CVE-2013-2171
- EPSS 24.17%
- Veröffentlicht 02.07.2013 03:43:33
- Zuletzt bearbeitet 11.04.2025 00:51:21
The vm_map_lookup function in sys/vm/vm_map.c in the mmap implementation in the kernel in FreeBSD 9.0 through 9.1-RELEASE-p4 does not properly determine whether a task should have write access to a memory location, which allows local users to bypass ...
CVE-2013-3266
- EPSS 2.31%
- Veröffentlicht 02.05.2013 11:44:41
- Zuletzt bearbeitet 11.04.2025 00:51:21
The nfsrvd_readdir function in sys/fs/nfsserver/nfs_nfsdport.c in the new NFS server in FreeBSD 8.0 through 9.1-RELEASE-p3 does not verify that a READDIR request is for a directory node, which allows remote attackers to cause a denial of service (mem...
CVE-2012-3549
- EPSS 12.21%
- Veröffentlicht 09.10.2012 23:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
The SCTP implementation in FreeBSD 8.2 allows remote attackers to cause a denial of service (NULL pointer dereference and kernel panic) via a crafted ASCONF chunk.
- EPSS 0.32%
- Veröffentlicht 25.07.2012 19:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Integer overflow in the calloc function in libc/stdlib/malloc.c in jemalloc in libc for FreeBSD 6.4 and NetBSD makes it easier for context-dependent attackers to perform memory-related attacks such as buffer overflows via a large size value, which tr...
- EPSS 0.32%
- Veröffentlicht 25.07.2012 19:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The ipalloc function in libc/stdlib/malloc.c in jemalloc in libc for FreeBSD 6.4 and NetBSD does not properly allocate memory, which makes it easier for context-dependent attackers to perform memory-related attacks such as buffer overflows via a larg...
CVE-2012-2143
- EPSS 3.87%
- Veröffentlicht 05.07.2012 14:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
The crypt_des (aka DES-based crypt) function in FreeBSD before 9.0-RELEASE-p2, as used in PHP, PostgreSQL, and other products, does not process the complete cleartext password if this password contains a 0x80 character, which makes it easier for cont...
CVE-2012-0217
- EPSS 86.54%
- Veröffentlicht 12.06.2012 22:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The x86-64 kernel system-call functionality in Xen 4.1.2 and earlier, as used in Citrix XenServer 6.0.2 and earlier and other products; Oracle Solaris 11 and earlier; illumos before r13724; Joyent SmartOS before 20120614T184600Z; FreeBSD before 9.0-R...
CVE-2011-2393
- EPSS 0.43%
- Veröffentlicht 02.02.2012 17:55:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in FreeBSD, NetBSD, and possibly other BSD-based operating systems allows remote attackers to cause a denial of service (CPU consumption and device hang) by sending many Router Adv...
- EPSS 92.59%
- Veröffentlicht 25.12.2011 01:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and earlier, Heimdal 1.5.1 and earlier, GNU inetutils, and possibly other products allows remote attackers to exec...
CVE-2011-4122
- EPSS 0.62%
- Veröffentlicht 17.11.2011 19:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Directory traversal vulnerability in openpam_configure.c in OpenPAM before r478 on FreeBSD 8.1 allows local users to load arbitrary DSOs and gain privileges via a .. (dot dot) in the service_name argument to the pam_start function, as demonstrated by...