CVE-2014-3873
- EPSS 0.06%
- Veröffentlicht 10.06.2014 14:55:10
- Zuletzt bearbeitet 06.05.2026 22:30:45
The ktrace utility in the FreeBSD kernel 8.4 before p11, 9.1 before p14, 9.2 before p7, and 9.3-BETA1 before p1 uses an incorrect page fault kernel trace entry size, which allows local users to obtain sensitive information from kernel memory via a ke...
CVE-2014-3880
- EPSS 0.05%
- Veröffentlicht 10.06.2014 14:55:10
- Zuletzt bearbeitet 06.05.2026 22:30:45
The (1) execve and (2) fexecve system calls in the FreeBSD kernel 8.4 before p11, 9.1 before p14, 9.2 before p7, and 10.0 before p4 destroys the virtual memory address space and mappings for a process before all threads have terminated, which allows ...
CVE-2014-3956
- EPSS 0.08%
- Veröffentlicht 04.06.2014 11:19:13
- Zuletzt bearbeitet 06.05.2026 22:30:45
The sm_close_on_exec function in conf.c in sendmail before 8.14.9 has arguments in the wrong order, and consequently skips setting expected FD_CLOEXEC flags, which allows local users to access unintended high-numbered file descriptors via a custom ma...
CVE-2014-3000
- EPSS 6.38%
- Veröffentlicht 02.05.2014 14:55:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
The TCP reassembly function in the inet module in FreeBSD 8.3 before p16, 8.4 before p9, 9.1 before p12, 9.2 before p5, and 10.0 before p2 allows remote attackers to cause a denial of service (undefined memory access and system crash) or possibly rea...
CVE-2014-3001
- EPSS 0.29%
- Veröffentlicht 02.05.2014 14:55:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
The device file system (aka devfs) in FreeBSD 10.0 before p2 does not load default rulesets when booting, which allows context-dependent attackers to bypass intended restrictions by leveraging a jailed device node process.
- EPSS 1.18%
- Veröffentlicht 16.04.2014 18:37:13
- Zuletzt bearbeitet 06.05.2026 22:30:45
The NFS server (nfsserver) in FreeBSD 8.3 through 10.0 does not acquire locks in the proper order when converting a directory file handle to a vnode, which allows remote authenticated users to cause a denial of service (deadlock) via vectors involvin...
CVE-2014-1452
- EPSS 0.62%
- Veröffentlicht 21.01.2014 15:17:12
- Zuletzt bearbeitet 29.04.2026 01:13:23
Stack-based buffer overflow in lib/snmpagent.c in bsnmpd, as used in FreeBSD 8.3 through 10.0, allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via a crafted GETBULK PDU request.
CVE-2013-6832
- EPSS 0.06%
- Veröffentlicht 21.11.2013 04:40:59
- Zuletzt bearbeitet 29.04.2026 01:13:23
The nand_ioctl function in sys/dev/nand/nand_geom.c in the nand driver in the kernel in FreeBSD 10 and earlier does not properly initialize a certain data structure, which allows local users to obtain sensitive information from kernel memory via a cr...
CVE-2013-6833
- EPSS 0.06%
- Veröffentlicht 21.11.2013 04:40:59
- Zuletzt bearbeitet 29.04.2026 01:13:23
The qls_eioctl function in sys/dev/qlxge/qls_ioctl.c in the kernel in FreeBSD 10 and earlier does not validate a certain size parameter, which allows local users to obtain sensitive information from kernel memory via a crafted ioctl call.
CVE-2013-6834
- EPSS 0.06%
- Veröffentlicht 21.11.2013 04:40:59
- Zuletzt bearbeitet 29.04.2026 01:13:23
The ql_eioctl function in sys/dev/qlxgbe/ql_ioctl.c in the kernel in FreeBSD 10 and earlier does not validate a certain size parameter, which allows local users to obtain sensitive information from kernel memory via a crafted ioctl call.