Lucene search

K

FreeBSD, NetBSD Security Vulnerabilities

openvas
openvas

FTPD glob Heap Corruption

The FTPD glob vulnerability manifests itself in handling of the glob command. The problem is not a typical buffer overflow or format string vulnerability, but a combination of two bugs: an implementation of the glob command that does not properly return an error condition when interpreting...

9.8CVSS

9.7AI Score

0.961EPSS

2005-11-03 12:00 AM
49
cve
cve

CVE-2002-1337

Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related to sender and recipient header comments as processed by the crackaddr function of...

7.6AI Score

0.902EPSS

2004-09-01 04:00 AM
52
cve
cve

CVE-2003-0078

ssl3_get_record in s3_pkt.c for OpenSSL before 0.9.7a and 0.9.6 before 0.9.6i does not perform a MAC computation if an incorrect block cipher padding is used, which causes an information leak (timing discrepancy) that may make it easier to launch cryptographic attacks that rely on distinguishing...

9.2AI Score

0.028EPSS

2004-09-01 04:00 AM
37
nvd
nvd

CVE-2003-0078

ssl3_get_record in s3_pkt.c for OpenSSL before 0.9.7a and 0.9.6 before 0.9.6i does not perform a MAC computation if an incorrect block cipher padding is used, which causes an information leak (timing discrepancy) that may make it easier to launch cryptographic attacks that rely on distinguishing...

6AI Score

0.028EPSS

2003-03-03 05:00 AM
cve
cve

CVE-2003-0466

Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code, as demonstrated in wu-ftpd 2.5.0 through 2.6.2 via commands that cause pathnames of length MAXPATHLEN+1 to trigger a buffer overflow, including (1) STOR, (2)....

9.8CVSS

9.8AI Score

0.795EPSS

2003-08-27 04:00 AM
84
prion
prion

Design/Logic Flaw

The dtls1_buffer_record function in ssl/d1_pkt.c in OpenSSL 0.9.8k and earlier 0.9.8 versions allows remote attackers to cause a denial of service (memory consumption) via a large series of "future epoch" DTLS records that are buffered in a queue, aka "DTLS record buffer limitation...

7AI Score

0.058EPSS

2009-05-19 07:30 PM
8
nvd
nvd

CVE-2004-0112

The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that causes an...

7.2AI Score

0.002EPSS

2004-11-23 05:00 AM
cve
cve

CVE-2004-0112

The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that causes an...

7.2AI Score

0.002EPSS

2004-11-23 05:00 AM
54
openvas
openvas

Huawei EulerOS: Security Advisory for kernel (EulerOS-SA-2021-1246)

The remote host is missing an update for the Huawei...

8.8CVSS

7.7AI Score

0.004EPSS

2021-02-05 12:00 AM
5
prion
prion

Memory corruption

Multiple memory leaks in the dtls1_process_out_of_seq_message function in ssl/d1_both.c in OpenSSL 0.9.8k and earlier 0.9.8 versions allow remote attackers to cause a denial of service (memory consumption) via DTLS records that (1) are duplicates or (2) have sequence numbers much greater than...

7AI Score

0.077EPSS

2009-05-19 07:30 PM
8
openvas
openvas

Debian: Security Advisory (DLA-1749-1)

The remote host is missing an update for the...

6.1CVSS

6.6AI Score

0.005EPSS

2019-04-03 12:00 AM
30
openvas
openvas

Huawei EulerOS: Security Advisory for libXfont (EulerOS-SA-2019-2357)

The remote host is missing an update for the Huawei...

5.5CVSS

7.1AI Score

0.103EPSS

2020-01-23 12:00 AM
7
openvas
openvas

Debian: Security Advisory (DLA-1664-1)

The remote host is missing an update for the...

8.2CVSS

8.3AI Score

0.038EPSS

2019-02-06 12:00 AM
51
cve
cve

CVE-2009-1386

ssl/s3_pkt.c in OpenSSL before 0.9.8i allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a DTLS ChangeCipherSpec packet that occurs before...

5.9AI Score

0.065EPSS

2009-06-04 04:30 PM
54
nvd
nvd

CVE-2009-1386

ssl/s3_pkt.c in OpenSSL before 0.9.8i allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a DTLS ChangeCipherSpec packet that occurs before...

7.1AI Score

0.065EPSS

2009-06-04 04:30 PM
1
openvas
openvas

Mageia: Security Advisory (MGASA-2022-0460)

The remote host is missing an update for...

7.5CVSS

7.5AI Score

0.002EPSS

2022-12-14 12:00 AM
7
nvd
nvd

CVE-2009-1387

The dtls1_retrieve_buffered_fragment function in ssl/d1_both.c in OpenSSL before 1.0.0 Beta 2 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an out-of-sequence DTLS handshake message, related to a "fragment...

7.2AI Score

0.037EPSS

2009-06-04 04:30 PM
1
cve
cve

CVE-2009-1387

The dtls1_retrieve_buffered_fragment function in ssl/d1_both.c in OpenSSL before 1.0.0 Beta 2 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an out-of-sequence DTLS handshake message, related to a "fragment...

6.4AI Score

0.037EPSS

2009-06-04 04:30 PM
82
nvd
nvd

CVE-2003-0466

Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code, as demonstrated in wu-ftpd 2.5.0 through 2.6.2 via commands that cause pathnames of length MAXPATHLEN+1 to trigger a buffer overflow, including (1) STOR, (2)....

9.8CVSS

9.9AI Score

0.795EPSS

2003-08-27 04:00 AM
openvas
openvas

Debian: Security Advisory (DSA-551-1)

The remote host is missing an update for the...

6.7AI Score

0.014EPSS

2008-01-17 12:00 AM
7
openvas
openvas

Mageia: Security Advisory (MGASA-2013-0331)

The remote host is missing an update for...

6.8AI Score

0.0004EPSS

2022-01-28 12:00 AM
3
nvd
nvd

CVE-2002-1337

Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related to sender and recipient header comments as processed by the crackaddr function of...

7.7AI Score

0.902EPSS

2003-03-07 05:00 AM
openvas
openvas

Huawei EulerOS: Security Advisory for kernel (EulerOS-SA-2021-2663)

The remote host is missing an update for the Huawei...

9.8CVSS

7AI Score

0.002EPSS

2021-11-12 12:00 AM
10
cve
cve

CVE-2009-1377

The dtls1_buffer_record function in ssl/d1_pkt.c in OpenSSL 0.9.8k and earlier 0.9.8 versions allows remote attackers to cause a denial of service (memory consumption) via a large series of "future epoch" DTLS records that are buffered in a queue, aka "DTLS record buffer limitation...

6.3AI Score

0.058EPSS

2009-05-19 07:30 PM
66
nvd
nvd

CVE-2009-1377

The dtls1_buffer_record function in ssl/d1_pkt.c in OpenSSL 0.9.8k and earlier 0.9.8 versions allows remote attackers to cause a denial of service (memory consumption) via a large series of "future epoch" DTLS records that are buffered in a queue, aka "DTLS record buffer limitation...

7.3AI Score

0.058EPSS

2009-05-19 07:30 PM
nvd
nvd

CVE-2009-1378

Multiple memory leaks in the dtls1_process_out_of_seq_message function in ssl/d1_both.c in OpenSSL 0.9.8k and earlier 0.9.8 versions allow remote attackers to cause a denial of service (memory consumption) via DTLS records that (1) are duplicates or (2) have sequence numbers much greater than...

7.3AI Score

0.077EPSS

2009-05-19 07:30 PM
1
cve
cve

CVE-2009-1378

Multiple memory leaks in the dtls1_process_out_of_seq_message function in ssl/d1_both.c in OpenSSL 0.9.8k and earlier 0.9.8 versions allow remote attackers to cause a denial of service (memory consumption) via DTLS records that (1) are duplicates or (2) have sequence numbers much greater than...

6.7AI Score

0.077EPSS

2009-05-19 07:30 PM
62
openvas
openvas

Debian: Security Advisory (DLA-444-1)

The remote host is missing an update for the...

9.1AI Score

0.008EPSS

2023-03-08 12:00 AM
6
nessus
nessus

FreeBSD : FreeBSD -- Xen guests can triger backend Out Of Memory (5d91370b-61fd-11eb-b87a-901b0ef719ab)

Some OSes (including Linux, FreeBSD, and NetBSD) are processing watch events using a single thread. If the events are received faster than the thread is able to handle, they will get queued. As the queue is unbound, a guest may be able to trigger a OOM in the...

6.5CVSS

7.4AI Score

0.0004EPSS

2021-01-29 12:00 AM
26
nvd
nvd

CVE-2002-0391

Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, allows remote attackers to execute arbitrary code by passing a large number of arguments to xdr_array through RPC services such as rpc.cmsd and...

9.8CVSS

9.8AI Score

0.85EPSS

2002-08-12 04:00 AM
4
nessus
nessus

Oracle Linux 7 / 8 : Unbreakable Enterprise kernel-container (ELSA-2021-9007)

The remote Oracle Linux 7 / 8 host has packages installed that are affected by multiple vulnerabilities as referenced in the ELSA-2021-9007 advisory. A flaw was found in the Linux kernel. A use-after-free memory flaw was found in the perf subsystem allowing a local attacker with permission...

8.8CVSS

8.3AI Score

0.004EPSS

2021-01-13 12:00 AM
76
cve
cve

CVE-2002-0391

Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, allows remote attackers to execute arbitrary code by passing a large number of arguments to xdr_array through RPC services such as rpc.cmsd and...

9.8CVSS

9.9AI Score

0.85EPSS

2003-04-02 05:00 AM
43
openvas
openvas

SUSE: Security Advisory (SUSE-SU-2020:0790-1)

The remote host is missing an update for...

7.5CVSS

7.6AI Score

0.002EPSS

2021-04-19 12:00 AM
2
nessus
nessus

Oracle Linux 7 / 8 : Unbreakable Enterprise kernel (ELSA-2021-9006)

The remote Oracle Linux 7 / 8 host has packages installed that are affected by multiple vulnerabilities as referenced in the ELSA-2021-9006 advisory. A flaw was found in the Linux kernel. A use-after-free memory flaw was found in the perf subsystem allowing a local attacker with permission...

8.8CVSS

8.2AI Score

0.004EPSS

2021-01-13 12:00 AM
41
cve
cve

CVE-2002-0083

Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain...

9.8CVSS

9.1AI Score

0.009EPSS

2002-06-25 04:00 AM
160
nvd
nvd

CVE-2002-0083

Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain...

9.8CVSS

9.1AI Score

0.009EPSS

2002-03-15 05:00 AM
nessus
nessus

Oracle Linux 6 / 7 : Unbreakable Enterprise kernel (ELSA-2021-9030)

The remote Oracle Linux 6 / 7 host has packages installed that are affected by multiple vulnerabilities as referenced in the ELSA-2021-9030 advisory. An issue was found in Linux kernel before 5.5.4. The mwifiex_cmd_append_vsie_tlv() function in drivers/net/wireless/marvell/mwifiex/scan.c...

8.8CVSS

8.3AI Score

0.004EPSS

2021-02-03 12:00 AM
34
openvas
openvas

SUSE: Security Advisory (SUSE-SU-2020:0792-1)

The remote host is missing an update for...

7.5CVSS

7.6AI Score

0.002EPSS

2021-04-19 12:00 AM
1
nessus
nessus

OracleVM 3.4 : kernel-uek (OVMSA-2021-0005)

The remote OracleVM system is missing necessary patches to address security updates: An issue was found in Linux kernel before 5.5.4. The mwifiex_cmd_append_vsie_tlv() function in drivers/net/wireless/marvell/mwifiex/scan.c allows local users to gain privileges or cause a denial of ...

8.8CVSS

8.4AI Score

0.004EPSS

2021-02-05 12:00 AM
125
nessus
nessus

Oracle Linux 7 : Unbreakable Enterprise kernel-container (ELSA-2021-9024)

The remote Oracle Linux 7 host has a package installed that is affected by multiple vulnerabilities as referenced in the ELSA-2021-9024 advisory. An issue was discovered in Xen through 4.14.x. Some OSes (such as Linux, FreeBSD, and NetBSD) are processing watch events using a single thread....

8.8CVSS

8AI Score

0.004EPSS

2021-02-01 12:00 AM
125
nessus
nessus

Oracle Linux 7 : Unbreakable Enterprise kernel-container (ELSA-2021-9008)

The remote Oracle Linux 7 host has a package installed that is affected by multiple vulnerabilities as referenced in the ELSA-2021-9008 advisory. An issue was discovered in Xen through 4.14.x. Some OSes (such as Linux, FreeBSD, and NetBSD) are processing watch events using a single thread....

8.8CVSS

8AI Score

0.004EPSS

2021-01-13 12:00 AM
128
nessus
nessus

Oracle Linux 7 : Unbreakable Enterprise kernel-container (ELSA-2021-9025)

The remote Oracle Linux 7 host has a package installed that is affected by multiple vulnerabilities as referenced in the ELSA-2021-9025 advisory. An issue was discovered in Xen through 4.14.x. Some OSes (such as Linux, FreeBSD, and NetBSD) are processing watch events using a single thread....

8.8CVSS

8AI Score

0.004EPSS

2021-02-01 12:00 AM
23
cert
cert

Apache Log4j allows insecure JNDI lookups

Overview Apache Log4j allows insecure JNDI lookups that could allow an unauthenticated, remote attacker to execute arbitrary code with the privileges of the vulnerable Java application using Log4j. CISA has published Apache Log4j Vulnerability Guidance and provides a Software List. Description The....

10CVSS

10AI Score

EPSS

2021-12-15 12:00 AM
987
nessus
nessus

Oracle Linux 7 / 8 : Unbreakable Enterprise kernel-container (ELSA-2021-9038)

The remote Oracle Linux 7 / 8 host has packages installed that are affected by multiple vulnerabilities as referenced in the ELSA-2021-9038 advisory. An issue was discovered in Xen through 4.14.x. Some OSes (such as Linux, FreeBSD, and NetBSD) are processing watch events using a single...

8.8CVSS

7.9AI Score

0.004EPSS

2021-04-14 12:00 AM
29
cert
cert

Dnsmasq is vulnerable to memory corruption and cache poisoning

Overview Dnsmasq is vulnerable to a set of memory corruption issues handling DNSSEC data and a second set of issues validating DNS responses. These vulnerabilities could allow an attacker to corrupt memory on a vulnerable system and perform cache poisoning attacks against a vulnerable environment.....

8.1CVSS

7.7AI Score

0.159EPSS

2021-01-19 12:00 AM
149
nessus
nessus

Ubuntu 16.04 LTS : Linux kernel vulnerabilities (USN-4748-1)

The remote Ubuntu 16.04 LTS host has a package installed that is affected by multiple vulnerabilities as referenced in the USN-4748-1 advisory. A flaw was found in the JFS filesystem code in the Linux Kernel which allows a local attacker with the ability to set extended attributes to panic...

7.8CVSS

7AI Score

0.001EPSS

2021-03-23 12:00 AM
34
nessus
nessus

Ubuntu 18.04 LTS / 20.04 LTS : Linux kernel vulnerabilities (USN-4750-1)

The remote Ubuntu 18.04 LTS / 20.04 LTS host has a package installed that is affected by multiple vulnerabilities as referenced in the USN-4750-1 advisory. A vulnerability was found in the Linux Kernel where the function sunkbd_reinit having been scheduled by sunkbd_interrupt before sunkbd...

8.8CVSS

7.8AI Score

0.001EPSS

2021-03-23 12:00 AM
46
nessus
nessus

Ubuntu 16.04 LTS / 18.04 LTS : Linux kernel vulnerabilities (USN-4749-1)

The remote Ubuntu 16.04 LTS / 18.04 LTS host has a package installed that is affected by multiple vulnerabilities as referenced in the USN-4749-1 advisory. A vulnerability was found in the Linux Kernel where the function sunkbd_reinit having been scheduled by sunkbd_interrupt before sunkbd...

8.8CVSS

7.7AI Score

0.001EPSS

2021-03-23 12:00 AM
22
cert
cert

OpenSSL 3.0.0 to 3.0.6 decodes some punycode email addresses in X.509 certificates improperly

Overview Two buffer overflow vulnerabilities were discovered in OpenSSL versions 3.0.0 through 3.0.6. These vulnerabilities were introduced in version 3.0.0 with the inclusion of support for punycode email address parsing for X.509 certificates. OpenSSL's assessment of the severity of the...

7.5CVSS

7.9AI Score

EPSS

2022-11-01 12:00 AM
711
nessus
nessus

Ubuntu 20.04 LTS : Linux kernel vulnerabilities (USN-4751-1)

The remote Ubuntu 20.04 LTS host has a package installed that is affected by multiple vulnerabilities as referenced in the USN-4751-1 advisory. A flaw was found in the Linux kernel. A use-after-free was found in the way the console subsystem was using ioctls KDGKBSENT and KDSKBSENT. A local...

8.8CVSS

7.9AI Score

0.001EPSS

2021-03-23 12:00 AM
34
Total number of security vulnerabilities2307