Known Vulnerabilities for products from Netbsd

Listed below are 20 of the newest known vulnerabilities associated with the vendor "Netbsd".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2023-45198 json ftpd before "NetBSD-ftpd 20230930" can leak information about the host filesystem before authentication via an MLSD or MLST c... 7.5 - HIGH 2023-10-05 2023-10-11
CVE-2021-45489 json In NetBSD through 9.2, the IPv6 Flow Label generation algorithm employs a weak cryptographic PRNG. 7.5 - HIGH 2021-12-25 2022-01-10
CVE-2021-45488 json In NetBSD through 9.2, there is an information leak in the TCP ISN (ISS) generation algorithm. 7.5 - HIGH 2021-12-25 2023-08-08
CVE-2021-45487 json In NetBSD through 9.2, the IPv4 ID generation algorithm does not use appropriate cryptographic measures. 7.5 - HIGH 2021-12-25 2023-08-08
CVE-2021-45484 json In NetBSD through 9.2, the IPv6 fragment ID generation algorithm employs a weak cryptographic PRNG. 7.5 - HIGH 2021-12-25 2023-08-08
CVE-2020-26139 json An issue was discovered in the kernel in NetBSD 7.1. An Access Point (AP) forwards EAPOL frames to other clients even though ... Not Provided 2021-05-11 2026-04-14
CVE-2017-1000378 json The NetBSD qsort() function is recursive, and not randomized, an attacker can construct a pathological input array of N eleme... 9.8 - CRITICAL 2017-06-19 2019-10-03
CVE-2017-1000375 json NetBSD maps the run-time link-editor ld.so directly below the stack region, even if ASLR is enabled, this allows attackers to... 9.8 - CRITICAL 2017-06-19 2017-08-12
CVE-2017-1000374 json A flaw exists in NetBSD's implementation of the stack guard page that allows attackers to bypass it resulting in arbitrary co... 9.8 - CRITICAL 2017-06-19 2019-10-03
CVE-2016-6253 json mail.local in NetBSD versions 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows local users to change ownership of or appe... 7.8 - HIGH 2017-01-20 2017-01-20
CVE-2015-8212 json CGI handling flaw in bozohttpd in NetBSD 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows remote attackers to execute arb... 9.8 - CRITICAL 2017-01-19 2017-01-20
CVE-2015-5917 json The glob implementation in tnftpd (formerly lukemftpd), as used in Apple OS X before 10.11, allows remote attackers to cause ... 5 - MEDIUM 2015-10-09 2016-12-08
CVE-2014-8517 json The fetch_url function in usr.bin/ftp/fetch.c in tnftp, as used in NetBSD 5.1 through 5.1.4, 5.2 through 5.2.2, 6.0 through 6... 7.5 - HIGH 2014-11-17 2017-11-06
CVE-2014-7250 json The TCP stack in 4.3BSD Net/2, as used in FreeBSD 5.4, NetBSD possibly 2.0, and OpenBSD possibly 3.6, does not properly imple... 5 - MEDIUM 2014-12-12 2014-12-12
CVE-2014-5384 json The VIQR module in the iconv implementation in FreeBSD 10.0 before p6 and NetBSD allows context-dependent attackers to cause ... 5 - MEDIUM 2014-08-21 2014-08-21
CVE-2014-5015 json bozotic HTTP server (aka bozohttpd) before 20140708, as used in NetBSD, truncates paths when checking .htpasswd restrictions,... 5 - MEDIUM 2014-07-24 2017-08-29
CVE-2014-3951 json The HZ module in the iconv implementation in FreeBSD 10.0 before p6 and NetBSD allows context-dependent attackers to cause a ... 5 - MEDIUM 2014-08-21 2014-08-21
CVE-2014-3566 json The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it... 3.4 - LOW 2014-10-15 2023-09-12
CVE-2012-5365 json The IPv6 implementation in FreeBSD and NetBSD (unknown versions, year 2012 and earlier) allows remote attackers to cause a de... 7.5 - HIGH 2020-02-20 2020-02-25
CVE-2012-5363 json The IPv6 implementation in FreeBSD and NetBSD (unknown versions, year 2012 and earlier) allows remote attackers to cause a de... 7.5 - HIGH 2020-02-20 2020-02-28

Known software with vulnerabilities from Netbsd

Type Vendor Product Version
ApplicationNetbsdFtpd-
Operating
System
NetbsdNetbsd-
ApplicationNetbsdUmapfs-