CVE-2023-3326
- EPSS 0.48%
- Veröffentlicht 22.06.2023 17:15:44
- Zuletzt bearbeitet 21.11.2024 08:17:01
pam_krb5 authenticates a user by essentially running kinit with the password, getting a ticket-granting ticket (tgt) from the Kerberos KDC (Key Distribution Center) over the network, as a way to verify the password. However, if a keytab is not provis...
CVE-2023-0751
- EPSS 0.32%
- Veröffentlicht 08.02.2023 20:15:24
- Zuletzt bearbeitet 25.03.2025 14:15:20
When GELI reads a key file from standard input, it does not reuse the key file to initialize multiple providers at once resulting in the second and subsequent devices silently using a NULL key as the user key file. If a user only uses a key file with...
CVE-2022-32264
- EPSS 0.54%
- Veröffentlicht 06.09.2022 18:15:15
- Zuletzt bearbeitet 17.06.2025 20:15:25
sys/netinet/tcp_timer.h in FreeBSD before 7.0 contains a denial-of-service (DoS) vulnerability due to improper handling of TSopt on TCP connections. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
CVE-2021-29632
- EPSS 0.32%
- Veröffentlicht 18.01.2022 17:15:08
- Zuletzt bearbeitet 21.11.2024 06:01:32
In FreeBSD 13.0-STABLE before n247428-9352de39c3dc, 12.2-STABLE before r370674, 13.0-RELEASE before p6, and 12.2-RELEASE before p12, certain conditions involving use of the highlight buffer while text is scrolling on the console, console data may ove...
CVE-2011-1075
- EPSS 0.2%
- Veröffentlicht 19.10.2021 15:15:07
- Zuletzt bearbeitet 21.11.2024 01:25:27
FreeBSD's crontab calculates the MD5 sum of the previous and new cronjob to determine if any changes have been made before copying the new version in. In particular, it uses the MD5File() function, which takes a pathname as an argument, and is called...
CVE-2021-29630
- EPSS 1.08%
- Veröffentlicht 30.08.2021 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:01:31
In FreeBSD 13.0-STABLE before n246938-0729ba2f49c9, 12.2-STABLE before r370383, 11.4-STABLE before r370381, 13.0-RELEASE before p4, 12.2-RELEASE before p10, and 11.4-RELEASE before p13, the ggatec daemon does not validate the size of a response befor...
CVE-2021-29631
- EPSS 0.05%
- Veröffentlicht 30.08.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 06:01:32
In FreeBSD 13.0-STABLE before n246941-20f96f215562, 12.2-STABLE before r370400, 11.4-STABLE before r370399, 13.0-RELEASE before p4, 12.2-RELEASE before p10, and 11.4-RELEASE before p13, certain VirtIO-based device models in bhyve failed to handle err...
CVE-2020-7469
- EPSS 0.54%
- Veröffentlicht 04.06.2021 12:15:07
- Zuletzt bearbeitet 21.11.2024 05:37:12
In FreeBSD 12.2-STABLE before r367402, 11.4-STABLE before r368202, 12.2-RELEASE before p1, 12.1-RELEASE before p11 and 11.4-RELEASE before p5 the handler for a routing option caches a pointer into the packet buffer holding the ICMPv6 message. However...
CVE-2021-29628
- EPSS 0.24%
- Veröffentlicht 28.05.2021 15:15:08
- Zuletzt bearbeitet 21.11.2024 06:01:31
In FreeBSD 13.0-STABLE before n245764-876ffe28796c, 12.2-STABLE before r369857, 13.0-RELEASE before p1, and 12.2-RELEASE before p7, a system call triggering a fault could cause SMAP protections to be disabled for the duration of the system call. This...
CVE-2021-29629
- EPSS 0.62%
- Veröffentlicht 28.05.2021 15:15:08
- Zuletzt bearbeitet 21.11.2024 06:01:31
In FreeBSD 13.0-STABLE before n245765-bec0d2c9c841, 12.2-STABLE before r369859, 11.4-STABLE before r369866, 13.0-RELEASE before p1, 12.2-RELEASE before p7, and 11.4-RELEASE before p10, missing message validation in libradius(3) could allow malicious ...