7.5

CVE-2015-1417

The inet module in FreeBSD 10.2x before 10.2-PRERELEASE, 10.2-BETA2-p2, 10.2-RC1-p1, 10.1x before 10.1-RELEASE-p16, 9.x before 9.3-STABLE, 9.3-RELEASE-p21, and 8.x before 8.4-STABLE, 8.4-RELEASE-p35 on systems with VNET enabled and at least 16 VNET instances allows remote attackers to cause a denial of service (mbuf consumption) via multiple concurrent TCP connections.

Data is provided by the National Vulnerability Database (NVD)
FreebsdFreebsd Version8.4 Update-
FreebsdFreebsd Version8.4 Updatebeta1
FreebsdFreebsd Version8.4 Updatep11
FreebsdFreebsd Version8.4 Updatep12
FreebsdFreebsd Version8.4 Updatep13
FreebsdFreebsd Version8.4 Updatep14
FreebsdFreebsd Version8.4 Updatep15
FreebsdFreebsd Version8.4 Updatep16
FreebsdFreebsd Version8.4 Updatep17
FreebsdFreebsd Version8.4 Updatep19
FreebsdFreebsd Version8.4 Updatep2
FreebsdFreebsd Version8.4 Updatep20
FreebsdFreebsd Version8.4 Updatep21
FreebsdFreebsd Version8.4 Updatep22
FreebsdFreebsd Version8.4 Updatep23
FreebsdFreebsd Version8.4 Updatep24
FreebsdFreebsd Version8.4 Updatep26
FreebsdFreebsd Version8.4 Updatep27
FreebsdFreebsd Version8.4 Updatep3
FreebsdFreebsd Version8.4 Updatep30
FreebsdFreebsd Version8.4 Updatep33
FreebsdFreebsd Version8.4 Updatep34
FreebsdFreebsd Version8.4 Updatep4
FreebsdFreebsd Version8.4 Updatep7
FreebsdFreebsd Version8.4 Updatep8
FreebsdFreebsd Version8.4 Updatep9
FreebsdFreebsd Version9.3 Update-
FreebsdFreebsd Version9.3 Updatep1
FreebsdFreebsd Version9.3 Updatep10
FreebsdFreebsd Version9.3 Updatep12
FreebsdFreebsd Version9.3 Updatep13
FreebsdFreebsd Version9.3 Updatep16
FreebsdFreebsd Version9.3 Updatep19
FreebsdFreebsd Version9.3 Updatep2
FreebsdFreebsd Version9.3 Updatep20
FreebsdFreebsd Version9.3 Updatep3
FreebsdFreebsd Version9.3 Updatep5
FreebsdFreebsd Version9.3 Updatep6
FreebsdFreebsd Version9.3 Updatep7
FreebsdFreebsd Version9.3 Updatep8
FreebsdFreebsd Version9.3 Updatep9
FreebsdFreebsd Version10.1 Update-
FreebsdFreebsd Version10.1 Updatep1
FreebsdFreebsd Version10.1 Updatep10
FreebsdFreebsd Version10.1 Updatep12
FreebsdFreebsd Version10.1 Updatep15
FreebsdFreebsd Version10.1 Updatep16
FreebsdFreebsd Version10.1 Updatep2
FreebsdFreebsd Version10.1 Updatep3
FreebsdFreebsd Version10.1 Updatep4
FreebsdFreebsd Version10.1 Updatep5
FreebsdFreebsd Version10.1 Updatep6
FreebsdFreebsd Version10.1 Updatep7
FreebsdFreebsd Version10.1 Updatep8
FreebsdFreebsd Version10.1 Updatep9
FreebsdFreebsd Version10.2 Update-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.4% 0.796
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-400 Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.