- EPSS 3.73%
- Veröffentlicht 12.12.2014 03:03:47
- Zuletzt bearbeitet 06.05.2026 22:30:45
The TCP stack in 4.3BSD Net/2, as used in FreeBSD 5.4, NetBSD possibly 2.0, and OpenBSD possibly 3.6, does not properly implement the session timer, which allows remote attackers to cause a denial of service (resource consumption) via crafted packets...
CVE-2014-8475
- EPSS 1.27%
- Veröffentlicht 18.11.2014 15:59:05
- Zuletzt bearbeitet 06.05.2026 22:30:45
FreeBSD 9.1, 9.2, and 10.0, when compiling OpenSSH with Kerberos support, uses incorrect library ordering when linking sshd, which causes symbols to be resolved incorrectly and allows remote attackers to cause a denial of service (sshd deadlock and p...
CVE-2014-8476
- EPSS 0.07%
- Veröffentlicht 13.11.2014 21:32:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
The setlogin function in FreeBSD 8.4 through 10.1-RC4 does not initialize the buffer used to store the login name, which allows local users to obtain sensitive information from kernel memory via a call to getlogin, which returns the entire buffer.
- EPSS 0.6%
- Veröffentlicht 27.10.2014 15:55:24
- Zuletzt bearbeitet 06.05.2026 22:30:45
namei in FreeBSD 9.1 through 10.1-RC2 allows remote attackers to cause a denial of service (memory exhaustion) via vectors that trigger a sandboxed process to look up a large number of nonexistent path names.
- EPSS 8.93%
- Veröffentlicht 27.10.2014 15:55:24
- Zuletzt bearbeitet 06.05.2026 22:30:45
Stack-based buffer overflow in rtsold in FreeBSD 9.1 through 10.1-RC2 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via crafted DNS parameters in a router advertisement message.
- EPSS 0.54%
- Veröffentlicht 27.10.2014 15:55:24
- Zuletzt bearbeitet 06.05.2026 22:30:45
routed in FreeBSD 8.4 through 10.1-RC2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via an RIP request from a source not on a directly connected network.
- EPSS 0.41%
- Veröffentlicht 21.08.2014 22:55:03
- Zuletzt bearbeitet 06.05.2026 22:30:45
The HZ module in the iconv implementation in FreeBSD 10.0 before p6 and NetBSD allows context-dependent attackers to cause a denial of service (NULL pointer dereference) via a crafted argument to the iconv_open function. NOTE: this issue was SPLIT p...
- EPSS 0.41%
- Veröffentlicht 21.08.2014 22:55:03
- Zuletzt bearbeitet 06.05.2026 22:30:45
The VIQR module in the iconv implementation in FreeBSD 10.0 before p6 and NetBSD allows context-dependent attackers to cause a denial of service (out-of-bounds array access) via a crafted argument to the iconv_open function. NOTE: this issue was SPL...
CVE-2014-3952
- EPSS 0.07%
- Veröffentlicht 15.07.2014 14:55:09
- Zuletzt bearbeitet 06.05.2026 22:30:45
FreeBSD 8.4 before p14, 9.1 before p17, 9.2 before p10, and 10.0 before p7 does not properly initialize the buffer between the header and data of a control message, which allows local users to obtain sensitive information from kernel memory via unspe...
CVE-2014-3953
- EPSS 0.07%
- Veröffentlicht 15.07.2014 14:55:09
- Zuletzt bearbeitet 06.05.2026 22:30:45
FreeBSD 8.4 before p14, 9.1 before p17, 9.2 before p10, and 10.0 before p7 does not properly initialize certain data structures, which allows local users to obtain sensitive information from kernel memory via a (1) SCTP_SNDRCV, (2) SCTP_EXTRCV, or (3...