Vulnerabilities
Vulnerable Software
Openbsd:  >> Openbsd  >> 2.9  Security Vulnerabilities
fts routines in FreeBSD 4.3 and earlier, NetBSD before 1.5.2, and OpenBSD 2.9 and earlier can be forced to change (chdir) into a different directory than intended when the directory above the current directory is moved, which could cause scripts to perform dangerous actions on the wrong directories.
CVSS Score
6.2
EPSS Score
0.003
Published
2001-08-17
Multiple TCP implementations could allow remote attackers to cause a denial of service (bandwidth and CPU exhaustion) by setting the maximum segment size (MSS) to a very small number and requesting large amounts of data, which generates more packets with less TCP-level data that amplify network traffic and consume more server CPU to process.
CVSS Score
5.0
EPSS Score
0.353
Published
2001-07-07
Race condition in OpenBSD VFS allows local users to cause a denial of service (kernel panic) by (1) creating a pipe in one thread and causing another thread to set one of the file descriptors to NULL via a close, or (2) calling dup2 on a file descriptor in one process, then setting the descriptor to NULL via a close in another process that is created via rfork.
CVSS Score
1.2
EPSS Score
0.003
Published
2001-06-02
Format string vulnerability in OpenBSD yp_passwd program (and possibly other BSD-based operating systems) allows attackers to gain root privileges a malformed name.
CVSS Score
7.2
EPSS Score
0.006
Published
2000-12-19
Format string vulnerability in OpenBSD su program (and possibly other BSD-based operating systems) allows local attackers to gain root privileges via a malformed shell.
CVSS Score
7.2
EPSS Score
0.005
Published
2000-12-19
OpenBSD kernel crash through TSS handling, as caused by the crashme program.
CVSS Score
5.0
EPSS Score
0.01
Published
1999-03-21
OpenBSD crash using nlink value in FFS and EXT2FS filesystems.
CVSS Score
2.1
EPSS Score
0.003
Published
1999-02-25
Buffer overflow in OpenBSD ping.
CVSS Score
2.1
EPSS Score
0.003
Published
1999-02-23
rpc.mountd on Linux, Ultrix, and possibly other operating systems, allows remote attackers to determine the existence of a file on the server by attempting to mount that file, which generates different error messages depending on whether the file exists or not.
CVSS Score
5.0
EPSS Score
0.018
Published
1997-08-24


Contact Us

Shodan ® - All rights reserved