CVE-2002-0973
- EPSS 0.09%
- Published 24.09.2002 04:00:00
- Last modified 03.04.2025 01:03:51
Integer signedness error in several system calls for FreeBSD 4.6.1 RELEASE-p10 and earlier may allow attackers to access sensitive kernel memory via large negative values to the (1) accept, (2) getsockname, and (3) getpeername system calls, and the (...
CVE-2002-1125
- EPSS 0.21%
- Published 24.09.2002 04:00:00
- Last modified 03.04.2025 01:03:51
FreeBSD port programs that use libkvm for FreeBSD 4.6.2-RELEASE and earlier, including (1) asmon, (2) ascpu, (3) bubblemon, (4) wmmon, and (5) wmnet2, leave open file descriptors for /dev/mem and /dev/kmem, which allows local users to read kernel mem...
- EPSS 7.42%
- Published 12.08.2002 04:00:00
- Last modified 03.04.2025 01:03:51
Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, allows remote attackers to execute arbitrary code by passing a large number of arguments to xdr_array ...
CVE-2002-0414
- EPSS 0.74%
- Published 12.08.2002 04:00:00
- Last modified 03.04.2025 01:03:51
KAME-derived implementations of IPsec on NetBSD 1.5.2, FreeBSD 4.5, and other operating systems, does not properly consult the Security Policy Database (SPD), which could cause a Security Gateway (SG) that does not use Encapsulating Security Payload ...
- EPSS 1.11%
- Published 12.08.2002 04:00:00
- Last modified 03.04.2025 01:03:51
The SYN cache (syncache) and SYN cookie (syncookie) mechanism in FreeBSD 4.5 and earlier allows remote attackers to cause a denial of service (crash) (1) via a SYN packet that is accepted using syncookies that causes a null pointer to be referenced f...
CVE-2002-0754
- EPSS 0.15%
- Published 12.08.2002 04:00:00
- Last modified 03.04.2025 01:03:51
Kerberos 5 su (k5su) in FreeBSD 4.4 and earlier relies on the getlogin system call to determine if the user running k5su is root, which could allow a root-initiated process to regain its privileges after it has dropped them.
CVE-2002-0755
- EPSS 0.07%
- Published 12.08.2002 04:00:00
- Last modified 03.04.2025 01:03:51
Kerberos 5 su (k5su) in FreeBSD 4.5 and earlier does not verify that a user is a member of the wheel group before granting superuser privileges, which could allow unauthorized users to execute commands as root.
- EPSS 0.9%
- Published 12.08.2002 04:00:00
- Last modified 03.04.2025 01:03:51
The accept_filter mechanism in FreeBSD 4 through 4.5 does not properly remove entries from the incomplete listen queue when adding a syncache, which allows remote attackers to cause a denial of service (network service availability) via a large numbe...
CVE-2002-0795
- EPSS 0.1%
- Published 12.08.2002 04:00:00
- Last modified 03.04.2025 01:03:51
The rc system startup script for FreeBSD 4 through 4.5 allows local users to delete arbitrary files via a symlink attack on X Windows lock files.
CVE-2002-0820
- EPSS 0.05%
- Published 12.08.2002 04:00:00
- Last modified 03.04.2025 01:03:51
FreeBSD kernel 4.6 and earlier closes the file descriptors 0, 1, and 2 after they have already been assigned to /dev/null when the descriptors reference procfs or linprocfs, which could allow local users to reuse the file descriptors in a setuid or s...