VYPR

Vendor CVEs

FreeBSD

All CVEs

619 total · sorted by risk
  • CVE-1999-0628Jul 1, 1997
    risk 0.00cvss —epss 0.01

    The rwho/rwhod service is running, which exposes machine status and user information.

  • CVE-1999-0037May 21, 1997
    risk 0.00cvss —epss 0.04

    Arbitrary command execution via metamail package using message headers, when user processes attacker's message using metamail.

  • CVE-1999-1298Apr 7, 1997
    risk 0.00cvss —epss 0.01

    Sysinstall in FreeBSD 2.2.1 and earlier, when configuring anonymous FTP, creates the ftp user without a password and with /bin/date as the shell, which could allow attackers to gain access to certain system resources.

  • CVE-1999-0299Mar 5, 1997
    risk 0.00cvss —epss 0.01

    Buffer overflow in FreeBSD lpd through long DNS hostnames.

  • CVE-1999-0345Jan 1, 1997
    risk 0.00cvss —epss 0.01

    Jolt ICMP attack causes a denial of service in Windows 95 and Windows NT systems.

  • CVE-1999-1385Dec 19, 1996
    risk 0.00cvss —epss 0.00

    Buffer overflow in ppp program in FreeBSD 2.1 and earlier allows local users to gain privileges via a long HOME environment variable.

  • CVE-1999-0297Dec 12, 1996
    risk 0.00cvss —epss 0.00

    Buffer overflow in Vixie Cron library up to version 3.0 allows local users to obtain root access via a long environmental variable.

  • CVE-1999-0096Dec 10, 1996
    risk 0.00cvss —epss 0.01

    Sendmail decode alias can be used to overwrite sensitive files.

  • CVE-1999-0129Dec 3, 1996
    risk 0.00cvss —epss 0.01

    Sendmail allows local users to write to a file and gain group permissions via a .forward or :include: file.

  • CVE-1999-0131Sep 11, 1996
    risk 0.00cvss —epss 0.01

    Buffer overflow and denial of service in Sendmail 8.7.5 and earlier through GECOS field gives root access to local users.

  • CVE-1999-1187Aug 26, 1996
    risk 0.00cvss —epss 0.00

    Pine before version 3.94 allows local users to gain privileges via a symlink attack on a lockfile that is created when a user receives new mail.

  • CVE-1999-0085Aug 21, 1996
    risk 0.00cvss —epss 0.04

    Buffer overflow in rwhod on AIX and other operating systems allows remote attackers to execute arbitrary code via a UDP packet with a long hostname.

  • CVE-1999-1572Jul 16, 1996
    risk 0.00cvss —epss 0.01

    cpio on FreeBSD 2.1.0, Debian GNU/Linux 3.0, and possibly other operating systems, uses a 0 umask when creating files using the -O (archive) or -F options, which creates the files with mode 0666 and allows local users to read or overwrite those files.

  • CVE-1999-1301Jul 16, 1996
    risk 0.00cvss —epss 0.01

    A design flaw in the Z-Modem protocol allows the remote sender of a file to execute arbitrary programs on the client, as implemented in rz in the rzsz module of FreeBSD before 2.1.5, and possibly other programs.

  • CVE-1999-0138Jun 26, 1996
    risk 0.00cvss —epss 0.01

    The suidperl and sperl program do not give up root privileges when changing UIDs back to the original users, allowing root access.

  • CVE-1999-1313May 23, 1996
    risk 0.00cvss —epss 0.00

    Manual page reader (man) in FreeBSD 2.2 and earlier allows local users to gain privileges via a sequence of commands.

  • CVE-1999-1314May 17, 1996
    risk 0.00cvss —epss 0.00

    Vulnerability in union file system in FreeBSD 2.2 and earlier, and possibly other operating systems, allows local users to cause a denial of service (system reload) via a series of certain mount_union commands.

  • CVE-1999-0078Apr 18, 1996
    risk 0.00cvss —epss 0.01

    pcnfsd (aka rpc.pcnfsd) allows local users to change file permissions, or execute arbitrary commands through arguments in the RPC call.

  • CVE-2000-0388May 9, 1990
    risk 0.00cvss —epss 0.02

    Buffer overflow in FreeBSD libmytinfo library allows local users to execute commands via a long TERMCAP environmental variable.

Page 13 of 13