CVE-2013-6833
- EPSS 0.06%
- Veröffentlicht 21.11.2013 04:40:59
- Zuletzt bearbeitet 11.04.2025 00:51:21
The qls_eioctl function in sys/dev/qlxge/qls_ioctl.c in the kernel in FreeBSD 10 and earlier does not validate a certain size parameter, which allows local users to obtain sensitive information from kernel memory via a crafted ioctl call.
CVE-2013-6834
- EPSS 0.06%
- Veröffentlicht 21.11.2013 04:40:59
- Zuletzt bearbeitet 11.04.2025 00:51:21
The ql_eioctl function in sys/dev/qlxgbe/ql_ioctl.c in the kernel in FreeBSD 10 and earlier does not validate a certain size parameter, which allows local users to obtain sensitive information from kernel memory via a crafted ioctl call.
- EPSS 1.2%
- Veröffentlicht 30.09.2013 22:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
Integer signedness error in the archive_write_zip_data function in archive_write_set_format_zip.c in libarchive 3.1.2 and earlier, when running on 64-bit machines, allows context-dependent attackers to cause a denial of service (crash) via unspecifie...
CVE-2013-5666
- EPSS 0.07%
- Veröffentlicht 23.09.2013 20:55:07
- Zuletzt bearbeitet 11.04.2025 00:51:21
The sendfile system-call implementation in sys/kern/uipc_syscalls.c in the kernel in FreeBSD 9.2-RC1 and 9.2-RC2 does not properly pad transmissions, which allows local users to obtain sensitive information (kernel memory) via a length greater than t...
CVE-2013-5710
- EPSS 0.05%
- Veröffentlicht 23.09.2013 20:55:07
- Zuletzt bearbeitet 11.04.2025 00:51:21
The nullfs implementation in sys/fs/nullfs/null_vnops.c in the kernel in FreeBSD 8.3 through 9.2 allows local users with certain permissions to bypass access restrictions via a hardlink in a nullfs instance to a file in a different instance.
CVE-2013-5691
- EPSS 0.06%
- Veröffentlicht 23.09.2013 10:18:59
- Zuletzt bearbeitet 11.04.2025 00:51:21
The (1) IPv6 and (2) ATM ioctl request handlers in the kernel in FreeBSD 8.3 through 9.2-STABLE do not validate SIOCSIFADDR, SIOCSIFBRDADDR, SIOCSIFDSTADDR, and SIOCSIFNETMASK requests, which allows local users to perform link-layer actions, cause a ...
CVE-2013-5209
- EPSS 0.63%
- Veröffentlicht 29.08.2013 12:07:56
- Zuletzt bearbeitet 11.04.2025 00:51:21
The sctp_send_initiate_ack function in sys/netinet/sctp_output.c in the SCTP implementation in the kernel in FreeBSD 8.3 through 9.2-PRERELEASE does not properly initialize the state-cookie data structure, which allows remote attackers to obtain sens...
CVE-2013-3077
- EPSS 0.04%
- Veröffentlicht 28.08.2013 13:13:58
- Zuletzt bearbeitet 11.04.2025 00:51:21
Multiple integer overflows in the IP_MSFILTER and IPV6_MSFILTER features in (1) sys/netinet/in_mcast.c and (2) sys/netinet6/in6_mcast.c in the multicast implementation in the kernel in FreeBSD 8.3 through 9.2-PRERELEASE allow local users to bypass in...
CVE-2013-4851
- EPSS 0.21%
- Veröffentlicht 29.07.2013 13:59:56
- Zuletzt bearbeitet 11.04.2025 00:51:21
The vfs_hang_addrlist function in sys/kern/vfs_export.c in the NFS server implementation in the kernel in FreeBSD 8.3 and 9.x through 9.1-RELEASE-p5 controls authorization for host/subnet export entries on the basis of group information sent by the c...
CVE-2013-4854
- EPSS 53.7%
- Veröffentlicht 29.07.2013 13:59:37
- Zuletzt bearbeitet 11.04.2025 00:51:21
The RFC 5011 implementation in rdata.c in ISC BIND 9.7.x and 9.8.x before 9.8.5-P2, 9.8.6b1, 9.9.x before 9.9.3-P2, and 9.9.4b1, and DNSco BIND 9.9.3-S1 before 9.9.3-S1-P1 and 9.9.4-S1b1, allows remote attackers to cause a denial of service (assertio...