NetBSD

15 May

CVE-2012-2612

The DiagTraceHex function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatch ...

CVE-2012-2611

The DiagTraceR3Info function in the Dialog processor in disp+work.exe 7010.29.15.58313 and 7200. ...

CVE-2012-2514

The DiagiEventSource function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Disp ...

CVE-2012-2513

The Diaginput function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher ...

CVE-2012-2512

The DiagTraceStreamI function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Disp ...

CVE-2012-2511

The DiagTraceAtoms function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispat ...

14 May

CVE-2012-2333

Integer underflow in OpenSSL before 0.9.8x, 1.0.0 before 1.0.0j, and 1.0.1 before 1.0.1c, when TLS 1 ...

CVE-2012-2277

The IRM Server in EMC Documentum Information Rights Management 4.x before 4.7.0100 and 5.x before 5. ...

CVE-2012-2276

The IRM Server in EMC Documentum Information Rights Management 4.x before 4.7.0100 and 5.x before 5. ...

CVE-2012-1804

Progea Movicon before 11.3 allows remote attackers to cause a denial of service (out-of-bounds r ...

Óâåäîìëåíèÿ 26 - 40 of 100
First | Prev. | 1 2 3 4 5 6 | Next | Last 

NetBSD Security Advisory 2006-015 Information leakage between local processes

Due to the documented behavior of AMD processors when running amd64, i386 and Xen NetBSD kernels, processors using floating point operations can leak information.

19 april, 2006

NetBSD Security Advisory 2006-013 sysctl(3) local denial of service

The user supplied buffer where results of the sysctl(3) call are stored is locked into physical memory without checking its size.

13 april, 2006

NetBSD Security Advisory 2006-012; SIOCGIFALIAS ioctl may cause system crash

A system crash can occur if a user attempts to gather information on a non-existent alias of a network interface via the SIOCGIFALIAS ioctl.

12 april, 2006

NetBSD Security Advisory 2006-011 Systems could be vulnerable to a replay attack

A vulnerability was found in the fast_ipsec(4) stack that renders the IPSec anti-replay service ineffective under certain circumstances.

01 april, 2006

NetBSD Security Advisory 2006-010 Sendmail race condition

Sendmail is vulnerable to a race condition in the handling of asynchronous signals. This may allow a remote attacker to execute arbitrary code with the privileges of the sendmail user.

31 march, 2006

NetBSD Security Advisory 2006-008: Malformed ELF interpreter causes system crash

The netbsd-2, netbsd-2-0 and netbsd-2-1 branches are only vulnerable if the kernel is compiled with the USE_TOPDOWN_VM option which is not set by default in GENERIC kernels.

31 march, 2006

NetBSD Security Advisory 2006-007 mail(1) creates record file with insecure umask

If the "set record" setting is present in a users .mailrc, and they have the default umask set, the record file will be created with insecure permissions.

31 march, 2006

NetBSD Security Advisory 2006-005 bridge memory disclosure

An information disclosure issue exists in if_bridge(4) code.

31 march, 2006

NetBSD Security Advisory 2006-004: Denial of services issues with pf

There is a logical bug in pf's scrub fragment cache, which in certain configurations may lead to a remotely exploitable denial of service attack.

31 march, 2006

NetBSD Security Advisory 2006-003 Multiple denial of services issues with racoon

On further testing the racoon daemon supplied with NetBSD and in pkgsrc were found to be vulnerable to a number of denial of service attacks.

31 march, 2006

NetBSD Security Advisory 2006-001 Kernfs kernel memory disclosure

The kernfs filesystem does not validate file offsets properly and a userlevel non-privileged process can read arbitrary kernel memory locations.

11 january, 2006

NetBSD Security Advisory 2006-002 settimeofday() time wrap

Setting the time backwards is not regularly allowed at securelevel > 1. The settime() code in the kernel had no provision against wrapping. Once the clock reached approximately "Tue Jan 19 03:14:07 UTC 2038", it will wrap to "Fri Dec 13 20:45:52 UTC 1901". After that, a root process can set the time to any value, since all values are greater than that.

11 january, 2006

NetBSD Security Advisory 2005-013 -- ptrace() permissions after S[UG]ID and exec()

Processes running with alternate privileges gained from setuid and setgid executables are prevented from debugger attachment by their original owner (via ptrace).

08 november, 2005

NetBSD Security Advisory 2005-012 -- SO_LINGER argument checking DIAGNOSTIC panic

The SO_LINGER socket option can be passed negative a linger time, which can be used by an unprivileged user to trigger a kernel assertion panic if the kernel is compiled with "options DIAGNOSTIC".

08 november, 2005

NetBSD Security Advisory 2005-011 -- ntpd may start with different group id than desired

When started with the -u parameter, and passed a group to run as, ntpd will use the primary group of the user and not the provided group.

08 november, 2005

Óâåäîìëåíèÿ 26 - 40 of 100
First | Prev. | 1 2 3 4 5 6 | Next | Last

CVE-2012-2612

The DiagTraceHex function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.

15 may, 2012

CVE-2012-2611

The DiagTraceR3Info function in the Dialog processor in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2, when a certain Developer Trace configuration is enabled, allows remote attackers to execu ...

15 may, 2012

CVE-2012-2514

The DiagiEventSource function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.

15 may, 2012

CVE-2012-2513

The Diaginput function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.

15 may, 2012

CVE-2012-2512

The DiagTraceStreamI function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.

15 may, 2012

CVE-2012-2511

The DiagTraceAtoms function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.

15 may, 2012

CVE-2012-2333

Integer underflow in OpenSSL before 0.9.8x, 1.0.0 before 1.0.0j, and 1.0.1 before 1.0.1c, when TLS 1.1, TLS 1.2, or DTLS is used with CBC encryption, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecif ...

14 may, 2012

CVE-2012-2277

The IRM Server in EMC Documentum Information Rights Management 4.x before 4.7.0100 and 5.x before 5.0.1030 allows remote attackers to cause a denial of service (pvcontrol.exe process hang) via \n (line feed) characters in the Id fields of ...

14 may, 2012

CVE-2012-2276

The IRM Server in EMC Documentum Information Rights Management 4.x before 4.7.0100 and 5.x before 5.0.1030 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via input data that (1) lacks FIPS ...

14 may, 2012

CVE-2012-1804

Progea Movicon before 11.3 allows remote attackers to cause a denial of service (out-of-bounds read and memory corruption) via a crafted HTTP request.

14 may, 2012

Firefox 8/9 AttributeChildRemoved() Use-After-Free Exploit

Target: Mozilla Firefox 8.x, 9.x
Impact: Code execution

MS12-027 MSCOMCTL ActiveX Buffer Overflow Exploit (meta)

Target: MSCOMCTL ActiveX
Impact: Code execution

Microsoft Windows RDP PoC (CVE-2012-0002)

Target: Microsoft Windows XP, 2003, Vista, 7, 2008
Impact: Code execution