Vendor CVEs
FreeBSD
All CVEs
619 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2013-4854 | 0.03 | — | 0.34 | Jul 29, 2013 | The RFC 5011 implementation in rdata.c in ISC BIND 9.7.x and 9.8.x before 9.8.5-P2, 9.8.6b1, 9.9.x before 9.9.3-P2, and 9.9.4b1, and DNSco BIND 9.9.3-S1 before 9.9.3-S1-P1 and 9.9.4-S1b1, allows remote attackers to cause a denial of service (assertion failure and named daemon… | |||
| CVE-2011-4122 | 0.03 | — | 0.01 | Nov 17, 2011 | Directory traversal vulnerability in openpam_configure.c in OpenPAM before r478 on FreeBSD 8.1 allows local users to load arbitrary DSOs and gain privileges via a .. (dot dot) in the service_name argument to the pam_start function, as demonstrated by a .. in the -c option to… | |||
| CVE-2011-4062 | 0.03 | — | 0.01 | Oct 18, 2011 | Buffer overflow in the kernel in FreeBSD 7.3 through 9.0-RC1 allows local users to cause a denial of service (panic) or possibly gain privileges via a bind system call with a long pathname for a UNIX socket. | |||
| CVE-2010-2693 | 0.03 | — | 0.01 | Jul 13, 2010 | FreeBSD 7.1 through 8.1-PRERELEASE does not copy the read-only flag when creating a duplicate mbuf buffer reference, which allows local users to cause a denial of service (system file corruption) and gain privileges via the sendfile system call. | |||
| CVE-2010-2020 | 0.03 | — | 0.01 | May 28, 2010 | sys/nfsclient/nfs_vfsops.c in the NFS client in the kernel in FreeBSD 7.2 through 8.1-PRERELEASE, when vfs.usermount is enabled, does not validate the length of a certain fhsize parameter, which allows local users to gain privileges via a crafted mount request. | |||
| CVE-2009-4147 | 0.03 | — | 0.04 | Dec 2, 2009 | The _rtld function in the Run-Time Link-Editor (rtld) in libexec/rtld-elf/rtld.c in FreeBSD 7.1 and 8.0 does not clear the (1) LD_LIBMAP, (2) LD_LIBRARY_PATH, (3) LD_LIBMAP_DISABLE, (4) LD_DEBUG, and (5) LD_ELF_HINTS_PATH environment variables, which allows local users to gain… | |||
| CVE-2009-4146 | 0.03 | — | 0.04 | Dec 2, 2009 | The _rtld function in the Run-Time Link-Editor (rtld) in libexec/rtld-elf/rtld.c in FreeBSD 7.1, 7.2, and 8.0 does not clear the LD_PRELOAD environment variable, which allows local users to gain privileges by executing a setuid or setguid program with a modified LD_PRELOAD… | |||
| CVE-2009-3527 | 0.03 | — | 0.01 | Oct 6, 2009 | Race condition in the Pipe (IPC) close function in FreeBSD 6.3 and 6.4 allows local users to cause a denial of service (crash) or gain privileges via vectors related to kqueues, which triggers a use after free, leading to a NULL pointer dereference or memory corruption. | |||
| CVE-2009-2649 | 0.03 | — | 0.01 | Jul 30, 2009 | The IATA (ata) driver in FreeBSD 6.0 and 8.0, when read access to /dev is available, allows local users to cause a denial of service (kernel panic) via a certain IOCTL request with a large count, which triggers a malloc call with a large value. | |||
| CVE-2009-1436 | 0.03 | — | 0.01 | Apr 27, 2009 | The db interface in libc in FreeBSD 6.3, 6.4, 7.0, 7.1, and 7.2-PRERELEASE does not properly initialize memory for Berkeley DB 1.85 database structures, which allows local users to obtain sensitive information by reading a database file. | |||
| CVE-2009-1041 | 0.03 | — | 0.01 | Mar 26, 2009 | The ktimer feature (sys/kern/kern_time.c) in FreeBSD 7.0, 7.1, and 7.2 allows local users to overwrite arbitrary kernel memory via an out-of-bounds timer value. | |||
| CVE-2008-5736 | 0.03 | — | 0.01 | Dec 26, 2008 | Multiple unspecified vulnerabilities in FreeBSD 6 before 6.4-STABLE, 6.3 before 6.3-RELEASE-p7, 6.4 before 6.4-RELEASE-p1, 7.0 before 7.0-RELEASE-p7, 7.1 before 7.1-RC2, and 7 before 7.1-PRERELEASE allow local users to gain privileges via unknown attack vectors related to… | |||
| CVE-2008-4609 | 0.03 | — | 0.32 | Oct 20, 2008 | The TCP implementation in (1) Linux, (2) platforms based on BSD Unix, (3) Microsoft Windows, (4) Cisco products, and probably other operating systems allows remote attackers to cause a denial of service (connection queue exhaustion) via multiple vectors that manipulate… | |||
| CVE-2008-4247 | 0.03 | — | 0.05 | Sep 25, 2008 | ftpd in OpenBSD 4.3, FreeBSD 7.0, NetBSD 4.0, Solaris, and possibly other operating systems interprets long commands from an FTP client as multiple commands, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and execute arbitrary FTP commands via… | |||
| CVE-2008-3531 | 0.03 | — | 0.01 | Sep 5, 2008 | Stack-based buffer overflow in sys/kern/vfs_mount.c in the kernel in FreeBSD 7.0 and 7.1, when vfs.usermount is enabled, allows local users to gain privileges via a crafted (1) mount or (2) nmount system call, related to copying of "user defined data" in "certain error… | |||
| CVE-2008-1215 | 0.03 | — | 0.01 | Mar 9, 2008 | Stack-based buffer overflow in the command_Expand_Interpret function in command.c in ppp (aka user-ppp), as distributed in FreeBSD 6.3 and 7.0, OpenBSD 4.1 and 4.2, and the net/userppp package for NetBSD, allows local users to gain privileges via long commands containing "~"… | |||
| CVE-2007-0267 | 0.03 | — | 0.01 | Jan 17, 2007 | The ufs_lookup function in the Mac OS X 10.4.8 and FreeBSD 6.1 kernels allows local users to cause a denial of service (kernel panic) and possibly corrupt other filesystems by mounting a crafted UNIX File System (UFS) DMG image that contains a corrupted directory entry (struct… | |||
| CVE-2007-0229 | 0.03 | — | 0.01 | Jan 13, 2007 | Integer overflow in the ffs_mountfs function in Mac OS X 10.4.8 and FreeBSD 6.1 allows local users to cause a denial of service (panic) and possibly gain privileges via a crafted DMG image that causes "allocation of a negative size buffer" leading to a heap-based buffer… | |||
| CVE-2006-5550 | 0.03 | — | 0.01 | Oct 26, 2006 | The kernel in FreeBSD 6.1 and OpenBSD 4.0 allows local users to cause a denial of service via unspecified vectors involving certain ioctl requests to /dev/crypto. | |||
| CVE-2006-5482 | 0.03 | — | 0.01 | Oct 24, 2006 | ufs_vnops.c in FreeBSD 6.1 allows local users to cause an unspecified denial of service by calling the ftruncate function on a file type that is not VREG, VLNK or VDIR, which is not defined in POSIX. | |||
| CVE-2006-5483 | 0.03 | — | 0.01 | Oct 24, 2006 | p1003_1b.c in FreeBSD 6.1 allows local users to cause an unspecified denial of service by setting a scheduler policy, which should only be settable by root. | |||
| CVE-2006-4516 | 0.03 | — | 0.01 | Oct 12, 2006 | Integer signedness error in FreeBSD 6.0-RELEASE allows local users to cause a denial of service (memory corruption and kernel panic) via a PT_LWPINFO ptrace command with a large negative data value that satisfies a signed maximum value check but is used in an unsigned copyout… | |||
| CVE-2006-4178 | 0.03 | — | 0.01 | Sep 26, 2006 | Integer signedness error in the i386_set_ldt call in FreeBSD 5.5, and possibly earlier versions down to 5.2, allows local users to cause a denial of service (crash) via unspecified arguments that use negative signed integers to cause the bzero function to be called with a large… | |||
| CVE-2004-2012 | 0.03 | — | 0.01 | Dec 31, 2004 | The systrace_exit function in the systrace utility for NetBSD-current and 2.0 before April 16, 2004, and certain FreeBSD ports, does not verify the owner of the /dec/systrace connection before setting euid to 0, which allows local users to gain root privileges. | |||
| CVE-2004-0618 | 0.03 | — | 0.01 | Dec 6, 2004 | FreeBSD 5.1 for the Alpha processor allows local users to cause a denial of service (crash) via an execve system call with an unaligned memory address as an argument. | |||
| CVE-2004-0114 | 0.03 | — | 0.01 | Mar 3, 2004 | The shmat system call in the System V Shared Memory interface for FreeBSD 5.2 and earlier, NetBSD 1.3 and earlier, and OpenBSD 2.6 and earlier, does not properly decrement a shared memory segment's reference count when the vm_map_find function fails, which could allow local… | |||
| CVE-2003-0144 | 0.03 | — | 0.02 | Mar 31, 2003 | Buffer overflow in the lprm command in the lprold lpr package on SuSE 7.1 through 7.3, OpenBSD 3.2 and earlier, and possibly other operating systems, allows local users to gain root privileges via long command line arguments such as (1) request ID or (2) user name. | |||
| CVE-2002-1125 | 0.03 | — | 0.01 | Sep 24, 2002 | FreeBSD port programs that use libkvm for FreeBSD 4.6.2-RELEASE and earlier, including (1) asmon, (2) ascpu, (3) bubblemon, (4) wmmon, and (5) wmnet2, leave open file descriptors for /dev/mem and /dev/kmem, which allows local users to read kernel memory. | |||
| CVE-2002-0824 | 0.03 | — | 0.01 | Aug 12, 2002 | BSD pppd allows local users to change the permissions of arbitrary files via a symlink attack on a file that is specified as a tty device. | |||
| CVE-2002-0572 | 0.03 | — | 0.02 | Jul 3, 2002 | FreeBSD 4.5 and earlier, and possibly other BSD-based operating systems, allows local users to write to or read from restricted files by closing the file descriptors 0 (standard input), 1 (standard output), or 2 (standard error), which may then be reused by a called setuid… | |||
| CVE-2002-0004 | 0.03 | — | 0.01 | Feb 27, 2002 | Heap corruption vulnerability in the "at" program allows local users to execute arbitrary code via a malformed execution time, which causes at to free the same memory twice. | |||
| CVE-2001-1185 | 0.03 | — | 0.01 | Dec 10, 2001 | Some AIO operations in FreeBSD 4.4 may be delayed until after a call to execve, which could allow a local user to overwrite memory of the new process and gain privileges. | |||
| CVE-2001-1029 | 0.03 | — | 0.01 | Sep 20, 2001 | libutil in OpenSSH on FreeBSD 4.4 and earlier does not drop privileges before verifying the capabilities for reading the copyright and welcome files, which allows local users to bypass the capabilities checks and read arbitrary files by specifying alternate copyright or welcome… | |||
| CVE-2001-0402 | 0.03 | — | 0.02 | Jun 18, 2001 | IPFilter 3.4.16 and earlier does not include sufficient session information in its cache, which allows remote attackers to bypass access restrictions by sending fragmented packets to a restricted port after sending unfragmented packets to an unrestricted port. | |||
| CVE-2001-0221 | 0.03 | — | 0.01 | Jun 2, 2001 | Buffer overflow in ja-xklock 2.7.1 and earlier allows local users to gain root privileges. | |||
| CVE-2001-0093 | 0.03 | — | 0.01 | Feb 12, 2001 | Vulnerability in telnetd in FreeBSD 1.5 allows local users to gain root privileges by modifying critical environmental variables that affect the behavior of telnetd. | |||
| CVE-2000-1096 | 0.03 | — | 0.01 | Jan 9, 2001 | crontab by Paul Vixie uses predictable file names for a temporary file and does not properly ensure that the file is owned by the user executing the crontab -e command, which allows local users with write access to the crontab spool directory to execute arbitrary commands by… | |||
| CVE-2000-0916 | 0.03 | — | 0.06 | Dec 19, 2000 | FreeBSD 4.1.1 and earlier, and possibly other BSD-based OSes, uses an insufficient random number generator to generate initial TCP sequence numbers (ISN), which allows remote attackers to spoof TCP connections. | |||
| CVE-2000-0993 | 0.03 | — | 0.02 | Dec 19, 2000 | Format string vulnerability in pw_error function in BSD libutil library allows local users to gain root privileges via a malformed password in commands such as chpass or passwd. | |||
| CVE-2000-0998 | 0.03 | — | 0.01 | Dec 11, 2000 | Format string vulnerability in top program allows local attackers to gain root privileges via the "kill" or "renice" function. | |||
| CVE-2000-0584 | 0.03 | — | 0.06 | Jul 2, 2000 | Buffer overflow in Canna input system allows remote attackers to execute arbitrary commands via an SR_INIT command with a long user name or group name. | |||
| CVE-1999-1008 | 0.03 | — | 0.01 | May 17, 2000 | xsoldier program allows local users to gain root access via a long argument. | |||
| CVE-2000-0440 | 0.03 | — | 0.03 | May 1, 2000 | NetBSD 1.4.2 and earlier allows remote attackers to cause a denial of service by sending a packet with an unaligned IP timestamp option. | |||
| CVE-2000-0163 | 0.03 | — | 0.01 | Feb 21, 2000 | asmon and ascpu in FreeBSD allow local users to gain root privileges via a configuration file. | |||
| CVE-1999-0823 | 0.03 | — | 0.01 | Dec 1, 1999 | Buffer overflow in FreeBSD xmindpath allows local users to gain privileges via -f argument. | |||
| CVE-1999-0857 | 0.03 | — | 0.01 | Dec 1, 1999 | FreeBSD gdc program allows local users to modify files via a symlink attack. | |||
| CVE-1999-0820 | 0.03 | — | 0.01 | Dec 1, 1999 | FreeBSD seyon allows users to gain privileges via a modified PATH variable for finding the xterm and seyon-emu commands. | |||
| CVE-1999-0826 | 0.03 | — | 0.01 | Dec 1, 1999 | Buffer overflow in FreeBSD angband allows local users to gain privileges. | |||
| CVE-1999-0855 | 0.03 | — | 0.01 | Dec 1, 1999 | Buffer overflow in FreeBSD gdc program. | |||
| CVE-1999-0821 | 0.03 | — | 0.01 | Nov 8, 1999 | FreeBSD seyon allows local users to gain privileges by providing a malicious program in the -emulator argument. |
- CVE-2013-4854Jul 29, 2013risk 0.03cvss —epss 0.34
The RFC 5011 implementation in rdata.c in ISC BIND 9.7.x and 9.8.x before 9.8.5-P2, 9.8.6b1, 9.9.x before 9.9.3-P2, and 9.9.4b1, and DNSco BIND 9.9.3-S1 before 9.9.3-S1-P1 and 9.9.4-S1b1, allows remote attackers to cause a denial of service (assertion failure and named daemon…
- CVE-2011-4122Nov 17, 2011risk 0.03cvss —epss 0.01
Directory traversal vulnerability in openpam_configure.c in OpenPAM before r478 on FreeBSD 8.1 allows local users to load arbitrary DSOs and gain privileges via a .. (dot dot) in the service_name argument to the pam_start function, as demonstrated by a .. in the -c option to…
- CVE-2011-4062Oct 18, 2011risk 0.03cvss —epss 0.01
Buffer overflow in the kernel in FreeBSD 7.3 through 9.0-RC1 allows local users to cause a denial of service (panic) or possibly gain privileges via a bind system call with a long pathname for a UNIX socket.
- CVE-2010-2693Jul 13, 2010risk 0.03cvss —epss 0.01
FreeBSD 7.1 through 8.1-PRERELEASE does not copy the read-only flag when creating a duplicate mbuf buffer reference, which allows local users to cause a denial of service (system file corruption) and gain privileges via the sendfile system call.
- CVE-2010-2020May 28, 2010risk 0.03cvss —epss 0.01
sys/nfsclient/nfs_vfsops.c in the NFS client in the kernel in FreeBSD 7.2 through 8.1-PRERELEASE, when vfs.usermount is enabled, does not validate the length of a certain fhsize parameter, which allows local users to gain privileges via a crafted mount request.
- CVE-2009-4147Dec 2, 2009risk 0.03cvss —epss 0.04
The _rtld function in the Run-Time Link-Editor (rtld) in libexec/rtld-elf/rtld.c in FreeBSD 7.1 and 8.0 does not clear the (1) LD_LIBMAP, (2) LD_LIBRARY_PATH, (3) LD_LIBMAP_DISABLE, (4) LD_DEBUG, and (5) LD_ELF_HINTS_PATH environment variables, which allows local users to gain…
- CVE-2009-4146Dec 2, 2009risk 0.03cvss —epss 0.04
The _rtld function in the Run-Time Link-Editor (rtld) in libexec/rtld-elf/rtld.c in FreeBSD 7.1, 7.2, and 8.0 does not clear the LD_PRELOAD environment variable, which allows local users to gain privileges by executing a setuid or setguid program with a modified LD_PRELOAD…
- CVE-2009-3527Oct 6, 2009risk 0.03cvss —epss 0.01
Race condition in the Pipe (IPC) close function in FreeBSD 6.3 and 6.4 allows local users to cause a denial of service (crash) or gain privileges via vectors related to kqueues, which triggers a use after free, leading to a NULL pointer dereference or memory corruption.
- CVE-2009-2649Jul 30, 2009risk 0.03cvss —epss 0.01
The IATA (ata) driver in FreeBSD 6.0 and 8.0, when read access to /dev is available, allows local users to cause a denial of service (kernel panic) via a certain IOCTL request with a large count, which triggers a malloc call with a large value.
- CVE-2009-1436Apr 27, 2009risk 0.03cvss —epss 0.01
The db interface in libc in FreeBSD 6.3, 6.4, 7.0, 7.1, and 7.2-PRERELEASE does not properly initialize memory for Berkeley DB 1.85 database structures, which allows local users to obtain sensitive information by reading a database file.
- CVE-2009-1041Mar 26, 2009risk 0.03cvss —epss 0.01
The ktimer feature (sys/kern/kern_time.c) in FreeBSD 7.0, 7.1, and 7.2 allows local users to overwrite arbitrary kernel memory via an out-of-bounds timer value.
- CVE-2008-5736Dec 26, 2008risk 0.03cvss —epss 0.01
Multiple unspecified vulnerabilities in FreeBSD 6 before 6.4-STABLE, 6.3 before 6.3-RELEASE-p7, 6.4 before 6.4-RELEASE-p1, 7.0 before 7.0-RELEASE-p7, 7.1 before 7.1-RC2, and 7 before 7.1-PRERELEASE allow local users to gain privileges via unknown attack vectors related to…
- CVE-2008-4609Oct 20, 2008risk 0.03cvss —epss 0.32
The TCP implementation in (1) Linux, (2) platforms based on BSD Unix, (3) Microsoft Windows, (4) Cisco products, and probably other operating systems allows remote attackers to cause a denial of service (connection queue exhaustion) via multiple vectors that manipulate…
- CVE-2008-4247Sep 25, 2008risk 0.03cvss —epss 0.05
ftpd in OpenBSD 4.3, FreeBSD 7.0, NetBSD 4.0, Solaris, and possibly other operating systems interprets long commands from an FTP client as multiple commands, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and execute arbitrary FTP commands via…
- CVE-2008-3531Sep 5, 2008risk 0.03cvss —epss 0.01
Stack-based buffer overflow in sys/kern/vfs_mount.c in the kernel in FreeBSD 7.0 and 7.1, when vfs.usermount is enabled, allows local users to gain privileges via a crafted (1) mount or (2) nmount system call, related to copying of "user defined data" in "certain error…
- CVE-2008-1215Mar 9, 2008risk 0.03cvss —epss 0.01
Stack-based buffer overflow in the command_Expand_Interpret function in command.c in ppp (aka user-ppp), as distributed in FreeBSD 6.3 and 7.0, OpenBSD 4.1 and 4.2, and the net/userppp package for NetBSD, allows local users to gain privileges via long commands containing "~"…
- CVE-2007-0267Jan 17, 2007risk 0.03cvss —epss 0.01
The ufs_lookup function in the Mac OS X 10.4.8 and FreeBSD 6.1 kernels allows local users to cause a denial of service (kernel panic) and possibly corrupt other filesystems by mounting a crafted UNIX File System (UFS) DMG image that contains a corrupted directory entry (struct…
- CVE-2007-0229Jan 13, 2007risk 0.03cvss —epss 0.01
Integer overflow in the ffs_mountfs function in Mac OS X 10.4.8 and FreeBSD 6.1 allows local users to cause a denial of service (panic) and possibly gain privileges via a crafted DMG image that causes "allocation of a negative size buffer" leading to a heap-based buffer…
- CVE-2006-5550Oct 26, 2006risk 0.03cvss —epss 0.01
The kernel in FreeBSD 6.1 and OpenBSD 4.0 allows local users to cause a denial of service via unspecified vectors involving certain ioctl requests to /dev/crypto.
- CVE-2006-5482Oct 24, 2006risk 0.03cvss —epss 0.01
ufs_vnops.c in FreeBSD 6.1 allows local users to cause an unspecified denial of service by calling the ftruncate function on a file type that is not VREG, VLNK or VDIR, which is not defined in POSIX.
- CVE-2006-5483Oct 24, 2006risk 0.03cvss —epss 0.01
p1003_1b.c in FreeBSD 6.1 allows local users to cause an unspecified denial of service by setting a scheduler policy, which should only be settable by root.
- CVE-2006-4516Oct 12, 2006risk 0.03cvss —epss 0.01
Integer signedness error in FreeBSD 6.0-RELEASE allows local users to cause a denial of service (memory corruption and kernel panic) via a PT_LWPINFO ptrace command with a large negative data value that satisfies a signed maximum value check but is used in an unsigned copyout…
- CVE-2006-4178Sep 26, 2006risk 0.03cvss —epss 0.01
Integer signedness error in the i386_set_ldt call in FreeBSD 5.5, and possibly earlier versions down to 5.2, allows local users to cause a denial of service (crash) via unspecified arguments that use negative signed integers to cause the bzero function to be called with a large…
- CVE-2004-2012Dec 31, 2004risk 0.03cvss —epss 0.01
The systrace_exit function in the systrace utility for NetBSD-current and 2.0 before April 16, 2004, and certain FreeBSD ports, does not verify the owner of the /dec/systrace connection before setting euid to 0, which allows local users to gain root privileges.
- CVE-2004-0618Dec 6, 2004risk 0.03cvss —epss 0.01
FreeBSD 5.1 for the Alpha processor allows local users to cause a denial of service (crash) via an execve system call with an unaligned memory address as an argument.
- CVE-2004-0114Mar 3, 2004risk 0.03cvss —epss 0.01
The shmat system call in the System V Shared Memory interface for FreeBSD 5.2 and earlier, NetBSD 1.3 and earlier, and OpenBSD 2.6 and earlier, does not properly decrement a shared memory segment's reference count when the vm_map_find function fails, which could allow local…
- CVE-2003-0144Mar 31, 2003risk 0.03cvss —epss 0.02
Buffer overflow in the lprm command in the lprold lpr package on SuSE 7.1 through 7.3, OpenBSD 3.2 and earlier, and possibly other operating systems, allows local users to gain root privileges via long command line arguments such as (1) request ID or (2) user name.
- CVE-2002-1125Sep 24, 2002risk 0.03cvss —epss 0.01
FreeBSD port programs that use libkvm for FreeBSD 4.6.2-RELEASE and earlier, including (1) asmon, (2) ascpu, (3) bubblemon, (4) wmmon, and (5) wmnet2, leave open file descriptors for /dev/mem and /dev/kmem, which allows local users to read kernel memory.
- CVE-2002-0824Aug 12, 2002risk 0.03cvss —epss 0.01
BSD pppd allows local users to change the permissions of arbitrary files via a symlink attack on a file that is specified as a tty device.
- CVE-2002-0572Jul 3, 2002risk 0.03cvss —epss 0.02
FreeBSD 4.5 and earlier, and possibly other BSD-based operating systems, allows local users to write to or read from restricted files by closing the file descriptors 0 (standard input), 1 (standard output), or 2 (standard error), which may then be reused by a called setuid…
- CVE-2002-0004Feb 27, 2002risk 0.03cvss —epss 0.01
Heap corruption vulnerability in the "at" program allows local users to execute arbitrary code via a malformed execution time, which causes at to free the same memory twice.
- CVE-2001-1185Dec 10, 2001risk 0.03cvss —epss 0.01
Some AIO operations in FreeBSD 4.4 may be delayed until after a call to execve, which could allow a local user to overwrite memory of the new process and gain privileges.
- CVE-2001-1029Sep 20, 2001risk 0.03cvss —epss 0.01
libutil in OpenSSH on FreeBSD 4.4 and earlier does not drop privileges before verifying the capabilities for reading the copyright and welcome files, which allows local users to bypass the capabilities checks and read arbitrary files by specifying alternate copyright or welcome…
- CVE-2001-0402Jun 18, 2001risk 0.03cvss —epss 0.02
IPFilter 3.4.16 and earlier does not include sufficient session information in its cache, which allows remote attackers to bypass access restrictions by sending fragmented packets to a restricted port after sending unfragmented packets to an unrestricted port.
- CVE-2001-0221Jun 2, 2001risk 0.03cvss —epss 0.01
Buffer overflow in ja-xklock 2.7.1 and earlier allows local users to gain root privileges.
- CVE-2001-0093Feb 12, 2001risk 0.03cvss —epss 0.01
Vulnerability in telnetd in FreeBSD 1.5 allows local users to gain root privileges by modifying critical environmental variables that affect the behavior of telnetd.
- CVE-2000-1096Jan 9, 2001risk 0.03cvss —epss 0.01
crontab by Paul Vixie uses predictable file names for a temporary file and does not properly ensure that the file is owned by the user executing the crontab -e command, which allows local users with write access to the crontab spool directory to execute arbitrary commands by…
- CVE-2000-0916Dec 19, 2000risk 0.03cvss —epss 0.06
FreeBSD 4.1.1 and earlier, and possibly other BSD-based OSes, uses an insufficient random number generator to generate initial TCP sequence numbers (ISN), which allows remote attackers to spoof TCP connections.
- CVE-2000-0993Dec 19, 2000risk 0.03cvss —epss 0.02
Format string vulnerability in pw_error function in BSD libutil library allows local users to gain root privileges via a malformed password in commands such as chpass or passwd.
- CVE-2000-0998Dec 11, 2000risk 0.03cvss —epss 0.01
Format string vulnerability in top program allows local attackers to gain root privileges via the "kill" or "renice" function.
- CVE-2000-0584Jul 2, 2000risk 0.03cvss —epss 0.06
Buffer overflow in Canna input system allows remote attackers to execute arbitrary commands via an SR_INIT command with a long user name or group name.
- CVE-1999-1008May 17, 2000risk 0.03cvss —epss 0.01
xsoldier program allows local users to gain root access via a long argument.
- CVE-2000-0440May 1, 2000risk 0.03cvss —epss 0.03
NetBSD 1.4.2 and earlier allows remote attackers to cause a denial of service by sending a packet with an unaligned IP timestamp option.
- CVE-2000-0163Feb 21, 2000risk 0.03cvss —epss 0.01
asmon and ascpu in FreeBSD allow local users to gain root privileges via a configuration file.
- CVE-1999-0823Dec 1, 1999risk 0.03cvss —epss 0.01
Buffer overflow in FreeBSD xmindpath allows local users to gain privileges via -f argument.
- CVE-1999-0857Dec 1, 1999risk 0.03cvss —epss 0.01
FreeBSD gdc program allows local users to modify files via a symlink attack.
- CVE-1999-0820Dec 1, 1999risk 0.03cvss —epss 0.01
FreeBSD seyon allows users to gain privileges via a modified PATH variable for finding the xterm and seyon-emu commands.
- CVE-1999-0826Dec 1, 1999risk 0.03cvss —epss 0.01
Buffer overflow in FreeBSD angband allows local users to gain privileges.
- CVE-1999-0855Dec 1, 1999risk 0.03cvss —epss 0.01
Buffer overflow in FreeBSD gdc program.
- CVE-1999-0821Nov 8, 1999risk 0.03cvss —epss 0.01
FreeBSD seyon allows local users to gain privileges by providing a malicious program in the -emulator argument.
Page 7 of 13