- EPSS 0.86%
- Veröffentlicht 04.12.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:53:59
In FreeBSD before 11.2-STABLE(r341486) and 11.2-RELEASE-p6, insufficient bounds checking in one of the device models provided by bhyve can permit a guest operating system to overwrite memory in the bhyve host possibly permitting arbitrary code execut...
- EPSS 12.18%
- Veröffentlicht 04.12.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:53:58
In FreeBSD before 11.2-STABLE(r340854) and 11.2-RELEASE-p5, an integer overflow error when handling opcodes can cause memory corruption by sending a specially crafted NFSv4 request. Unprivileged remote users with access to the NFS server may be able ...
CVE-2018-17158
- EPSS 4.47%
- Veröffentlicht 04.12.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:53:59
In FreeBSD before 11.2-STABLE(r340854) and 11.2-RELEASE-p5, an integer overflow error can occur when handling the client address length field in an NFSv4 request. Unprivileged remote users with access to the NFS server can crash the system by sending...
CVE-2018-17159
- EPSS 4.47%
- Veröffentlicht 04.12.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:53:59
In FreeBSD before 11.2-STABLE(r340854) and 11.2-RELEASE-p5, the NFS server lacks a bounds check in the READDIRPLUS NFS request. Unprivileged remote users with access to the NFS server can cause a resource exhaustion by forcing the server to allocate ...
CVE-2018-17156
- EPSS 0.38%
- Veröffentlicht 28.11.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:53:58
In FreeBSD before 11.2-STABLE(r340268) and 11.2-RELEASE-p5, due to incorrectly accounting for padding on 64-bit platforms, a buffer underwrite could occur when constructing an ICMP reply packet when using a non-standard value for the net.inet.icmp.qu...
CVE-2018-6925
- EPSS 0.04%
- Veröffentlicht 28.09.2018 13:29:01
- Zuletzt bearbeitet 21.11.2024 04:11:26
In FreeBSD before 11.2-STABLE(r338986), 11.2-RELEASE-p4, 11.1-RELEASE-p15, 10.4-STABLE(r338985), and 10.4-RELEASE-p13, due to improper maintenance of IPv6 protocol control block flags through various failure paths, an unprivileged authenticated local...
CVE-2018-17154
- EPSS 0.04%
- Veröffentlicht 28.09.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:53:58
In FreeBSD before 11.2-STABLE(r338987), 11.2-RELEASE-p4, and 11.1-RELEASE-p15, due to insufficient memory checking in the freebsd4_getfsstat system call, a NULL pointer dereference can occur. Unprivileged authenticated local users may be able to caus...
CVE-2018-17155
- EPSS 0.05%
- Veröffentlicht 28.09.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:53:58
In FreeBSD before 11.2-STABLE(r338983), 11.2-RELEASE-p4, 11.1-RELEASE-p15, 10.4-STABLE(r338984), and 10.4-RELEASE-p13, due to insufficient initialization of memory copied to userland in the getcontext and swapcontext system calls, small amounts of ke...
CVE-2018-6924
- EPSS 0.06%
- Veröffentlicht 12.09.2018 14:29:01
- Zuletzt bearbeitet 21.11.2024 04:11:26
In FreeBSD before 11.1-STABLE, 11.2-RELEASE-p3, 11.1-RELEASE-p14, 10.4-STABLE, and 10.4-RELEASE-p12, insufficient validation in the ELF header parser could allow a malicious ELF binary to cause a kernel crash or disclose kernel memory.
CVE-2017-1082
- EPSS 0.54%
- Veröffentlicht 12.09.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:21:18
In FreeBSD 11.x before 11.1-RELEASE and 10.x before 10.4-RELEASE, the qsort algorithm has a deterministic recursion pattern. Feeding a pathological input to the algorithm can lead to excessive stack usage and potential overflow. Applications that use...