CVE-2013-5209
- EPSS 0.63%
- Veröffentlicht 29.08.2013 12:07:56
- Zuletzt bearbeitet 11.04.2025 00:51:21
The sctp_send_initiate_ack function in sys/netinet/sctp_output.c in the SCTP implementation in the kernel in FreeBSD 8.3 through 9.2-PRERELEASE does not properly initialize the state-cookie data structure, which allows remote attackers to obtain sens...
CVE-2013-3077
- EPSS 0.04%
- Veröffentlicht 28.08.2013 13:13:58
- Zuletzt bearbeitet 11.04.2025 00:51:21
Multiple integer overflows in the IP_MSFILTER and IPV6_MSFILTER features in (1) sys/netinet/in_mcast.c and (2) sys/netinet6/in6_mcast.c in the multicast implementation in the kernel in FreeBSD 8.3 through 9.2-PRERELEASE allow local users to bypass in...
CVE-2013-4851
- EPSS 0.21%
- Veröffentlicht 29.07.2013 13:59:56
- Zuletzt bearbeitet 11.04.2025 00:51:21
The vfs_hang_addrlist function in sys/kern/vfs_export.c in the NFS server implementation in the kernel in FreeBSD 8.3 and 9.x through 9.1-RELEASE-p5 controls authorization for host/subnet export entries on the basis of group information sent by the c...
CVE-2013-4854
- EPSS 65.17%
- Veröffentlicht 29.07.2013 13:59:37
- Zuletzt bearbeitet 11.04.2025 00:51:21
The RFC 5011 implementation in rdata.c in ISC BIND 9.7.x and 9.8.x before 9.8.5-P2, 9.8.6b1, 9.9.x before 9.9.3-P2, and 9.9.4b1, and DNSco BIND 9.9.3-S1 before 9.9.3-S1-P1 and 9.9.4-S1b1, allows remote attackers to cause a denial of service (assertio...
CVE-2013-2171
- EPSS 22.59%
- Veröffentlicht 02.07.2013 03:43:33
- Zuletzt bearbeitet 11.04.2025 00:51:21
The vm_map_lookup function in sys/vm/vm_map.c in the mmap implementation in the kernel in FreeBSD 9.0 through 9.1-RELEASE-p4 does not properly determine whether a task should have write access to a memory location, which allows local users to bypass ...
CVE-2013-3266
- EPSS 2.31%
- Veröffentlicht 02.05.2013 11:44:41
- Zuletzt bearbeitet 11.04.2025 00:51:21
The nfsrvd_readdir function in sys/fs/nfsserver/nfs_nfsdport.c in the new NFS server in FreeBSD 8.0 through 9.1-RELEASE-p3 does not verify that a READDIR request is for a directory node, which allows remote attackers to cause a denial of service (mem...
CVE-2012-3549
- EPSS 12.21%
- Veröffentlicht 09.10.2012 23:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
The SCTP implementation in FreeBSD 8.2 allows remote attackers to cause a denial of service (NULL pointer dereference and kernel panic) via a crafted ASCONF chunk.
- EPSS 0.32%
- Veröffentlicht 25.07.2012 19:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Integer overflow in the calloc function in libc/stdlib/malloc.c in jemalloc in libc for FreeBSD 6.4 and NetBSD makes it easier for context-dependent attackers to perform memory-related attacks such as buffer overflows via a large size value, which tr...
- EPSS 0.32%
- Veröffentlicht 25.07.2012 19:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The ipalloc function in libc/stdlib/malloc.c in jemalloc in libc for FreeBSD 6.4 and NetBSD does not properly allocate memory, which makes it easier for context-dependent attackers to perform memory-related attacks such as buffer overflows via a larg...
CVE-2012-2143
- EPSS 8.18%
- Veröffentlicht 05.07.2012 14:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
The crypt_des (aka DES-based crypt) function in FreeBSD before 9.0-RELEASE-p2, as used in PHP, PostgreSQL, and other products, does not process the complete cleartext password if this password contains a 0x80 character, which makes it easier for cont...