netbsd CVE Vulnerabilities & Metrics

Focus on netbsd vulnerabilities and metrics.

Last updated: 16 Apr 2025, 22:25 UTC

About netbsd Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with netbsd. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total netbsd CVEs: 16
Earliest CVE date: 21 Aug 1996, 04:00 UTC
Latest CVE date: 01 Jul 2024, 13:15 UTC

Latest CVE reference: CVE-2024-6387

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 1

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical netbsd CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 5.51

Max CVSS: 10.0

Critical CVEs (≥9): 16

CVSS Range vs. Count

Range Count
0.0-3.9 37
4.0-6.9 70
7.0-8.9 49
9.0-10.0 16

CVSS Distribution Chart

Top 5 Highest CVSS netbsd CVEs

These are the five CVEs with the highest CVSS scores for netbsd, sorted by severity first and recency.

All CVEs for netbsd

CVE-2024-6387 netbsd vulnerability CVSS: 0 01 Jul 2024, 13:15 UTC

A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.

CVE-2023-45198 netbsd vulnerability CVSS: 0 05 Oct 2023, 05:15 UTC

ftpd before "NetBSD-ftpd 20230930" can leak information about the host filesystem before authentication via an MLSD or MLST command. tnftpd (the portable version of NetBSD ftpd) before 20231001 is also vulnerable.

CVE-2021-45489 netbsd vulnerability CVSS: 5.0 25 Dec 2021, 02:15 UTC

In NetBSD through 9.2, the IPv6 Flow Label generation algorithm employs a weak cryptographic PRNG.

CVE-2021-45488 netbsd vulnerability CVSS: 5.0 25 Dec 2021, 02:15 UTC

In NetBSD through 9.2, there is an information leak in the TCP ISN (ISS) generation algorithm.

CVE-2021-45487 netbsd vulnerability CVSS: 5.0 25 Dec 2021, 02:15 UTC

In NetBSD through 9.2, the IPv4 ID generation algorithm does not use appropriate cryptographic measures.

CVE-2021-45484 netbsd vulnerability CVSS: 5.0 25 Dec 2021, 02:15 UTC

In NetBSD through 9.2, the IPv6 fragment ID generation algorithm employs a weak cryptographic PRNG.

CVE-2020-26139 netbsd vulnerability CVSS: 2.9 11 May 2021, 20:15 UTC

An issue was discovered in the kernel in NetBSD 7.1. An Access Point (AP) forwards EAPOL frames to other clients even though the sender has not yet successfully authenticated to the AP. This might be abused in projected Wi-Fi networks to launch denial-of-service attacks against connected clients and makes it easier to exploit other vulnerabilities in connected clients.

CVE-2012-5365 netbsd vulnerability CVSS: 7.8 20 Feb 2020, 15:15 UTC

The IPv6 implementation in FreeBSD and NetBSD (unknown versions, year 2012 and earlier) allows remote attackers to cause a denial of service via a flood of ICMPv6 Router Advertisement packets containing multiple Routing entries.

CVE-2012-5363 netbsd vulnerability CVSS: 7.8 20 Feb 2020, 15:15 UTC

The IPv6 implementation in FreeBSD and NetBSD (unknown versions, year 2012 and earlier) allows remote attackers to cause a denial of service via a flood of ICMPv6 Neighbor Solicitation messages, a different vulnerability than CVE-2011-2393.

CVE-2011-2480 netbsd vulnerability CVSS: 5.0 27 Nov 2019, 19:15 UTC

Information Disclosure vulnerability in the 802.11 stack, as used in FreeBSD before 8.2 and NetBSD when using certain non-x86 architectures. A signedness error in the IEEE80211_IOC_CHANINFO ioctl allows a local unprivileged user to cause the kernel to copy large amounts of kernel memory back to the user, disclosing potentially sensitive information.

CVE-2017-1000378 netbsd vulnerability CVSS: 7.5 19 Jun 2017, 16:29 UTC

The NetBSD qsort() function is recursive, and not randomized, an attacker can construct a pathological input array of N elements that causes qsort() to deterministically recurse N/4 times. This allows attackers to consume arbitrary amounts of stack memory and manipulate stack memory to assist in arbitrary code execution attacks. This affects NetBSD 7.1 and possibly earlier versions.

CVE-2017-1000375 netbsd vulnerability CVSS: 7.5 19 Jun 2017, 16:29 UTC

NetBSD maps the run-time link-editor ld.so directly below the stack region, even if ASLR is enabled, this allows attackers to more easily manipulate memory leading to arbitrary code execution. This affects NetBSD 7.1 and possibly earlier versions.

CVE-2017-1000374 netbsd vulnerability CVSS: 7.5 19 Jun 2017, 16:29 UTC

A flaw exists in NetBSD's implementation of the stack guard page that allows attackers to bypass it resulting in arbitrary code execution using certain setuid binaries. This affects NetBSD 7.1 and possibly earlier versions.

CVE-2016-6253 netbsd vulnerability CVSS: 7.2 20 Jan 2017, 15:59 UTC

mail.local in NetBSD versions 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows local users to change ownership of or append data to arbitrary files on the target system via a symlink attack on the user mailbox.

CVE-2015-8212 netbsd vulnerability CVSS: 7.5 19 Jan 2017, 20:59 UTC

CGI handling flaw in bozohttpd in NetBSD 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows remote attackers to execute arbitrary code via crafted arguments, which are handled by a non-CGI aware program.

CVE-2015-5917 netbsd vulnerability CVSS: 5.0 09 Oct 2015, 05:59 UTC

The glob implementation in tnftpd (formerly lukemftpd), as used in Apple OS X before 10.11, allows remote attackers to cause a denial of service (memory consumption and daemon outage) via a STAT command containing a crafted pattern, as demonstrated by multiple instances of the {..,..,..}/* substring.

CVE-2014-7250 netbsd vulnerability CVSS: 5.0 12 Dec 2014, 03:03 UTC

The TCP stack in 4.3BSD Net/2, as used in FreeBSD 5.4, NetBSD possibly 2.0, and OpenBSD possibly 3.6, does not properly implement the session timer, which allows remote attackers to cause a denial of service (resource consumption) via crafted packets.

CVE-2014-8517 netbsd vulnerability CVSS: 7.5 17 Nov 2014, 16:59 UTC

The fetch_url function in usr.bin/ftp/fetch.c in tnftp, as used in NetBSD 5.1 through 5.1.4, 5.2 through 5.2.2, 6.0 through 6.0.6, and 6.1 through 6.1.5 allows remote attackers to execute arbitrary commands via a | (pipe) character at the end of an HTTP redirect.

CVE-2014-3566 netbsd vulnerability CVSS: 4.3 15 Oct 2014, 00:55 UTC

The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue.

CVE-2014-5384 netbsd vulnerability CVSS: 5.0 21 Aug 2014, 22:55 UTC

The VIQR module in the iconv implementation in FreeBSD 10.0 before p6 and NetBSD allows context-dependent attackers to cause a denial of service (out-of-bounds array access) via a crafted argument to the iconv_open function. NOTE: this issue was SPLIT from CVE-2014-3951 per ADT2 due to different vulnerability types.

CVE-2014-3951 netbsd vulnerability CVSS: 5.0 21 Aug 2014, 22:55 UTC

The HZ module in the iconv implementation in FreeBSD 10.0 before p6 and NetBSD allows context-dependent attackers to cause a denial of service (NULL pointer dereference) via a crafted argument to the iconv_open function. NOTE: this issue was SPLIT per ADT2 due to different vulnerability types. CVE-2014-5384 is used for the NULL pointer dereference.

CVE-2014-5015 netbsd vulnerability CVSS: 5.0 24 Jul 2014, 14:55 UTC

bozotic HTTP server (aka bozohttpd) before 20140708, as used in NetBSD, truncates paths when checking .htpasswd restrictions, which allows remote attackers to bypass the HTTP authentication scheme and access restrictions via a long path.

CVE-2007-6754 netbsd vulnerability CVSS: 5.0 25 Jul 2012, 19:55 UTC

The ipalloc function in libc/stdlib/malloc.c in jemalloc in libc for FreeBSD 6.4 and NetBSD does not properly allocate memory, which makes it easier for context-dependent attackers to perform memory-related attacks such as buffer overflows via a large size value, related to "integer rounding and overflow" errors.

CVE-2006-7252 netbsd vulnerability CVSS: 5.0 25 Jul 2012, 19:55 UTC

Integer overflow in the calloc function in libc/stdlib/malloc.c in jemalloc in libc for FreeBSD 6.4 and NetBSD makes it easier for context-dependent attackers to perform memory-related attacks such as buffer overflows via a large size value, which triggers a memory allocation of one byte.

CVE-2012-0217 netbsd vulnerability CVSS: 7.2 12 Jun 2012, 22:55 UTC

The x86-64 kernel system-call functionality in Xen 4.1.2 and earlier, as used in Citrix XenServer 6.0.2 and earlier and other products; Oracle Solaris 11 and earlier; illumos before r13724; Joyent SmartOS before 20120614T184600Z; FreeBSD before 9.0-RELEASE-p3; NetBSD 6.0 Beta and earlier; Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1; and possibly other operating systems, when running on an Intel processor, incorrectly uses the sysret path in cases where a certain address is not a canonical address, which allows local users to gain privileges via a crafted application. NOTE: because this issue is due to incorrect use of the Intel specification, it should have been split into separate identifiers; however, there was some value in preserving the original mapping of the multi-codebase coordinated-disclosure effort to a single identifier.

CVE-2011-2393 netbsd vulnerability CVSS: 7.8 02 Feb 2012, 17:55 UTC

The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in FreeBSD, NetBSD, and possibly other BSD-based operating systems allows remote attackers to cause a denial of service (CPU consumption and device hang) by sending many Router Advertisement (RA) messages with different source addresses, a similar vulnerability to CVE-2010-4670.

CVE-2011-2895 netbsd vulnerability CVSS: 9.3 19 Aug 2011, 17:55 UTC

The LZW decompressor in (1) the BufCompressedFill function in fontfile/decompress.c in X.Org libXfont before 1.4.4 and (2) compress/compress.c in 4.3BSD, as used in zopen.c in OpenBSD before 3.8, FreeBSD, NetBSD 4.0.x and 5.0.x before 5.0.3 and 5.1.x before 5.1.1, FreeType 2.1.9, and other products, does not properly handle code words that are absent from the decompression table when encountered, which allows context-dependent attackers to trigger an infinite loop or a heap-based buffer overflow, and possibly execute arbitrary code, via a crafted compressed stream, a related issue to CVE-2006-1168 and CVE-2011-2896.

CVE-2011-0418 netbsd vulnerability CVSS: 4.0 24 May 2011, 23:55 UTC

The glob implementation in Pure-FTPd before 1.0.32, and in libc in NetBSD 5.1, does not properly expand expressions containing curly brackets, which allows remote authenticated users to cause a denial of service (memory consumption) via a crafted FTP STAT command.

CVE-2011-1920 netbsd vulnerability CVSS: 3.3 23 May 2011, 22:55 UTC

The make include files in NetBSD before 1.6.2, as used in pmake 1.111 and other products, allow local users to overwrite arbitrary files via a symlink attack on a /tmp/_depend##### temporary file, related to (1) bsd.lib.mk and (2) bsd.prog.mk.

CVE-2011-0419 netbsd vulnerability CVSS: 4.3 16 May 2011, 17:55 UTC

Stack consumption vulnerability in the fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library before 1.4.3 and the Apache HTTP Server before 2.2.18, and in fnmatch.c in libc in NetBSD 5.1, OpenBSD 4.8, FreeBSD, Apple Mac OS X 10.6, Oracle Solaris 10, and Android, allows context-dependent attackers to cause a denial of service (CPU and memory consumption) via *? sequences in the first argument, as demonstrated by attacks against mod_autoindex in httpd.

CVE-2011-1547 netbsd vulnerability CVSS: 6.8 09 May 2011, 19:55 UTC

Multiple stack consumption vulnerabilities in the kernel in NetBSD 4.0, 5.0 before 5.0.3, and 5.1 before 5.1.1, when IPsec is enabled, allow remote attackers to cause a denial of service (memory corruption and panic) or possibly have unspecified other impact via a crafted (1) IPv4 or (2) IPv6 packet with nested IPComp headers.

CVE-2010-4755 netbsd vulnerability CVSS: 4.0 02 Mar 2011, 20:00 UTC

The (1) remote_glob function in sftp-glob.c and the (2) process_put function in sftp.c in OpenSSH 5.8 and earlier, as used in FreeBSD 7.3 and 8.1, NetBSD 5.0.2, OpenBSD 4.7, and other products, allow remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in SSH_FXP_STAT requests to an sftp daemon, a different vulnerability than CVE-2010-2632.

CVE-2010-4754 netbsd vulnerability CVSS: 4.0 02 Mar 2011, 20:00 UTC

The glob implementation in libc in FreeBSD 7.3 and 8.1, NetBSD 5.0.2, and OpenBSD 4.7, and Libsystem in Apple Mac OS X before 10.6.8, allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632.

CVE-2010-2530 netbsd vulnerability CVSS: 4.9 29 Sep 2010, 17:00 UTC

Multiple integer signedness errors in smb_subr.c in the netsmb module in the kernel in NetBSD 5.0.2 and earlier, FreeBSD, and Apple Mac OS X allow local users to cause a denial of service (panic) via a negative size value in a /dev/nsmb ioctl operation, as demonstrated by a (1) SMBIOC_LOOKUP or (2) SMBIOC_OPENSESSION ioctl call.

CVE-2010-3014 netbsd vulnerability CVSS: 1.2 20 Aug 2010, 20:00 UTC

The Coda filesystem kernel module, as used in NetBSD and FreeBSD, when Coda is loaded and Venus is running with /coda mounted, allows local users to read sensitive heap memory via a large out_size value in a ViceIoctl struct to a Coda ioctl, which triggers a buffer over-read.

CVE-2010-0561 netbsd vulnerability CVSS: 4.9 08 Feb 2010, 21:30 UTC

Integer signedness error in NetBSD 4.0, 5.0, and NetBSD-current before 2010-01-21 allows local users to cause a denial of service (kernel panic) via a negative mixer index number being passed to (1) the azalia_query_devinfo function in the azalia audio driver (src/sys/dev/pci/azalia.c) or (2) the hdaudio_afg_query_devinfo function in the hdaudio audio driver (src/sys/dev/pci/hdaudio/hdaudio_afg.c).

CVE-2009-2793 netbsd vulnerability CVSS: 4.6 18 Sep 2009, 22:30 UTC

The kernel in NetBSD, probably 5.0.1 and earlier, on x86 platforms does not properly handle a pre-commit failure of the iret instruction, which might allow local users to gain privileges via vectors related to a tempEIP pseudocode variable that is outside of the code-segment limits.

CVE-2009-0687 netbsd vulnerability CVSS: 7.8 11 Aug 2009, 10:30 UTC

The pf_test_rule function in OpenBSD Packet Filter (PF), as used in OpenBSD 4.2 through 4.5, NetBSD 5.0 before RC3, MirOS 10 and earlier, and MidnightBSD 0.3-current allows remote attackers to cause a denial of service (panic) via crafted IP packets that trigger a NULL pointer dereference during translation, related to an IPv4 packet with an ICMPv6 payload.

CVE-2009-2483 netbsd vulnerability CVSS: 4.9 16 Jul 2009, 16:30 UTC

libprop/prop_object.c in proplib in NetBSD 4.0 and 4.0.1 allows local users to cause a denial of service (NULL pointer dereference and kernel panic) via a malformed externalized plist (XML form) containing an undefined element.

CVE-2009-2482 netbsd vulnerability CVSS: 6.9 16 Jul 2009, 16:30 UTC

The pam_unix module in OpenPAM in NetBSD 4.0 before 4.0.2 and 5.0 before 5.0.1 allows local users to change the current root password if it is already known, even when they are not in the wheel group.

CVE-2009-0689 netbsd vulnerability CVSS: 6.8 01 Jul 2009, 13:00 UTC

Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the (2) gdtoa (aka new dtoa) implementation in gdtoa/misc.c in libc, as used in multiple operating systems and products including in FreeBSD 6.4 and 7.2, NetBSD 5.0, OpenBSD 4.5, Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4, K-Meleon 1.5.3, SeaMonkey 1.1.8, and other products, allows context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a large precision value in the format argument to a printf function, which triggers incorrect memory allocation and a heap-based buffer overflow during conversion to a floating-point number.

CVE-2008-4609 netbsd vulnerability CVSS: 7.1 20 Oct 2008, 17:59 UTC

The TCP implementation in (1) Linux, (2) platforms based on BSD Unix, (3) Microsoft Windows, (4) Cisco products, and probably other operating systems allows remote attackers to cause a denial of service (connection queue exhaustion) via multiple vectors that manipulate information in the TCP state table, as demonstrated by sockstress.

CVE-2008-2476 netbsd vulnerability CVSS: 9.3 03 Oct 2008, 15:07 UTC

The IPv6 Neighbor Discovery Protocol (NDP) implementation in (1) FreeBSD 6.3 through 7.1, (2) OpenBSD 4.2 and 4.3, (3) NetBSD, (4) Force10 FTOS before E7.7.1.1, (5) Juniper JUNOS, and (6) Wind River VxWorks 5.x through 6.4 does not validate the origin of Neighbor Discovery messages, which allows remote attackers to cause a denial of service (loss of connectivity) or read private network traffic via a spoofed message that modifies the Forward Information Base (FIB).

CVE-2008-4247 netbsd vulnerability CVSS: 7.5 25 Sep 2008, 19:25 UTC

ftpd in OpenBSD 4.3, FreeBSD 7.0, NetBSD 4.0, Solaris, and possibly other operating systems interprets long commands from an FTP client as multiple commands, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and execute arbitrary FTP commands via a long ftp:// URI that leverages an existing session from the FTP client implementation in a web browser.

CVE-2008-3584 netbsd vulnerability CVSS: 9.3 11 Sep 2008, 21:06 UTC

NetBSD 3.0, 3.1, and 4.0, when a pppoe instance exists, does not properly check the length of a PPPoE packet tag, which allows remote attackers to cause a denial of service (system crash) via a crafted PPPoE packet.

CVE-2008-2464 netbsd vulnerability CVSS: 7.1 11 Sep 2008, 01:10 UTC

The mld_input function in sys/netinet6/mld6.c in the kernel in NetBSD 4.0, FreeBSD, and KAME, when INET6 is enabled, allows remote attackers to cause a denial of service (divide-by-zero error and panic) via a malformed ICMPv6 Multicast Listener Discovery (MLD) query with a certain Maximum Response Delay value.

CVE-2008-1391 netbsd vulnerability CVSS: 7.5 27 Mar 2008, 17:44 UTC

Multiple integer overflows in libc in NetBSD 4.x, FreeBSD 6.x and 7.x, and probably other BSD and Apple Mac OS platforms allow context-dependent attackers to execute arbitrary code via large values of certain integer fields in the format argument to (1) the strfmon function in lib/libc/stdlib/strfmon.c, related to the GET_NUMBER macro; and (2) the printf function, related to left_prec and right_prec.

CVE-2008-1335 netbsd vulnerability CVSS: 9.3 13 Mar 2008, 18:44 UTC

The ipsec4_get_ulp function in the kernel in NetBSD 2.0 through 3.1 and NetBSD-current before 20071028, when the fast_ipsec subsystem is enabled, allows remote attackers to bypass the IPsec policy by sending packets from a source machine with a different endianness than the destination machine, a different vulnerability than CVE-2006-0905.

CVE-2008-1215 netbsd vulnerability CVSS: 4.6 09 Mar 2008, 02:44 UTC

Stack-based buffer overflow in the command_Expand_Interpret function in command.c in ppp (aka user-ppp), as distributed in FreeBSD 6.3 and 7.0, OpenBSD 4.1 and 4.2, and the net/userppp package for NetBSD, allows local users to gain privileges via long commands containing "~" characters.

CVE-2007-3654 netbsd vulnerability CVSS: 2.1 17 Sep 2007, 17:17 UTC

The display driver allocattr functions in NetBSD 3.0 through 4.0_BETA2, and NetBSD-current before 20070728, allow local users to cause a denial of service (panic) via a (1) negative or (2) large value in an ioctl call, as demonstrated by the vga_allocattr function.

CVE-2007-1677 netbsd vulnerability CVSS: 6.6 30 Mar 2007, 00:19 UTC

Multiple buffer overflows in the ISO network protocol support in the NetBSD kernel 2.0 through 4.0_BETA2, and NetBSD-current before 20070329, allow local users to execute arbitrary code via long parameters to certain functions, as demonstrated by a long sockaddr structure argument to the clnp_route function.

CVE-2007-1523 netbsd vulnerability CVSS: 7.5 20 Mar 2007, 20:19 UTC

Heap-based buffer overflow in the kernel in NetBSD 3.0, certain versions of FreeBSD and OpenBSD, and possibly other BSD derived operating systems allows local users to have an unknown impact. NOTE: this information is based upon a vague pre-advisory with no actionable information. Details will be updated after 20070329.

CVE-2006-6730 netbsd vulnerability CVSS: 6.6 26 Dec 2006, 23:28 UTC

OpenBSD and NetBSD permit usermode code to kill the display server and write to the X.Org /dev/xf86 device, which allows local users with root privileges to reduce securelevel by replacing the System Management Mode (SMM) handler via a write to an SMRAM address within /dev/xf86 (aka the video card memory-mapped I/O range), and then launching the new handler via a System Management Interrupt (SMI), as demonstrated by a write to Programmed I/O port 0xB2.

CVE-2006-6652 netbsd vulnerability CVSS: 9.0 20 Dec 2006, 02:28 UTC

Buffer overflow in the glob implementation (glob.c) in libc in NetBSD-current before 20050914, NetBSD 2.* and 3.* before 20061203, and Apple Mac OS X before 2007-004, as used by the FTP daemon and tnftpd, allows remote authenticated users to execute arbitrary code via a long pathname that results from path expansion.

CVE-2006-6654 netbsd vulnerability CVSS: 4.3 20 Dec 2006, 02:28 UTC

The sendmsg function in NetBSD-current before 20061023, NetBSD 3.0 and 3.0.1 before 20061024, and NetBSD 2.x before 20061029, when run on a 64-bit architecture, allows attackers to cause a denial of service (kernel panic) via an invalid msg_controllen parameter to the sendit function.

CVE-2006-6656 netbsd vulnerability CVSS: 2.1 20 Dec 2006, 02:28 UTC

Unspecified vulnerability in ptrace in NetBSD-current before 20061027, NetBSD 3.0 and 3.0.1 before 20061027, and NetBSD 2.x before 20061119 allows local users to read kernel memory and obtain sensitive information via certain manipulations of a PT_LWPINFO request, which leads to a memory leak and information leak.

CVE-2006-6657 netbsd vulnerability CVSS: 2.1 20 Dec 2006, 02:28 UTC

The if_clone_list function in NetBSD-current before 20061027, NetBSD 3.0 and 3.0.1 before 20061027, and NetBSD 2.x before 20061119 allows local users to read potentially sensitive, uninitialized stack memory via unspecified vectors.

CVE-2006-6653 netbsd vulnerability CVSS: 1.7 20 Dec 2006, 02:28 UTC

The accept function in NetBSD-current before 20061023, NetBSD 3.0 and 3.0.1 before 20061024, and NetBSD 2.x before 20061029 allows local users to cause a denial of service (socket consumption) via an invalid (1) name or (2) namelen parameter, which may result in the socket never being closed (aka "a dangling socket").

CVE-2006-6655 netbsd vulnerability CVSS: 1.7 20 Dec 2006, 02:28 UTC

The procfs implementation in NetBSD-current before 20061023, NetBSD 3.0 and 3.0.1 before 20061024, and NetBSD 2.x before 20061029 allows local users to cause a denial of service (kernel panic) by attempting to access /emul/linux/proc/0/stat on a procfs filesystem that was mounted with mount_procfs -o linux, which results in a NULL pointer dereference.

CVE-2006-6397 netbsd vulnerability CVSS: 4.4 08 Dec 2006, 01:28 UTC

Integer overflow in banner/banner.c in FreeBSD, NetBSD, and OpenBSD might allow local users to modify memory via a long banner. NOTE: CVE and multiple third parties dispute this issue. Since banner is not setuid, an exploit would not cross privilege boundaries in normal operations. This issue is not a vulnerability

CVE-2006-6165 netbsd vulnerability CVSS: 7.2 29 Nov 2006, 01:28 UTC

ld.so in FreeBSD, NetBSD, and possibly other BSD distributions does not remove certain harmful environment variables, which allows local users to gain privileges by passing certain environment variables to loading processes. NOTE: this issue has been disputed by a third party, stating that it is the responsibility of the application to properly sanitize the environment

CVE-2006-6014 netbsd vulnerability CVSS: 7.2 21 Nov 2006, 23:07 UTC

The NetBSD-current kernel before 20061028 does not properly perform bounds checking of an unspecified userspace parameter in the ptrace system call during a PT_DUMPCORE request, which allows local users to have an unknown impact.

CVE-2006-6013 netbsd vulnerability CVSS: 2.1 21 Nov 2006, 23:07 UTC

Integer signedness error in the fw_ioctl (FW_IOCTL) function in the FireWire (IEEE-1394) drivers (dev/firewire/fwdev.c) in various BSD kernels, including DragonFlyBSD, FreeBSD 5.5, MidnightBSD 0.1-CURRENT before 20061115, NetBSD-current before 20061116, NetBSD-4 before 20061203, and TrustedBSD, allows local users to read arbitrary memory contents via certain negative values of crom_buf->len in an FW_GCROM command. NOTE: this issue has been labeled as an integer overflow, but it is more like an integer signedness error.

CVE-2006-5218 netbsd vulnerability CVSS: 4.6 10 Oct 2006, 04:06 UTC

Integer overflow in the systrace_preprepl function (STRIOCREPLACE) in systrace in OpenBSD 3.9 and NetBSD 3 allows local users to cause a denial of service (crash), gain privileges, or read arbitrary kernel memory via large numeric arguments to the systrace ioctl.

CVE-2006-5215 netbsd vulnerability CVSS: 2.6 10 Oct 2006, 04:06 UTC

The Xsession script, as used by X Display Manager (xdm) in NetBSD before 20060212, X.Org before 20060317, and Solaris 8 through 10 before 20061006, allows local users to overwrite arbitrary files, or read another user's Xsession errors file, via a symlink attack on a /tmp/xses-$USER file.

CVE-2006-5214 netbsd vulnerability CVSS: 1.2 10 Oct 2006, 04:06 UTC

Race condition in the Xsession script, as used by X Display Manager (xdm) in NetBSD before 20060212, X.Org before 20060225, and Solaris 8 through 10 before 20061006, causes a user's Xsession errors file to have weak permissions before a chmod is performed, which allows local users to read Xsession errors files of other users.

CVE-2006-4304 netbsd vulnerability CVSS: 10.0 24 Aug 2006, 01:04 UTC

Buffer overflow in the sppp driver in FreeBSD 4.11 through 6.1, NetBSD 2.0 through 4.0 beta before 20060823, and OpenBSD 3.8 and 3.9 before 20060902 allows remote attackers to cause a denial of service (panic), obtain sensitive information, and possibly execute arbitrary code via crafted Link Control Protocol (LCP) packets with an option length that exceeds the overall length, which triggers the overflow in (1) pppoe and (2) ippp. NOTE: this issue was originally incorrectly reported for the ppp driver.

CVE-2006-3202 netbsd vulnerability CVSS: 4.9 23 Jun 2006, 20:06 UTC

The ip6_savecontrol function in NetBSD 2.0 through 3.0, under certain configurations, does not check to see if IPv4-mapped sockets are being used before processing IPv6 socket options, which allows local users to cause a denial of service (crash) by creating an IPv4-mapped IPv6 socket with the SO_TIMESTAMP socket option set, then sending an IPv4 packet through the socket.

CVE-2006-2205 netbsd vulnerability CVSS: 2.1 05 May 2006, 12:46 UTC

The audio_write function in NetBSD 3.0 allows local users to cause a denial of service (kernel crash) by using the audiosetinfo ioctl to change the sample rate of an audio device.

CVE-2006-1833 netbsd vulnerability CVSS: 2.6 19 Apr 2006, 16:06 UTC

Intel RNG Driver in NetBSD 1.6 through 3.0 may incorrectly detect the presence of the pchb interface, which will cause it to always generate the same random number, which allows remote attackers to more easily crack encryption keys generated from the interface.

CVE-2006-1797 netbsd vulnerability CVSS: 4.9 18 Apr 2006, 10:02 UTC

The kernel in NetBSD-current before September 28, 2005 allows local users to cause a denial of service (system crash) by using the SIOCGIFALIAS ioctl to gather information on a non-existent alias of a network interface, which causes a NULL pointer dereference.

CVE-2006-1814 netbsd vulnerability CVSS: 2.1 18 Apr 2006, 10:02 UTC

NetBSD 1.6, 2.0, 2.1 and 3.0 allows local users to cause a denial of service (memory exhaustion) by using the sysctl system call to lock a large buffer into physical memory.

CVE-2006-1589 netbsd vulnerability CVSS: 4.9 03 Apr 2006, 10:04 UTC

The elf_load_file function in NetBSD 2.0 through 3.0 allows local users to cause a denial of service (kernel crash) via an ELF interpreter that does not have a PT_LOAD section in its header, which triggers a null dereference.

CVE-2006-1587 netbsd vulnerability CVSS: 2.1 03 Apr 2006, 10:04 UTC

NetBSD 1.6 up to 3.0, when a user has "set record" in .mailrc with the default umask set, creates the record file with 0644 permissions, which allows local users to read the record file.

CVE-2006-1588 netbsd vulnerability CVSS: 2.1 03 Apr 2006, 10:04 UTC

The bridge ioctl (if_bridge code) in NetBSD 1.6 through 3.0 does not clear sensitive memory before copying ioctl results to the requesting process, which allows local users to obtain portions of kernel memory.

CVE-2006-0905 netbsd vulnerability CVSS: 7.5 23 Mar 2006, 11:06 UTC

A "programming error" in fast_ipsec in FreeBSD 4.8-RELEASE through 6.1-STABLE and NetBSD 2 through 3 does not properly update the sequence number associated with a Security Association, which allows packets to pass sequence number checks and allows remote attackers to capture IPSec packets and conduct replay attacks.

CVE-2006-0145 netbsd vulnerability CVSS: 4.6 09 Jan 2006, 23:03 UTC

The kernfs_xread function in kernfs in NetBSD 1.6 through 2.1, and OpenBSD 3.8, does not properly validate file offsets against negative 32-bit values that occur as a result of truncation, which allows local users to read arbitrary kernel memory and gain privileges via the lseek system call.

CVE-2005-4741 netbsd vulnerability CVSS: 7.5 31 Dec 2005, 05:00 UTC

NetBSD 1.6, NetBSD 2.0 through 2.1, and NetBSD-current before 20051031 allows local users to gain privileges by attaching a debugger to a setuid/setgid (P_SUGID) process that performs an exec without a reset of real credentials.

CVE-2005-4776 netbsd vulnerability CVSS: 7.2 31 Dec 2005, 05:00 UTC

Integer overflow in the FreeBSD compatibility code (freebsd_misc.c) in NetBSD-current, NetBSD-3, NetBSD-2.0, and NetBSD-2 before 20050913; and NetBSD-1.6 before 20050914; allows local users to cause a denial of service (heap corruption or system crash) and possibly gain root privileges.

CVE-2005-4733 netbsd vulnerability CVSS: 4.9 31 Dec 2005, 05:00 UTC

NetBSD 2.0 before 20050316 and NetBSD-current before 20050112 allow local users to cause a denial of service (infinite loop and system hang) by calling the F_CLOSEM fcntl with a parameter value of 0.

CVE-2005-4782 netbsd vulnerability CVSS: 4.9 31 Dec 2005, 05:00 UTC

NetBSD 2.0 before 2.0.4, 2.1 before 2.1.1, and 3, when the kernel is compiled with "options DIAGNOSTIC," allows local users to cause a denial of service (kernel assertion panic) via a negative linger time in the SO_LINGER socket option.

CVE-2005-4779 netbsd vulnerability CVSS: 3.6 31 Dec 2005, 05:00 UTC

verifiedexecioctl in verified_exec.c in NetBSD 2.0.2 calls NDINIT with UIO_USERSPACE rather than UID_SYSSPACE, which removes the functionality of the verified exec kernel subsystem and might allow local users to execute Trojan horse programs.

CVE-2005-4352 netbsd vulnerability CVSS: 2.1 31 Dec 2005, 05:00 UTC

The securelevels implementation in NetBSD 2.1 and earlier, and Linux 2.6.15 and earlier, allows local users to bypass time setting restrictions and set the clock backwards by setting the clock ahead to the maximum unixtime value (19 Jan 2038), which then wraps around to the minimum value (13 Dec 1901), which can then be set ahead to the desired time, aka "settimeofday() time wrap."

CVE-2005-4691 netbsd vulnerability CVSS: 2.1 31 Dec 2005, 05:00 UTC

imake in NetBSD before 2.0.3, NetBSD-current before 12 September 2005, certain versions of X.Org, and certain versions of XFree86 allows local users to overwrite arbitrary files via a symlink attack on the temporary file for the file.0 target, which is used for a pre-formatted manual page.

CVE-2005-4783 netbsd vulnerability CVSS: 2.1 31 Dec 2005, 05:00 UTC

kernfs_xread in kernfs_vnops.c in NetBSD before 20050831 does not check for a negative offset when reading the message buffer, which allows local users to read arbitrary kernel memory.

CVE-2005-2134 netbsd vulnerability CVSS: 2.1 05 Jul 2005, 04:00 UTC

The (1) clcs and (2) emuxki drivers in NetBSD 1.6 through 2.0.2 allow local users to cause a denial of service (kernel crash) by using the set-parameters ioctl on an audio device to change the block size and set the pause state to "unpaused" in the same ioctl, which causes a divide-by-zero error.

CVE-2004-2012 netbsd vulnerability CVSS: 7.2 31 Dec 2004, 05:00 UTC

The systrace_exit function in the systrace utility for NetBSD-current and 2.0 before April 16, 2004, and certain FreeBSD ports, does not verify the owner of the /dec/systrace connection before setting euid to 0, which allows local users to gain root privileges.

CVE-2004-1374 netbsd vulnerability CVSS: 7.2 18 Dec 2004, 05:00 UTC

Multiple buffer overflows in NetBSD kernel may allow local users to execute arbitrary code and gain privileges.

CVE-2004-1323 netbsd vulnerability CVSS: 2.1 16 Dec 2004, 05:00 UTC

Multiple syscalls in the compat subsystem for NetBSD before 2.0 allow local users to cause a denial of service (kernel crash) via a large signal number to (1) xxx_sys_kill, (2) xxx_sys_sigaction, and possibly other translation functions.

CVE-2004-0257 netbsd vulnerability CVSS: 5.0 23 Nov 2004, 05:00 UTC

OpenBSD 3.4 and NetBSD 1.6 and 1.6.1 allow remote attackers to cause a denial of service (crash) by sending an IPv6 packet with a small MTU to a listening port and then issuing a TCP connect to that port.

CVE-2004-0230 netbsd vulnerability CVSS: 5.0 18 Aug 2004, 04:00 UTC

TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to persistent TCP connections by repeatedly injecting a TCP RST packet, especially in protocols that use long-lived connections, such as BGP.

CVE-2004-0114 netbsd vulnerability CVSS: 4.6 03 Mar 2004, 05:00 UTC

The shmat system call in the System V Shared Memory interface for FreeBSD 5.2 and earlier, NetBSD 1.3 and earlier, and OpenBSD 2.6 and earlier, does not properly decrement a shared memory segment's reference count when the vm_map_find function fails, which could allow local users to gain read or write access to a portion of kernel memory and gain privileges.

CVE-2003-0914 netbsd vulnerability CVSS: 4.3 15 Dec 2003, 05:00 UTC

ISC BIND 8.3.x before 8.3.7, and 8.4.x before 8.4.3, allows remote attackers to poison the cache via a malicious name server that returns negative responses with a large TTL (time-to-live) value.

CVE-2003-0730 netbsd vulnerability CVSS: 7.5 20 Oct 2003, 04:00 UTC

Multiple integer overflows in the font libraries for XFree86 4.3.0 allow local or remote attackers to cause a denial of service or execute arbitrary code via heap-based and stack-based buffer overflow attacks.

CVE-2003-0694 netbsd vulnerability CVSS: 10.0 06 Oct 2003, 04:00 UTC

The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c.

CVE-2003-0681 netbsd vulnerability CVSS: 7.5 06 Oct 2003, 04:00 UTC

A "potential buffer overflow in ruleset parsing" for Sendmail 8.12.9, when using the nonstandard rulesets (1) recipient (2), final, or (3) mailer-specific envelope recipients, has unknown consequences.

CVE-2003-0466 netbsd vulnerability CVSS: 10.0 27 Aug 2003, 04:00 UTC

Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code, as demonstrated in wu-ftpd 2.5.0 through 2.6.2 via commands that cause pathnames of length MAXPATHLEN+1 to trigger a buffer overflow, including (1) STOR, (2) RETR, (3) APPE, (4) DELE, (5) MKD, (6) RMD, (7) STOU, or (8) RNTO.

CVE-2003-0653 netbsd vulnerability CVSS: 5.0 27 Aug 2003, 04:00 UTC

The OSI networking kernel (sys/netiso) in NetBSD 1.6.1 and earlier does not use a BSD-required "PKTHDR" mbuf when sending certain error responses to the sender of an OSI packet, which allows remote attackers to cause a denial of service (kernel panic or crash) via certain OSI packets.

CVE-2002-1476 netbsd vulnerability CVSS: 4.6 22 Apr 2003, 04:00 UTC

Buffer overflow in setlocale in libc on NetBSD 1.4.x through 1.6, and possibly other operating systems, when called with the LC_ALL category, allows local attackers to execute arbitrary code via a user-controlled locale string that has more than 6 elements, which exceeds the boundaries of the new_categories category array, as exploitable through programs such as xterm and zsh.

CVE-2002-1500 netbsd vulnerability CVSS: 7.2 02 Apr 2003, 05:00 UTC

Buffer overflow in (1) mrinfo, (2) mtrace, and (3) pppd in NetBSD 1.4.x through 1.6 allows local users to gain privileges by executing the programs after filling the file descriptor tables, which produces file descriptors larger than FD_SETSIZE, which are not checked by FD_SET().

CVE-2002-1490 netbsd vulnerability CVSS: 2.1 02 Apr 2003, 05:00 UTC

NetBSD 1.4 through 1.6 beta allows local users to cause a denial of service (kernel panic) via a series of calls to the TIOCSCTTY ioctl, which causes an integer overflow in a structure counter and sets the counter to zero, which frees memory that is still in use by other processes.

CVE-2002-1543 netbsd vulnerability CVSS: 4.6 31 Mar 2003, 05:00 UTC

Buffer overflow in trek on NetBSD 1.5 through 1.5.3 allows local users to gain privileges via long keyboard input.

CVE-2003-0102 netbsd vulnerability CVSS: 4.6 18 Mar 2003, 05:00 UTC

Buffer overflow in tryelf() in readelf.c of the file command allows attackers to execute arbitrary code as the user running file, possibly via a large entity size value in an ELF header (elfhdr.e_shentsize).

CVE-2002-1337 netbsd vulnerability CVSS: 10.0 07 Mar 2003, 05:00 UTC

Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related to sender and recipient header comments as processed by the crackaddr function of headers.c.

CVE-2003-0001 netbsd vulnerability CVSS: 5.0 17 Jan 2003, 05:00 UTC

Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote attackers to obtain information from previous packets or kernel memory by using malformed packets, as demonstrated by Etherleak.

CVE-2002-2245 netbsd vulnerability CVSS: 5.0 31 Dec 2002, 05:00 UTC

ftpd in NetBSD 1.5 through 1.5.3 and 1.6 does not properly quote a digit in response to a STAT command for a filename that contains a carriage return followed by a digit, which can cause firewalls and other intermediary devices to lose proper track of the FTP session.

CVE-2002-2092 netbsd vulnerability CVSS: 3.7 31 Dec 2002, 05:00 UTC

Race condition in exec in OpenBSD 4.0 and earlier, NetBSD 1.5.2 and earlier, and FreeBSD 4.4 and earlier allows local users to gain privileges by attaching a debugger to a process before the kernel has determined that the process is setuid or setgid.

CVE-2002-1915 netbsd vulnerability CVSS: 2.1 31 Dec 2002, 05:00 UTC

tip on multiple BSD-based operating systems allows local users to cause a denial of service (execution prevention) by using flock() to lock the /var/log/acculog file.

CVE-2002-0666 netbsd vulnerability CVSS: 5.0 04 Nov 2002, 05:00 UTC

IPSEC implementations including (1) FreeS/WAN and (2) KAME do not properly calculate the length of authentication data, which allows remote attackers to cause a denial of service (kernel panic) via spoofed, short Encapsulating Security Payload (ESP) packets, which result in integer signedness errors.

CVE-2002-1194 netbsd vulnerability CVSS: 7.5 28 Oct 2002, 05:00 UTC

Buffer overflow in talkd on NetBSD 1.6 and earlier, and possibly other operating systems, may allow remote attackers to execute arbitrary code via a long inbound message.

CVE-2002-1192 netbsd vulnerability CVSS: 4.6 28 Oct 2002, 05:00 UTC

Multiple buffer overflows in rogue on NetBSD 1.6 and earlier, FreeBSD 4.6, and possibly other operating systems, allows local users to gain "games" group privileges via malformed entries in a game save file.

CVE-2002-1165 netbsd vulnerability CVSS: 4.6 11 Oct 2002, 04:00 UTC

Sendmail Consortium's Restricted Shell (SMRSH) in Sendmail 8.12.6, 8.11.6-15, and possibly other versions after 8.11 from 5/19/1998, allows attackers to bypass the intended restrictions of smrsh by inserting additional commands after (1) "||" sequences or (2) "/" characters, which are not properly filtered or verified.

CVE-2002-0414 netbsd vulnerability CVSS: 7.5 12 Aug 2002, 04:00 UTC

KAME-derived implementations of IPsec on NetBSD 1.5.2, FreeBSD 4.5, and other operating systems, does not properly consult the Security Policy Database (SPD), which could cause a Security Gateway (SG) that does not use Encapsulating Security Payload (ESP) to forward forged IPv4 packets.

CVE-2000-1208 netbsd vulnerability CVSS: 7.2 12 Aug 2002, 04:00 UTC

Format string vulnerability in startprinting() function of printjob.c in BSD-based lpr lpd package may allow local users to gain privileges via an improper syslog call that uses format strings from the checkremote() call.

CVE-2002-0381 netbsd vulnerability CVSS: 5.0 25 Jun 2002, 04:00 UTC

The TCP implementation in various BSD operating systems (tcp_input.c) does not properly block connections to broadcast addresses, which could allow remote attackers to bypass intended filters via packets with a unicast link layer address and an IP broadcast address.

CVE-2002-0004 netbsd vulnerability CVSS: 7.2 27 Feb 2002, 05:00 UTC

Heap corruption vulnerability in the "at" program allows local users to execute arbitrary code via a malformed execution time, which causes at to free the same memory twice.

CVE-2001-0734 netbsd vulnerability CVSS: 7.2 18 Oct 2001, 04:00 UTC

Hitachi Super-H architecture in NetBSD 1.5 and 1.4.1 allows a local user to gain privileges via modified Status Register contents, which are not properly handled by (1) the sigreturn system call or (2) the process_write_regs kernel routine.

CVE-2001-0670 netbsd vulnerability CVSS: 7.5 03 Oct 2001, 04:00 UTC

Buffer overflow in BSD line printer daemon (in.lpd or lpd) in various BSD-based operating systems allows remote attackers to execute arbitrary code via an incomplete print job followed by a request to display the printer queue.

CVE-2001-0710 netbsd vulnerability CVSS: 5.0 20 Sep 2001, 04:00 UTC

NetBSD 1.5 and earlier and FreeBSD 4.3 and earlier allows a remote attacker to cause a denial of service by sending a large number of IP fragments to the machine, exhausting the mbuf pool.

CVE-2001-1091 netbsd vulnerability CVSS: 7.2 23 Aug 2001, 04:00 UTC

The (1) dump and (2) dump_lfs commands in NetBSD 1.4.x through 1.5.1 do not properly drop privileges, which could allow local users to gain privileges via the RCMD_CMD environment variable.

CVE-2001-1145 netbsd vulnerability CVSS: 6.2 17 Aug 2001, 04:00 UTC

fts routines in FreeBSD 4.3 and earlier, NetBSD before 1.5.2, and OpenBSD 2.9 and earlier can be forced to change (chdir) into a different directory than intended when the directory above the current directory is moved, which could cause scripts to perform dangerous actions on the wrong directories.

CVE-2001-0554 netbsd vulnerability CVSS: 10.0 14 Aug 2001, 04:00 UTC

Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a set of options including AYT (Are You There), which is not properly handled by the telrcv function.

CVE-2001-0993 netbsd vulnerability CVSS: 2.1 24 Jul 2001, 04:00 UTC

sendmsg function in NetBSD 1.3 through 1.5 allows local users to cause a denial of service (kernel trap or panic) via a msghdr structure with a large msg_controllen length.

CVE-2001-1244 netbsd vulnerability CVSS: 5.0 07 Jul 2001, 04:00 UTC

Multiple TCP implementations could allow remote attackers to cause a denial of service (bandwidth and CPU exhaustion) by setting the maximum segment size (MSS) to a very small number and requesting large amounts of data, which generates more packets with less TCP-level data that amplify network traffic and consume more server CPU to process.

CVE-2001-0247 netbsd vulnerability CVSS: 10.0 18 Jun 2001, 04:00 UTC

Buffer overflows in BSD-based FTP servers allows remote attackers to execute arbitrary commands via a long pattern string containing a {} sequence, as seen in (1) g_opendir, (2) g_lstat, (3) g_stat, and (4) the glob0 buffer as used in the glob functions glob2 and glob3.

CVE-2001-0268 netbsd vulnerability CVSS: 7.2 03 May 2001, 04:00 UTC

The i386_set_ldt system call in NetBSD 1.5 and earlier, and OpenBSD 2.8 and earlier, when the USER_LDT kernel option is enabled, does not validate a call gate target, which allows local users to gain root privileges by creating a segment call gate in the Local Descriptor Table (LDT) with a target that specifies an arbitrary kernel address.

CVE-2000-0314 netbsd vulnerability CVSS: 5.0 12 Mar 2001, 05:00 UTC

traceroute in NetBSD 1.3.3 and Linux systems allows local users to flood other systems by providing traceroute with a large waittime (-w) option, which is not parsed properly and sets the time delay for sending packets to zero.

CVE-2000-0315 netbsd vulnerability CVSS: 5.0 12 Mar 2001, 05:00 UTC

traceroute in NetBSD 1.3.3 and Linux systems allows local unprivileged users to modify the source address of the packets, which could be used in spoofing attacks.

CVE-2001-0033 netbsd vulnerability CVSS: 7.2 16 Feb 2001, 05:00 UTC

KTH Kerberos IV allows local users to change the configuration of a Kerberos server running at an elevated privilege by specifying an alternate directory using with the KRBCONFDIR environmental variable, which allows the user to gain additional privileges.

CVE-2001-0053 netbsd vulnerability CVSS: 10.0 12 Feb 2001, 05:00 UTC

One-byte buffer overflow in replydirname function in BSD-based ftpd allows remote attackers to gain root privileges.

CVE-2000-0993 netbsd vulnerability CVSS: 7.2 19 Dec 2000, 05:00 UTC

Format string vulnerability in pw_error function in BSD libutil library allows local users to gain root privileges via a malformed password in commands such as chpass or passwd.

CVE-2000-0997 netbsd vulnerability CVSS: 7.2 19 Dec 2000, 05:00 UTC

Format string vulnerabilities in eeprom program in OpenBSD, NetBSD, and possibly other operating systems allows local attackers to gain root privileges.

CVE-2000-0750 netbsd vulnerability CVSS: 7.5 20 Oct 2000, 04:00 UTC

Buffer overflow in mopd (Maintenance Operations Protocol loader daemon) allows remote attackers to execute arbitrary commands via a long file name.

CVE-2000-0751 netbsd vulnerability CVSS: 7.5 20 Oct 2000, 04:00 UTC

mopd (Maintenance Operations Protocol loader daemon) does not properly cleanse user-injected format strings, which allows remote attackers to execute arbitrary commands.

CVE-2000-0461 netbsd vulnerability CVSS: 2.1 29 May 2000, 04:00 UTC

The undocumented semconfig system call in BSD freezes the state of semaphores, which allows local users to cause a denial of service of the semaphore system by using the semconfig call.

CVE-2000-0456 netbsd vulnerability CVSS: 2.1 28 May 2000, 04:00 UTC

NetBSD 1.4.2 and earlier allows local users to cause a denial of service by repeatedly running certain system calls in the kernel which do not yield the CPU, aka "cpu-hog".

CVE-2000-0462 netbsd vulnerability CVSS: 2.1 28 May 2000, 04:00 UTC

ftpd in NetBSD 1.4.2 does not properly parse entries in /etc/ftpchroot and does not chroot the specified users, which allows those users to access other files outside of their home directory.

CVE-2000-0440 netbsd vulnerability CVSS: 5.0 01 May 2000, 04:00 UTC

NetBSD 1.4.2 and earlier allows remote attackers to cause a denial of service by sending a packet with an unaligned IP timestamp option.

CVE-2000-0094 netbsd vulnerability CVSS: 7.2 16 Feb 2000, 05:00 UTC

procfs in BSD systems allows local users to gain root privileges by modifying the /proc/pid/mem interface via a modified file descriptor for stderr.

CVE-2000-0157 netbsd vulnerability CVSS: 7.2 01 Feb 2000, 05:00 UTC

NetBSD ptrace call on VAX allows local users to gain privileges by modifying the PSL contents in the debugging process.

CVE-2000-0092 netbsd vulnerability CVSS: 6.2 19 Jan 2000, 05:00 UTC

The BSD make program allows local users to modify files via a symlink attack when the -j option is being used.

CVE-2000-0489 netbsd vulnerability CVSS: 2.1 05 Sep 1999, 04:00 UTC

FreeBSD, NetBSD, and OpenBSD allow an attacker to cause a denial of service by creating a large number of socket pairs using the socketpair function, setting a large buffer size via setsockopt, then writing large buffers.

CVE-1999-0674 netbsd vulnerability CVSS: 7.2 09 Aug 1999, 04:00 UTC

The BSD profil system call allows a local user to modify the internal data space of a program via profiling and execve.

CVE-1999-1518 netbsd vulnerability CVSS: 5.0 15 Jul 1999, 04:00 UTC

Operating systems with shared memory implementations based on BSD 4.4 code allow a user to conduct a denial of service and bypass memory limits (e.g., as specified with rlimits) using mmap or shmget to allocate memory and cause page faults.

CVE-1999-0763 netbsd vulnerability CVSS: 6.4 01 May 1999, 04:00 UTC

NetBSD on a multi-homed host allows ARP packets on one network to modify ARP entries on another connected network.

CVE-1999-0764 netbsd vulnerability CVSS: 6.4 01 May 1999, 04:00 UTC

NetBSD allows ARP packets to overwrite static ARP entries.

CVE-1999-0466 netbsd vulnerability CVSS: 7.2 21 Apr 1999, 04:00 UTC

The SVR4 /dev/wabi special device file in NetBSD 1.3.3 and earlier allows a local user to read or write arbitrary files on the disk associated with that device.

CVE-1999-0446 netbsd vulnerability CVSS: 2.1 12 Apr 1999, 04:00 UTC

Local users can perform a denial of service in NetBSD 1.3.3 and earlier versions by creating an unusual symbolic link with the ln command, triggering a bug in VFS.

CVE-1999-0434 netbsd vulnerability CVSS: 7.5 30 Mar 1999, 05:00 UTC

XFree86 xfs command is vulnerable to a symlink attack, allowing local users to create files in restricted directories, possibly allowing them to gain privileges or cause a denial of service.

CVE-1999-0433 netbsd vulnerability CVSS: 4.6 21 Mar 1999, 05:00 UTC

XFree86 startx command is vulnerable to a symlink attack, allowing local users to create files in restricted directories, possibly allowing them to gain privileges or cause a denial of service.

CVE-1999-0420 netbsd vulnerability CVSS: 7.2 17 Mar 1999, 05:00 UTC

umapfs allows local users to gain root privileges by changing their uid through a malicious mount_umap program.

CVE-1999-0422 netbsd vulnerability CVSS: 4.6 17 Mar 1999, 05:00 UTC

In some cases, NetBSD 1.3.3 mount allows local users to execute programs in some file systems that have the "noexec" flag set.

CVE-1999-0396 netbsd vulnerability CVSS: 2.6 17 Feb 1999, 05:00 UTC

A race condition between the select() and accept() calls in NetBSD TCP servers allows remote attackers to cause a denial of service.

CVE-1999-0367 netbsd vulnerability CVSS: 2.1 09 Feb 1999, 05:00 UTC

NetBSD netstat command allows local users to access kernel memory.

CVE-1999-1409 netbsd vulnerability CVSS: 2.1 03 Jul 1998, 04:00 UTC

The at program in IRIX 6.2 and NetBSD 1.3.2 and earlier allows local users to read portions of arbitrary files by submitting the file to at with the -f argument, which generates error messages that at sends to the user via e-mail.

CVE-1999-0303 netbsd vulnerability CVSS: 4.6 21 May 1998, 04:00 UTC

Buffer overflow in BNU UUCP daemon (uucpd) through long hostnames.

CVE-1999-0009 netbsd vulnerability CVSS: 10.0 08 Apr 1998, 04:00 UTC

Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases.

CVE-1999-0011 netbsd vulnerability CVSS: 10.0 08 Apr 1998, 04:00 UTC

Denial of Service vulnerabilities in BIND 4.9 and BIND 8 Releases via CNAME record and zone transfer.

CVE-1999-0010 netbsd vulnerability CVSS: 5.0 08 Apr 1998, 04:00 UTC

Denial of Service vulnerability in BIND 8 Releases via maliciously formatted DNS messages.

CVE-1999-0323 netbsd vulnerability CVSS: 10.0 20 Feb 1998, 05:00 UTC

FreeBSD mmap function allows users to modify append-only or immutable files.

CVE-1999-0304 netbsd vulnerability CVSS: 7.2 01 Feb 1998, 05:00 UTC

mmap function in BSD allows local attackers in the kmem group to modify memory through devices.

CVE-1999-0513 netbsd vulnerability CVSS: 5.0 05 Jan 1998, 05:00 UTC

ICMP messages to broadcast addresses are allowed, allowing for a Smurf attack that can cause a denial of service.

CVE-1999-0015 netbsd vulnerability CVSS: 5.0 16 Dec 1997, 05:00 UTC

Teardrop IP denial of service.

CVE-1999-0017 netbsd vulnerability CVSS: 7.5 10 Dec 1997, 05:00 UTC

FTP servers can allow an attacker to connect to arbitrary ports on machines other than the FTP client, aka FTP bounce.

CVE-1999-0016 netbsd vulnerability CVSS: 5.0 01 Dec 1997, 05:00 UTC

Land IP denial of service.

CVE-1999-1214 netbsd vulnerability CVSS: 2.1 15 Sep 1997, 04:00 UTC

The asynchronous I/O facility in 4.4 BSD kernel does not check user credentials when setting the recipient of I/O notification, which allows local users to cause a denial of service by using certain ioctl and fcntl calls to cause the signal to be sent to an arbitrary process ID.

CVE-1999-1225 netbsd vulnerability CVSS: 5.0 24 Aug 1997, 04:00 UTC

rpc.mountd on Linux, Ultrix, and possibly other operating systems, allows remote attackers to determine the existence of a file on the server by attempting to mount that file, which generates different error messages depending on whether the file exists or not.

CVE-1999-0074 netbsd vulnerability CVSS: 6.4 01 Jul 1997, 04:00 UTC

Listening TCP ports are sequentially allocated, allowing spoofing attacks.

CVE-1999-0628 netbsd vulnerability CVSS: 5.0 01 Jul 1997, 04:00 UTC

The rwho/rwhod service is running, which exposes machine status and user information.

CVE-1999-0046 netbsd vulnerability CVSS: 10.0 06 Feb 1997, 05:00 UTC

Buffer overflow of rlogin program using TERM environmental variable.

CVE-1999-0297 netbsd vulnerability CVSS: 7.2 12 Dec 1996, 05:00 UTC

Buffer overflow in Vixie Cron library up to version 3.0 allows local users to obtain root access via a long environmental variable.

CVE-1999-0085 netbsd vulnerability CVSS: 7.5 21 Aug 1996, 04:00 UTC

Buffer overflow in rwhod on AIX and other operating systems allows remote attackers to execute arbitrary code via a UDP packet with a long hostname.