FreeBSD
by FreeBSD
Source repositories
CVEs (547)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-1999-0796 | 0.00 | — | 0.01 | May 1, 1998 | FreeBSD T/TCP Extensions for Transactions can be subjected to spoofing attacks. | |||
| CVE-1999-0323 | 0.00 | — | 0.01 | Feb 20, 1998 | FreeBSD mmap function allows users to modify append-only or immutable files. | |||
| CVE-1999-0304 | 0.00 | — | 0.00 | Feb 1, 1998 | mmap function in BSD allows local attackers in the kmem group to modify memory through devices. | |||
| CVE-1999-0305 | 0.00 | — | 0.01 | Feb 1, 1998 | The system configuration control (sysctl) facility in BSD based operating systems OpenBSD 2.2 and earlier, and FreeBSD 2.2.5 and earlier, does not properly restrict source routed packets even when the (1) dosourceroute or (2) forwarding variables are set, which allows remote… | |||
| CVE-1999-0017 | 0.00 | — | 0.02 | Dec 10, 1997 | FTP servers can allow an attacker to connect to arbitrary ports on machines other than the FTP client, aka FTP bounce. | |||
| CVE-1999-0322 | 0.00 | — | 0.00 | Oct 29, 1997 | The open() function in FreeBSD allows local attackers to write to arbitrary files. | |||
| CVE-1999-0061 | 0.00 | — | 0.02 | Oct 2, 1997 | File creation and deletion, and remote execution, in the BSD line printer daemon (lpd). | |||
| CVE-1999-1214 | 0.00 | — | 0.00 | Sep 15, 1997 | The asynchronous I/O facility in 4.4 BSD kernel does not check user credentials when setting the recipient of I/O notification, which allows local users to cause a denial of service by using certain ioctl and fcntl calls to cause the signal to be sent to an arbitrary process ID. | |||
| CVE-1999-0628 | 0.00 | — | 0.01 | Jul 1, 1997 | The rwho/rwhod service is running, which exposes machine status and user information. | |||
| CVE-1999-0037 | 0.00 | — | 0.04 | May 21, 1997 | Arbitrary command execution via metamail package using message headers, when user processes attacker's message using metamail. | |||
| CVE-1999-1298 | 0.00 | — | 0.01 | Apr 7, 1997 | Sysinstall in FreeBSD 2.2.1 and earlier, when configuring anonymous FTP, creates the ftp user without a password and with /bin/date as the shell, which could allow attackers to gain access to certain system resources. | |||
| CVE-1999-0299 | 0.00 | — | 0.01 | Mar 5, 1997 | Buffer overflow in FreeBSD lpd through long DNS hostnames. | |||
| CVE-1999-0345 | 0.00 | — | 0.01 | Jan 1, 1997 | Jolt ICMP attack causes a denial of service in Windows 95 and Windows NT systems. | |||
| CVE-1999-1385 | 0.00 | — | 0.00 | Dec 19, 1996 | Buffer overflow in ppp program in FreeBSD 2.1 and earlier allows local users to gain privileges via a long HOME environment variable. | |||
| CVE-1999-0297 | 0.00 | — | 0.00 | Dec 12, 1996 | Buffer overflow in Vixie Cron library up to version 3.0 allows local users to obtain root access via a long environmental variable. | |||
| CVE-1999-0096 | 0.00 | — | 0.01 | Dec 10, 1996 | Sendmail decode alias can be used to overwrite sensitive files. | |||
| CVE-1999-0129 | 0.00 | — | 0.01 | Dec 3, 1996 | Sendmail allows local users to write to a file and gain group permissions via a .forward or :include: file. | |||
| CVE-1999-0131 | 0.00 | — | 0.01 | Sep 11, 1996 | Buffer overflow and denial of service in Sendmail 8.7.5 and earlier through GECOS field gives root access to local users. | |||
| CVE-1999-1187 | 0.00 | — | 0.00 | Aug 26, 1996 | Pine before version 3.94 allows local users to gain privileges via a symlink attack on a lockfile that is created when a user receives new mail. | |||
| CVE-1999-0085 | 0.00 | — | 0.04 | Aug 21, 1996 | Buffer overflow in rwhod on AIX and other operating systems allows remote attackers to execute arbitrary code via a UDP packet with a long hostname. |
- CVE-1999-0796May 1, 1998risk 0.00cvss —epss 0.01
FreeBSD T/TCP Extensions for Transactions can be subjected to spoofing attacks.
- CVE-1999-0323Feb 20, 1998risk 0.00cvss —epss 0.01
FreeBSD mmap function allows users to modify append-only or immutable files.
- CVE-1999-0304Feb 1, 1998risk 0.00cvss —epss 0.00
mmap function in BSD allows local attackers in the kmem group to modify memory through devices.
- CVE-1999-0305Feb 1, 1998risk 0.00cvss —epss 0.01
The system configuration control (sysctl) facility in BSD based operating systems OpenBSD 2.2 and earlier, and FreeBSD 2.2.5 and earlier, does not properly restrict source routed packets even when the (1) dosourceroute or (2) forwarding variables are set, which allows remote…
- CVE-1999-0017Dec 10, 1997risk 0.00cvss —epss 0.02
FTP servers can allow an attacker to connect to arbitrary ports on machines other than the FTP client, aka FTP bounce.
- CVE-1999-0322Oct 29, 1997risk 0.00cvss —epss 0.00
The open() function in FreeBSD allows local attackers to write to arbitrary files.
- CVE-1999-0061Oct 2, 1997risk 0.00cvss —epss 0.02
File creation and deletion, and remote execution, in the BSD line printer daemon (lpd).
- CVE-1999-1214Sep 15, 1997risk 0.00cvss —epss 0.00
The asynchronous I/O facility in 4.4 BSD kernel does not check user credentials when setting the recipient of I/O notification, which allows local users to cause a denial of service by using certain ioctl and fcntl calls to cause the signal to be sent to an arbitrary process ID.
- CVE-1999-0628Jul 1, 1997risk 0.00cvss —epss 0.01
The rwho/rwhod service is running, which exposes machine status and user information.
- CVE-1999-0037May 21, 1997risk 0.00cvss —epss 0.04
Arbitrary command execution via metamail package using message headers, when user processes attacker's message using metamail.
- CVE-1999-1298Apr 7, 1997risk 0.00cvss —epss 0.01
Sysinstall in FreeBSD 2.2.1 and earlier, when configuring anonymous FTP, creates the ftp user without a password and with /bin/date as the shell, which could allow attackers to gain access to certain system resources.
- CVE-1999-0299Mar 5, 1997risk 0.00cvss —epss 0.01
Buffer overflow in FreeBSD lpd through long DNS hostnames.
- CVE-1999-0345Jan 1, 1997risk 0.00cvss —epss 0.01
Jolt ICMP attack causes a denial of service in Windows 95 and Windows NT systems.
- CVE-1999-1385Dec 19, 1996risk 0.00cvss —epss 0.00
Buffer overflow in ppp program in FreeBSD 2.1 and earlier allows local users to gain privileges via a long HOME environment variable.
- CVE-1999-0297Dec 12, 1996risk 0.00cvss —epss 0.00
Buffer overflow in Vixie Cron library up to version 3.0 allows local users to obtain root access via a long environmental variable.
- CVE-1999-0096Dec 10, 1996risk 0.00cvss —epss 0.01
Sendmail decode alias can be used to overwrite sensitive files.
- CVE-1999-0129Dec 3, 1996risk 0.00cvss —epss 0.01
Sendmail allows local users to write to a file and gain group permissions via a .forward or :include: file.
- CVE-1999-0131Sep 11, 1996risk 0.00cvss —epss 0.01
Buffer overflow and denial of service in Sendmail 8.7.5 and earlier through GECOS field gives root access to local users.
- CVE-1999-1187Aug 26, 1996risk 0.00cvss —epss 0.00
Pine before version 3.94 allows local users to gain privileges via a symlink attack on a lockfile that is created when a user receives new mail.
- CVE-1999-0085Aug 21, 1996risk 0.00cvss —epss 0.04
Buffer overflow in rwhod on AIX and other operating systems allows remote attackers to execute arbitrary code via a UDP packet with a long hostname.
Page 27 of 28