CVE-2019-6111
- EPSS 60.04%
- Veröffentlicht 31.01.2019 18:29:00
- Zuletzt bearbeitet 21.11.2024 04:45:57
An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses which files/directories are sent to the client. However, the scp client only performs cursory validation of the object name returned...
CVE-2018-17161
- EPSS 1.96%
- Veröffentlicht 03.01.2019 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:53:59
In FreeBSD before 11.2-STABLE(r348229), 11.2-RELEASE-p7, 12.0-STABLE(r342228), and 12.0-RELEASE-p1, insufficient validation of network-provided data in bootpd may make it possible for a malicious attacker to craft a bootp packet which could cause a s...
- EPSS 0.79%
- Veröffentlicht 04.12.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:53:59
In FreeBSD before 11.2-STABLE(r341486) and 11.2-RELEASE-p6, insufficient bounds checking in one of the device models provided by bhyve can permit a guest operating system to overwrite memory in the bhyve host possibly permitting arbitrary code execut...
- EPSS 12.12%
- Veröffentlicht 04.12.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:53:58
In FreeBSD before 11.2-STABLE(r340854) and 11.2-RELEASE-p5, an integer overflow error when handling opcodes can cause memory corruption by sending a specially crafted NFSv4 request. Unprivileged remote users with access to the NFS server may be able ...
CVE-2018-17158
- EPSS 6.54%
- Veröffentlicht 04.12.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:53:59
In FreeBSD before 11.2-STABLE(r340854) and 11.2-RELEASE-p5, an integer overflow error can occur when handling the client address length field in an NFSv4 request. Unprivileged remote users with access to the NFS server can crash the system by sending...
CVE-2018-17159
- EPSS 6.54%
- Veröffentlicht 04.12.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:53:59
In FreeBSD before 11.2-STABLE(r340854) and 11.2-RELEASE-p5, the NFS server lacks a bounds check in the READDIRPLUS NFS request. Unprivileged remote users with access to the NFS server can cause a resource exhaustion by forcing the server to allocate ...
CVE-2018-17156
- EPSS 0.38%
- Veröffentlicht 28.11.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:53:58
In FreeBSD before 11.2-STABLE(r340268) and 11.2-RELEASE-p5, due to incorrectly accounting for padding on 64-bit platforms, a buffer underwrite could occur when constructing an ICMP reply packet when using a non-standard value for the net.inet.icmp.qu...
CVE-2018-6925
- EPSS 0.04%
- Veröffentlicht 28.09.2018 13:29:01
- Zuletzt bearbeitet 21.11.2024 04:11:26
In FreeBSD before 11.2-STABLE(r338986), 11.2-RELEASE-p4, 11.1-RELEASE-p15, 10.4-STABLE(r338985), and 10.4-RELEASE-p13, due to improper maintenance of IPv6 protocol control block flags through various failure paths, an unprivileged authenticated local...
CVE-2018-17154
- EPSS 0.04%
- Veröffentlicht 28.09.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:53:58
In FreeBSD before 11.2-STABLE(r338987), 11.2-RELEASE-p4, and 11.1-RELEASE-p15, due to insufficient memory checking in the freebsd4_getfsstat system call, a NULL pointer dereference can occur. Unprivileged authenticated local users may be able to caus...
CVE-2018-17155
- EPSS 0.05%
- Veröffentlicht 28.09.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:53:58
In FreeBSD before 11.2-STABLE(r338983), 11.2-RELEASE-p4, 11.1-RELEASE-p15, 10.4-STABLE(r338984), and 10.4-RELEASE-p13, due to insufficient initialization of memory copied to userland in the getcontext and swapcontext system calls, small amounts of ke...