FreeBSD
by FreeBSD
Source repositories
CVEs (557)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2000-0963 | 0.00 | — | 0.01 | Dec 19, 2000 | Buffer overflow in ncurses library allows local users to execute arbitrary commands via long environmental information such as TERM or TERMINFO_DIRS. | |||
| CVE-2000-1011 | 0.00 | — | 0.00 | Dec 11, 2000 | Buffer overflow in catopen() function in FreeBSD 5.0 and earlier, and possibly other OSes, allows local users to gain root privileges via a long environmental variable. | |||
| CVE-2000-1066 | 0.00 | — | 0.02 | Dec 11, 2000 | The getnameinfo function in FreeBSD 4.1.1 and earlier, and possibly other operating systems, allows a remote attacker to cause a denial of service via a long DNS hostname. | |||
| CVE-2000-1013 | 0.00 | — | 0.00 | Dec 11, 2000 | The setlocale function in FreeBSD 5.0 and earlier, and possibly other OSes, allows local users to read arbitrary files via the LANG environmental variable. | |||
| CVE-2000-1012 | 0.00 | — | 0.00 | Dec 11, 2000 | The catopen function in FreeBSD 5.0 and earlier, and possibly other OSes, allows local users to read arbitrary files via the LANG environmental variable. | |||
| CVE-2000-0852 | 0.00 | — | 0.00 | Nov 14, 2000 | Multiple buffer overflows in eject on FreeBSD and possibly other OSes allows local users to gain root privileges. | |||
| CVE-2000-0749 | 0.00 | — | 0.00 | Oct 20, 2000 | Buffer overflow in the Linux binary compatibility module in FreeBSD 3.x through 5.x allows local users to gain root privileges via long filenames in the linux shadow file system. | |||
| CVE-2000-0729 | 0.00 | — | 0.00 | Oct 20, 2000 | FreeBSD 5.x, 4.x, and 3.x allows local users to cause a denial of service by executing a program with a malformed ELF image header. | |||
| CVE-2000-0752 | 0.00 | — | 0.00 | Oct 20, 2000 | Buffer overflows in brouted in FreeBSD and possibly other OSes allows local users to gain root privileges via long command line arguments. | |||
| CVE-1999-0761 | 0.00 | — | 0.00 | Sep 16, 2000 | Buffer overflow in FreeBSD fts library routines allows local user to modify arbitrary files via the periodic program. | |||
| CVE-2000-0595 | 0.00 | — | 0.01 | Jul 5, 2000 | libedit searches for the .editrc file in the current directory instead of the user's home directory, which may allow local users to execute arbitrary commands by installing a modified .editrc in another directory. | |||
| CVE-2000-0535 | 0.00 | — | 0.01 | Jun 12, 2000 | OpenSSL 0.9.4 and OpenSSH for FreeBSD do not properly check for the existence of the /dev/random or /dev/urandom devices, which are absent on FreeBSD Alpha systems, which causes them to produce weak keys which may be more easily broken. | |||
| CVE-2000-0532 | 0.00 | — | 0.02 | Jun 7, 2000 | A FreeBSD patch for SSH on 2000-01-14 configures ssh to listen on port 722 as well as port 22, which might allow remote attackers to access SSH through port 722 even if port 22 is otherwise filtered. | |||
| CVE-2000-0461 | 0.00 | — | 0.00 | May 29, 2000 | The undocumented semconfig system call in BSD freezes the state of semaphores, which allows local users to cause a denial of service of the semaphore system by using the semconfig call. | |||
| CVE-2000-0235 | 0.00 | — | 0.00 | Mar 27, 2000 | Buffer overflow in the huh program in the orville-write package allows local users to gain root privileges. | |||
| CVE-2000-0186 | 0.00 | — | 0.00 | Feb 28, 2000 | Buffer overflow in the dump utility in the Linux ext2fs backup package allows local users to gain privileges via a long command line argument. | |||
| CVE-2000-0092 | 0.00 | — | 0.00 | Jan 19, 2000 | The BSD make program allows local users to modify files via a symlink attack when the -j option is being used. | |||
| CVE-1999-0964 | 0.00 | — | 0.00 | Jan 1, 2000 | Buffer overflow in FreeBSD setlocale in the libc module allows attackers to execute arbitrary code via a long PATH_LOCALE environment variable. | |||
| CVE-1999-1339 | 0.00 | — | 0.03 | Dec 31, 1999 | Vulnerability when Network Address Translation (NAT) is enabled in Linux 2.2.10 and earlier with ipchains, or FreeBSD 3.2 with ipfw, allows remote attackers to cause a denial of service (kernel panic) via a ping -R (record route) command. | |||
| CVE-1999-0001 | 0.00 | — | 0.03 | Dec 30, 1999 | ip_input.c in BSD-derived TCP/IP implementations allows remote attackers to cause a denial of service (crash or hang) via crafted packets. |
- CVE-2000-0963Dec 19, 2000risk 0.00cvss —epss 0.01
Buffer overflow in ncurses library allows local users to execute arbitrary commands via long environmental information such as TERM or TERMINFO_DIRS.
- CVE-2000-1011Dec 11, 2000risk 0.00cvss —epss 0.00
Buffer overflow in catopen() function in FreeBSD 5.0 and earlier, and possibly other OSes, allows local users to gain root privileges via a long environmental variable.
- CVE-2000-1066Dec 11, 2000risk 0.00cvss —epss 0.02
The getnameinfo function in FreeBSD 4.1.1 and earlier, and possibly other operating systems, allows a remote attacker to cause a denial of service via a long DNS hostname.
- CVE-2000-1013Dec 11, 2000risk 0.00cvss —epss 0.00
The setlocale function in FreeBSD 5.0 and earlier, and possibly other OSes, allows local users to read arbitrary files via the LANG environmental variable.
- CVE-2000-1012Dec 11, 2000risk 0.00cvss —epss 0.00
The catopen function in FreeBSD 5.0 and earlier, and possibly other OSes, allows local users to read arbitrary files via the LANG environmental variable.
- CVE-2000-0852Nov 14, 2000risk 0.00cvss —epss 0.00
Multiple buffer overflows in eject on FreeBSD and possibly other OSes allows local users to gain root privileges.
- CVE-2000-0749Oct 20, 2000risk 0.00cvss —epss 0.00
Buffer overflow in the Linux binary compatibility module in FreeBSD 3.x through 5.x allows local users to gain root privileges via long filenames in the linux shadow file system.
- CVE-2000-0729Oct 20, 2000risk 0.00cvss —epss 0.00
FreeBSD 5.x, 4.x, and 3.x allows local users to cause a denial of service by executing a program with a malformed ELF image header.
- CVE-2000-0752Oct 20, 2000risk 0.00cvss —epss 0.00
Buffer overflows in brouted in FreeBSD and possibly other OSes allows local users to gain root privileges via long command line arguments.
- CVE-1999-0761Sep 16, 2000risk 0.00cvss —epss 0.00
Buffer overflow in FreeBSD fts library routines allows local user to modify arbitrary files via the periodic program.
- CVE-2000-0595Jul 5, 2000risk 0.00cvss —epss 0.01
libedit searches for the .editrc file in the current directory instead of the user's home directory, which may allow local users to execute arbitrary commands by installing a modified .editrc in another directory.
- CVE-2000-0535Jun 12, 2000risk 0.00cvss —epss 0.01
OpenSSL 0.9.4 and OpenSSH for FreeBSD do not properly check for the existence of the /dev/random or /dev/urandom devices, which are absent on FreeBSD Alpha systems, which causes them to produce weak keys which may be more easily broken.
- CVE-2000-0532Jun 7, 2000risk 0.00cvss —epss 0.02
A FreeBSD patch for SSH on 2000-01-14 configures ssh to listen on port 722 as well as port 22, which might allow remote attackers to access SSH through port 722 even if port 22 is otherwise filtered.
- CVE-2000-0461May 29, 2000risk 0.00cvss —epss 0.00
The undocumented semconfig system call in BSD freezes the state of semaphores, which allows local users to cause a denial of service of the semaphore system by using the semconfig call.
- CVE-2000-0235Mar 27, 2000risk 0.00cvss —epss 0.00
Buffer overflow in the huh program in the orville-write package allows local users to gain root privileges.
- CVE-2000-0186Feb 28, 2000risk 0.00cvss —epss 0.00
Buffer overflow in the dump utility in the Linux ext2fs backup package allows local users to gain privileges via a long command line argument.
- CVE-2000-0092Jan 19, 2000risk 0.00cvss —epss 0.00
The BSD make program allows local users to modify files via a symlink attack when the -j option is being used.
- CVE-1999-0964Jan 1, 2000risk 0.00cvss —epss 0.00
Buffer overflow in FreeBSD setlocale in the libc module allows attackers to execute arbitrary code via a long PATH_LOCALE environment variable.
- CVE-1999-1339Dec 31, 1999risk 0.00cvss —epss 0.03
Vulnerability when Network Address Translation (NAT) is enabled in Linux 2.2.10 and earlier with ipchains, or FreeBSD 3.2 with ipfw, allows remote attackers to cause a denial of service (kernel panic) via a ping -R (record route) command.
- CVE-1999-0001Dec 30, 1999risk 0.00cvss —epss 0.03
ip_input.c in BSD-derived TCP/IP implementations allows remote attackers to cause a denial of service (crash or hang) via crafted packets.
Page 26 of 28