Freebsd

Freebsd

503 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 4.59%
  • Veröffentlicht 30.01.2017 21:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

NTP before 4.2.8p6 and 4.3.x before 4.3.90, when configured in broadcast mode, allows man-in-the-middle attackers to conduct replay attacks by sniffing the network.

  • EPSS 9.71%
  • Veröffentlicht 30.01.2017 21:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

ntpd in NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to cause a denial of service (NULL pointer dereference) via a ntpdc reslist command.

Exploit
  • EPSS 15.27%
  • Veröffentlicht 07.08.2016 10:59:13
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Integer overflow in the _gd2GetHeader function in gd_gd2.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8, allows remote attackers to cause a denial of service (heap-based ...

Exploit
  • EPSS 0.38%
  • Veröffentlicht 25.05.2016 15:59:03
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Integer signedness error in the sockargs function in sys/kern/uipc_syscalls.c in FreeBSD 10.1 before p34, 10.2 before p17, and 10.3 before p3 allows local users to cause a denial of service (memory overwrite and kernel panic) or gain privileges via a...

Exploit
  • EPSS 0.22%
  • Veröffentlicht 25.05.2016 15:59:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Integer signedness error in the genkbd_commonioctl function in sys/dev/kbd/kbd.c in FreeBSD 9.3 before p42, 10.1 before p34, 10.2 before p17, and 10.3 before p3 allows local users to obtain sensitive information from kernel memory, cause a denial of ...

Exploit
  • EPSS 0.15%
  • Veröffentlicht 12.04.2016 02:00:06
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Integer signedness error in the amd64_set_ldt function in sys/amd64/amd64/sys_machdep.c in FreeBSD 9.3 before p39, 10.1 before p31, and 10.2 before p14 allows local users to cause a denial of service (kernel panic) via an i386_set_ldt system call, wh...

  • EPSS 0.47%
  • Veröffentlicht 29.01.2016 19:59:08
  • Zuletzt bearbeitet 12.04.2025 10:46:40

FreeBSD 9.3 before p33, 10.1 before p26, and 10.2 before p9 allow remote attackers to cause a denial of service (kernel crash) via vectors related to creating a TCP connection with the TCP_MD5SIG and TCP_NOOPT socket options.

  • EPSS 19.79%
  • Veröffentlicht 29.01.2016 19:59:07
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The Stream Control Transmission Protocol (SCTP) module in FreeBSD 9.3 before p33, 10.1 before p26, and 10.2 before p9, when the kernel is configured for IPv6, allows remote attackers to cause a denial of service (assertion failure or NULL pointer der...

  • EPSS 0.11%
  • Veröffentlicht 18.09.2015 10:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The __sflush function in fflush.c in stdio in libc in FreeBSD 10.1 and the kernel in Apple iOS before 9 mishandles failures of the write system call, which allows context-dependent attackers to execute arbitrary code or cause a denial of service (hea...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 10.04.2015 15:00:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The bsdinstall installer in FreeBSD 10.x before 10.1 p9, when configuring full disk encrypted ZFS, uses world-readable permissions for the GELI keyfile (/boot/encryption.key), which allows local users to obtain sensitive key information by reading th...