6.4
2004-08-25 CVE-2004-0819 Denial-Of-Service vulnerability in OpenBSD
The bridge functionality in OpenBSD 3.4 and 3.5, when running a gateway configured as a bridging firewall with the link2 option for IPSec enabled, allows remote attackers to cause a denial of service (crash) via an ICMP echo (ping) packet.
network
low complexity
openbsd
5.0
2004-08-18 CVE-2004-0175 Path Traversal vulnerability in Openbsd Openssh
Directory traversal vulnerability in scp for OpenSSH before 3.4p1 allows remote malicious servers to overwrite arbitrary files.
network
openbsd CWE-22
4.3
2004-08-06 CVE-2004-0417 Integer overflow in the "Max-dotdot" CVS protocol command (serve_max_dotdot) for CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attackers to cause a server crash, which could cause temporary data to remain undeleted and consume disk space.
network
low complexity
cvs openpkg sgi gentoo openbsd
5.0
2004-05-04 CVE-2004-0219 Unspecified vulnerability in Openbsd
isakmpd in OpenBSD 3.4 and earlier allows remote attackers to cause a denial of service (crash) via an ISAKMP packet with a malformed IPSEC SA payload, as demonstrated by the Striker ISAKMP Protocol Test Suite.
network
low complexity
openbsd
5.0
2004-05-04 CVE-2004-0218 Denial Of Service vulnerability in OpenBSD ISAKMPD Zero Payload Length
isakmpd in OpenBSD 3.4 and earlier allows remote attackers to cause a denial of service (infinite loop) via an ISAKMP packet with a zero-length payload, as demonstrated by the Striker ISAKMP Protocol Test Suite.
network
low complexity
openbsd
5.0
2004-03-15 CVE-2004-0171 Remote Denial Of Service vulnerability in BSD Out Of Sequence Packets
FreeBSD 5.1 and earlier, and Mac OS X before 10.3.4, allows remote attackers to cause a denial of service (resource exhaustion of memory buffers and system crash) via a large number of out-of-sequence TCP packets, which prevents the operating system from creating new connections.
network
low complexity
freebsd openbsd
5.0
2004-03-03 CVE-2004-0114 Privilege Escalation vulnerability in BSD Kernel SHMAT System Call
The shmat system call in the System V Shared Memory interface for FreeBSD 5.2 and earlier, NetBSD 1.3 and earlier, and OpenBSD 2.6 and earlier, does not properly decrement a shared memory segment's reference count when the vm_map_find function fails, which could allow local users to gain read or write access to a portion of kernel memory and gain privileges.
local
low complexity
freebsd netbsd openbsd
4.6