CVE-2014-3001
- EPSS 0.29%
- Veröffentlicht 02.05.2014 14:55:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
The device file system (aka devfs) in FreeBSD 10.0 before p2 does not load default rulesets when booting, which allows context-dependent attackers to bypass intended restrictions by leveraging a jailed device node process.
- EPSS 1.18%
- Veröffentlicht 16.04.2014 18:37:13
- Zuletzt bearbeitet 12.04.2025 10:46:40
The NFS server (nfsserver) in FreeBSD 8.3 through 10.0 does not acquire locks in the proper order when converting a directory file handle to a vnode, which allows remote authenticated users to cause a denial of service (deadlock) via vectors involvin...
CVE-2014-1452
- EPSS 0.62%
- Veröffentlicht 21.01.2014 15:17:12
- Zuletzt bearbeitet 11.04.2025 00:51:21
Stack-based buffer overflow in lib/snmpagent.c in bsnmpd, as used in FreeBSD 8.3 through 10.0, allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via a crafted GETBULK PDU request.
CVE-2013-6832
- EPSS 0.06%
- Veröffentlicht 21.11.2013 04:40:59
- Zuletzt bearbeitet 11.04.2025 00:51:21
The nand_ioctl function in sys/dev/nand/nand_geom.c in the nand driver in the kernel in FreeBSD 10 and earlier does not properly initialize a certain data structure, which allows local users to obtain sensitive information from kernel memory via a cr...
CVE-2013-6833
- EPSS 0.06%
- Veröffentlicht 21.11.2013 04:40:59
- Zuletzt bearbeitet 11.04.2025 00:51:21
The qls_eioctl function in sys/dev/qlxge/qls_ioctl.c in the kernel in FreeBSD 10 and earlier does not validate a certain size parameter, which allows local users to obtain sensitive information from kernel memory via a crafted ioctl call.
CVE-2013-6834
- EPSS 0.06%
- Veröffentlicht 21.11.2013 04:40:59
- Zuletzt bearbeitet 11.04.2025 00:51:21
The ql_eioctl function in sys/dev/qlxgbe/ql_ioctl.c in the kernel in FreeBSD 10 and earlier does not validate a certain size parameter, which allows local users to obtain sensitive information from kernel memory via a crafted ioctl call.
- EPSS 1.2%
- Veröffentlicht 30.09.2013 22:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
Integer signedness error in the archive_write_zip_data function in archive_write_set_format_zip.c in libarchive 3.1.2 and earlier, when running on 64-bit machines, allows context-dependent attackers to cause a denial of service (crash) via unspecifie...
CVE-2013-5666
- EPSS 0.07%
- Veröffentlicht 23.09.2013 20:55:07
- Zuletzt bearbeitet 11.04.2025 00:51:21
The sendfile system-call implementation in sys/kern/uipc_syscalls.c in the kernel in FreeBSD 9.2-RC1 and 9.2-RC2 does not properly pad transmissions, which allows local users to obtain sensitive information (kernel memory) via a length greater than t...
CVE-2013-5710
- EPSS 0.05%
- Veröffentlicht 23.09.2013 20:55:07
- Zuletzt bearbeitet 11.04.2025 00:51:21
The nullfs implementation in sys/fs/nullfs/null_vnops.c in the kernel in FreeBSD 8.3 through 9.2 allows local users with certain permissions to bypass access restrictions via a hardlink in a nullfs instance to a file in a different instance.
CVE-2013-5691
- EPSS 0.06%
- Veröffentlicht 23.09.2013 10:18:59
- Zuletzt bearbeitet 11.04.2025 00:51:21
The (1) IPv6 and (2) ATM ioctl request handlers in the kernel in FreeBSD 8.3 through 9.2-STABLE do not validate SIOCSIFADDR, SIOCSIFBRDADDR, SIOCSIFDSTADDR, and SIOCSIFNETMASK requests, which allows local users to perform link-layer actions, cause a ...