Vulnerabilidades em openbsd

33 resultados
Análise Vexday

OpenBSD apresenta footprint reduzido na base Vexday com apenas 1 CVE registrado, sem evidências de exploração ativa em campo. A vulnerabilidade identificada (CWE-125: leitura fora dos limites) foi publicada recentemente, mas sua classificação abaixo do nível crítico e ausência de ataques documentados indicam risco contido no curto prazo.

CVE-2025-32728MEDIUMIn sshd in OpenSSH before 10.0, the DisableForwarding directive does not adhere to the documentation stating that it disables X11 and agent EPSS 0.2%CVE-2026-59998MEDIUMsshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in WindoEPSS 0.2%CVE-2026-35414MEDIUMOpenSSH before 10.3 mishandles the authorized_keys principals option in uncommon scenarios involving a principals list in conjunction with aEPSS 0.2%CVE-2026-59997MEDIUMinternal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-lEPSS 0.2%CVE-2026-59999MEDIUMIn sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.EPSS 0.2%CVE-2023-52556MEDIUMOpenBSD 7.4 pf state race condition kernel crashEPSS 0.1%CVE-2024-11149MEDIUMOpenBSD vmm GDTR limitsEPSS 0.1%CVE-2026-35388LOWOpenSSH before 10.3 omits connection multiplexing confirmation for proxy-mode multiplexing sessions.EPSS 0.1%CVE-2026-57589HIGHsys/kern/sysv_sem.c in OpenBSD through 7.9 has a use-after-free allowing local privilege escalation to root. This is a context switch use-afEPSS 0.1%CVE-2025-61985LOWssh in OpenSSH before 10.1 allows the '\0' character in an ssh:// URI, potentially leading to code execution when a ProxyCommand is used.EPSS 0.1%CVE-2026-73281LOWIn ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that aEPSS CVE-2026-73282MEDIUMIn ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.EPSS CVE-2026-73283LOWIn sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.EPSS