CVE-2016-1881
- EPSS 0.04%
- Veröffentlicht 15.02.2017 15:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The kernel in FreeBSD 9.3, 10.1, and 10.2 allows local users to cause a denial of service (crash) or potentially gain privilege via a crafted Linux compatibility layer setgroups system call.
CVE-2016-1883
- EPSS 0.04%
- Veröffentlicht 15.02.2017 15:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The issetugid system call in the Linux compatibility layer in FreeBSD 9.3, 10.1, and 10.2 allows local users to gain privilege via unspecified vectors.
CVE-2016-1888
- EPSS 1.76%
- Veröffentlicht 15.02.2017 15:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The telnetd service in FreeBSD 9.3, 10.1, 10.2, 10.3, and 11.0 allows remote attackers to inject arguments to login and bypass authentication via vectors involving a "sequence of memory allocation failures."
CVE-2016-1889
- EPSS 0.04%
- Veröffentlicht 15.02.2017 15:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Integer overflow in the bhyve hypervisor in FreeBSD 10.1, 10.2, 10.3, and 11.0 when configured with a large amount of guest memory, allows local users to gain privilege via a crafted device descriptor.
CVE-2015-5677
- EPSS 0.09%
- Veröffentlicht 07.02.2017 15:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
bsnmpd, as used in FreeBSD 9.3, 10.1, and 10.2, uses world-readable permissions on the snmpd.config file, which allows local users to obtain the secret key for USM authentication by reading the file.
CVE-2016-2518
- EPSS 0.79%
- Veröffentlicht 30.01.2017 21:59:01
- Zuletzt bearbeitet 20.04.2025 01:37:25
The MATCH_ASSOC function in NTP before version 4.2.8p9 and 4.3.x before 4.3.92 allows remote attackers to cause an out-of-bounds reference via an addpeer request with a large hmode value.
CVE-2015-7973
- EPSS 4.59%
- Veröffentlicht 30.01.2017 21:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
NTP before 4.2.8p6 and 4.3.x before 4.3.90, when configured in broadcast mode, allows man-in-the-middle attackers to conduct replay attacks by sniffing the network.
CVE-2015-7977
- EPSS 9.71%
- Veröffentlicht 30.01.2017 21:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
ntpd in NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to cause a denial of service (NULL pointer dereference) via a ntpdc reslist command.
CVE-2016-5766
- EPSS 15.27%
- Veröffentlicht 07.08.2016 10:59:13
- Zuletzt bearbeitet 12.04.2025 10:46:40
Integer overflow in the _gd2GetHeader function in gd_gd2.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8, allows remote attackers to cause a denial of service (heap-based ...
CVE-2016-1887
- EPSS 0.38%
- Veröffentlicht 25.05.2016 15:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
Integer signedness error in the sockargs function in sys/kern/uipc_syscalls.c in FreeBSD 10.1 before p34, 10.2 before p17, and 10.3 before p3 allows local users to cause a denial of service (memory overwrite and kernel panic) or gain privileges via a...