VYPR

FreeBSD

by FreeBSD

Source repositories

CVEs (557)

  • CVE-2001-1244Jul 7, 2001
    risk 0.00cvss —epss 0.22

    Multiple TCP implementations could allow remote attackers to cause a denial of service (bandwidth and CPU exhaustion) by setting the maximum segment size (MSS) to a very small number and requesting large amounts of data, which generates more packets with less TCP-level data that…

  • CVE-2001-0439Jul 2, 2001
    risk 0.00cvss —epss 0.02

    licq before 1.0.3 allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.

  • CVE-2001-0424Jul 2, 2001
    risk 0.00cvss —epss 0.00

    BubbleMon 1.31 does not properly drop group privileges before executing programs, which allows local users to execute arbitrary commands with the kmem group id.

  • CVE-2001-0469Jun 27, 2001
    risk 0.00cvss —epss 0.02

    rwho daemon rwhod in FreeBSD 4.2 and earlier, and possibly other operating systems, allows remote attackers to cause a denial of service via malformed packets with a short length.

  • CVE-2001-0388Jun 27, 2001
    risk 0.00cvss —epss 0.03

    time server daemon timed allows remote attackers to cause a denial of service via malformed packets.

  • CVE-2001-0371Jun 18, 2001
    risk 0.00cvss —epss 0.00

    Race condition in the UFS and EXT2FS file systems in FreeBSD 4.2 and earlier, and possibly other operating systems, makes deleted data available to user processes before it is zeroed out, which allows a local user to access otherwise restricted information.

  • CVE-2001-0230Jun 2, 2001
    risk 0.00cvss —epss 0.00

    Buffer overflow in dc20ctrl before 0.4_1 in FreeBSD, and possibly other operating systems, allows local users to gain privileges.

  • CVE-2001-0310Jun 2, 2001
    risk 0.00cvss —epss 0.00

    sort in FreeBSD 4.1.1 and earlier, and possibly other operating systems, uses predictable temporary file names and does not properly handle when the temporary file already exists, which causes sort to crash and possibly impacts security-sensitive scripts.

  • CVE-2001-0196May 3, 2001
    risk 0.00cvss —epss 0.02

    inetd ident server in FreeBSD 4.x and earlier does not properly set group permissions, which allows remote attackers to read the first 16 bytes of files that are accessible by the wheel group.

  • CVE-2001-0235Mar 26, 2001
    risk 0.00cvss —epss 0.00

    Vulnerability in crontab allows local users to read crontab files of other users by replacing the temporary file that is being edited while crontab is running.

  • CVE-2001-0128Mar 12, 2001
    risk 0.00cvss —epss 0.00

    Zope before 2.2.4 does not properly compute local roles, which could allow users to bypass specified access restrictions and gain privileges.

  • CVE-2000-0375Mar 12, 2001
    risk 0.00cvss —epss 0.00

    The kernel in FreeBSD 3.2 follows symbolic links when it creates core dump files, which allows local attackers to modify arbitrary files.

  • CVE-2000-0890Feb 16, 2001
    risk 0.00cvss —epss 0.00

    periodic in FreeBSD 4.1.1 and earlier, and possibly other operating systems, allows local users to overwrite arbitrary files via a symlink attack.

  • CVE-2001-0063Feb 12, 2001
    risk 0.00cvss —epss 0.00

    procfs in FreeBSD and possibly other operating systems allows local users to bypass access control restrictions for a jail environment and gain additional privileges.

  • CVE-2001-0094Feb 12, 2001
    risk 0.00cvss —epss 0.00

    Buffer overflow in kdc_reply_cipher of libkrb (Kerberos 4 authentication library) in NetBSD 1.5 and FreeBSD 4.2 and earlier, as used in Kerberised applications such as telnetd and login, allows local users to gain root privileges.

  • CVE-2001-0062Feb 12, 2001
    risk 0.00cvss —epss 0.00

    procfs in FreeBSD and possibly other operating systems allows local users to cause a denial of service by calling mmap on the process' own mem file, which causes the kernel to hang.

  • CVE-2001-0061Feb 12, 2001
    risk 0.00cvss —epss 0.00

    procfs in FreeBSD and possibly other operating systems does not properly restrict access to per-process mem and ctl files, which allows local users to gain root privileges by forking a child process and executing a privileged process from the child, while the parent retains…

  • CVE-2000-1167Jan 9, 2001
    risk 0.00cvss —epss 0.02

    ppp utility in FreeBSD 4.1.1 and earlier does not properly restrict access as specified by the "nat deny_incoming" command, which allows remote attackers to connect to the target system.

  • CVE-2000-1184Jan 9, 2001
    risk 0.00cvss —epss 0.02

    telnetd in FreeBSD 4.2 and earlier, and possibly other operating systems, allows remote attackers to cause a denial of service by specifying an arbitrary large file in the TERMCAP environmental variable, which consumes resources as the server processes the file.

  • CVE-2000-0915Dec 19, 2000
    risk 0.00cvss —epss 0.02

    fingerd in FreeBSD 4.1.1 allows remote attackers to read arbitrary files by specifying the target file name instead of a regular user name.

Page 25 of 28