CVE-2016-1888
- EPSS 1.3%
- Veröffentlicht 15.02.2017 15:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The telnetd service in FreeBSD 9.3, 10.1, 10.2, 10.3, and 11.0 allows remote attackers to inject arguments to login and bypass authentication via vectors involving a "sequence of memory allocation failures."
CVE-2016-1889
- EPSS 0.04%
- Veröffentlicht 15.02.2017 15:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Integer overflow in the bhyve hypervisor in FreeBSD 10.1, 10.2, 10.3, and 11.0 when configured with a large amount of guest memory, allows local users to gain privilege via a crafted device descriptor.
CVE-2015-5677
- EPSS 0.09%
- Veröffentlicht 07.02.2017 15:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
bsnmpd, as used in FreeBSD 9.3, 10.1, and 10.2, uses world-readable permissions on the snmpd.config file, which allows local users to obtain the secret key for USM authentication by reading the file.
CVE-2016-2518
- EPSS 3.48%
- Veröffentlicht 30.01.2017 21:59:01
- Zuletzt bearbeitet 13.05.2026 00:24:29
The MATCH_ASSOC function in NTP before version 4.2.8p9 and 4.3.x before 4.3.92 allows remote attackers to cause an out-of-bounds reference via an addpeer request with a large hmode value.
CVE-2015-7973
- EPSS 8.6%
- Veröffentlicht 30.01.2017 21:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
NTP before 4.2.8p6 and 4.3.x before 4.3.90, when configured in broadcast mode, allows man-in-the-middle attackers to conduct replay attacks by sniffing the network.
CVE-2015-7977
- EPSS 16.35%
- Veröffentlicht 30.01.2017 21:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
ntpd in NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to cause a denial of service (NULL pointer dereference) via a ntpdc reslist command.
CVE-2016-5766
- EPSS 16.23%
- Veröffentlicht 07.08.2016 10:59:13
- Zuletzt bearbeitet 06.05.2026 22:30:45
Integer overflow in the _gd2GetHeader function in gd_gd2.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8, allows remote attackers to cause a denial of service (heap-based ...
CVE-2016-1887
- EPSS 0.38%
- Veröffentlicht 25.05.2016 15:59:03
- Zuletzt bearbeitet 06.05.2026 22:30:45
Integer signedness error in the sockargs function in sys/kern/uipc_syscalls.c in FreeBSD 10.1 before p34, 10.2 before p17, and 10.3 before p3 allows local users to cause a denial of service (memory overwrite and kernel panic) or gain privileges via a...
CVE-2016-1886
- EPSS 0.22%
- Veröffentlicht 25.05.2016 15:59:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
Integer signedness error in the genkbd_commonioctl function in sys/dev/kbd/kbd.c in FreeBSD 9.3 before p42, 10.1 before p34, 10.2 before p17, and 10.3 before p3 allows local users to obtain sensitive information from kernel memory, cause a denial of ...
CVE-2016-1885
- EPSS 0.15%
- Veröffentlicht 12.04.2016 02:00:06
- Zuletzt bearbeitet 06.05.2026 22:30:45
Integer signedness error in the amd64_set_ldt function in sys/amd64/amd64/sys_machdep.c in FreeBSD 9.3 before p39, 10.1 before p31, and 10.2 before p14 allows local users to cause a denial of service (kernel panic) via an i386_set_ldt system call, wh...