ISOMAN

Filtered CVEs

OpenBSD CVEs

CVEs linked to tracked OpenBSD releases.

Release Context

  1. OpenBSD · 7.9 alpha boot-cd
  2. OpenBSD · 7.9 alpha install
  3. OpenBSD · 7.9 alpha miniroot
  4. OpenBSD · 7.9 amd64 boot-cd
  5. OpenBSD · 7.9 amd64 floppy
  6. OpenBSD · 7.9 amd64 install
  7. OpenBSD · 7.9 amd64 miniroot
  8. OpenBSD · 7.9 arm64 boot-cd
  9. OpenBSD · 7.9 arm64 install
  10. OpenBSD · 7.9 arm64 miniroot
  11. OpenBSD · 7.9 armv7 miniroot
  12. OpenBSD · 7.9 hppa boot-cd
  13. OpenBSD · 7.9 hppa install
  14. OpenBSD · 7.9 hppa lif
  15. OpenBSD · 7.9 i386 boot-cd
  16. OpenBSD · 7.9 i386 floppy
  17. OpenBSD · 7.9 i386 install
  18. OpenBSD · 7.9 i386 miniroot
  19. OpenBSD · 7.9 landisk miniroot
  20. OpenBSD · 7.9 loongson boot-cd
  21. OpenBSD · 7.9 loongson miniroot
  22. OpenBSD · 7.9 luna88k miniroot
  23. OpenBSD · 7.9 macppc boot-cd
  24. OpenBSD · 7.9 macppc install
  25. OpenBSD · 7.9 octeon install
  26. OpenBSD · 7.9 octeon miniroot
  27. OpenBSD · 7.9 powerpc64 install
  28. OpenBSD · 7.9 powerpc64 miniroot
  29. OpenBSD · 7.9 riscv64 install
  30. OpenBSD · 7.9 riscv64 miniroot
  31. OpenBSD · 7.9 sparc64 boot-cd
  32. OpenBSD · 7.9 sparc64 floppy
  33. OpenBSD · 7.9 sparc64 floppy-b
  34. OpenBSD · 7.9 sparc64 install
  35. OpenBSD · 7.9 sparc64 miniroot

19 CVEs

  1. CVE-2026-57589
    HIGH · CVSS 7.4 ·

    sys/kern/sysv_sem.c in OpenBSD through 7.9 has a use-after-free allowing local privilege escalation to root. This is a context switch use-after-free after tsleep in sys_semget().

  2. CVE-2026-56099
    MEDIUM · CVSS 6.9 ·

    OpenBSD before commit 6a23123 (2026-06-18) contains an out-of-bounds read vulnerability in the mpls_do_error function within sys/netmpls/mpls_input.c that allows remote attackers to disclose kernel stack memory by sending crafted MPLS frames with 16 labels and no Bottom-of-Stack bit set.

  3. CVE-2007-4305
    MEDIUM · CVSS 6.2 ·

    Multiple race conditions in the (1) Sudo monitor mode and (2) Sysjail policies in Systrace on NetBSD and OpenBSD allow local users to defeat system call interposition, and consequently bypass access control policy and auditing.

  4. CVE-2006-6730
    MEDIUM · CVSS 6.6 ·

    OpenBSD and NetBSD permit usermode code to kill the display server and write to the X.Org /dev/xf86 device, which allows local users with root privileges to reduce securelevel by replacing the System Management Mode (SMM) handler via a write to an SMRAM address within /dev/xf86 (aka the video card memory-mapped I/O range), and then launching the new handler via a System Management Interrupt (SMI), as demonstrated by a write to Programmed I/O port 0xB2.

  5. CVE-2006-6397
    MEDIUM · CVSS 4.4 ·

    Integer overflow in banner/banner.c in FreeBSD, NetBSD, and OpenBSD might allow local users to modify memory via a long banner. NOTE: CVE and multiple third parties dispute this issue. Since banner is not setuid, an exploit would not cross privilege boundaries in normal operations. This issue is not a vulnerability

  6. CVE-2004-0414
    HIGH · CVSS 10 ·

    CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle malformed "Entry" lines, which prevents a NULL terminator from being used and may lead to a denial of service (crash), modification of critical program data, or arbitrary code execution.

  7. CVE-2004-0416
    HIGH · CVSS 10 ·

    Double free vulnerability for the error_prog_name string in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attackers to execute arbitrary code.

  8. CVE-2004-0417
    MEDIUM · CVSS 5 ·

    Integer overflow in the "Max-dotdot" CVS protocol command (serve_max_dotdot) for CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attackers to cause a server crash, which could cause temporary data to remain undeleted and consume disk space.

  9. CVE-2004-0418
    HIGH · CVSS 10 ·

    serve_notify in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle empty data lines, which may allow remote attackers to perform an "out-of-bounds" write for a single byte to execute arbitrary code or modify critical program data.

  10. CVE-2004-0492
    HIGH · CVSS 10 ·

    Heap-based buffer overflow in proxy_util.c for mod_proxy in Apache 1.3.25 to 1.3.31 allows remote attackers to cause a denial of service (process crash) and possibly execute arbitrary code via a negative Content-Length HTTP header field, which causes a large amount of data to be copied.

  11. CVE-2002-0701
    LOW · CVSS 2.1 ·

    ktrace in BSD-based operating systems allows the owner of a process with special privileges to trace the process after its privileges have been lowered, which may allow the owner to obtain sensitive information that the process obtained while it was running with the extra privileges.

  12. CVE-2002-0381
    MEDIUM · CVSS 5 ·

    The TCP implementation in various BSD operating systems (tcp_input.c) does not properly block connections to broadcast addresses, which could allow remote attackers to bypass intended filters via packets with a unicast link layer address and an IP broadcast address.

  13. CVE-2001-0670
    HIGH · CVSS 7.5 ·

    Buffer overflow in BSD line printer daemon (in.lpd or lpd) in various BSD-based operating systems allows remote attackers to execute arbitrary code via an incomplete print job followed by a request to display the printer queue.

  14. CVE-2000-0995
    HIGH · CVSS 7.2 ·

    Format string vulnerability in OpenBSD yp_passwd program (and possibly other BSD-based operating systems) allows attackers to gain root privileges a malformed name.

  15. CVE-2000-0996
    HIGH · CVSS 7.2 ·

    Format string vulnerability in OpenBSD su program (and possibly other BSD-based operating systems) allows local attackers to gain root privileges via a malformed shell.

  16. CVE-1999-0482
    MEDIUM · CVSS 5 ·

    OpenBSD kernel crash through TSS handling, as caused by the crashme program.

  17. CVE-1999-0483
    LOW · CVSS 2.1 ·

    OpenBSD crash using nlink value in FFS and EXT2FS filesystems.

  18. CVE-1999-0484
    LOW · CVSS 2.1 ·

    Buffer overflow in OpenBSD ping.

  19. CVE-1999-1225
    MEDIUM · CVSS 5 ·

    rpc.mountd on Linux, Ultrix, and possibly other operating systems, allows remote attackers to determine the existence of a file on the server by attempting to mount that file, which generates different error messages depending on whether the file exists or not.