CVE-2011-1073
- EPSS 0.03%
- Veröffentlicht 04.03.2011 23:00:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
crontab.c in crontab in FreeBSD and Apple Mac OS X allows local users to (1) determine the existence of arbitrary files via a symlink attack on a /tmp/crontab.XXXXXXXXXX temporary file and (2) perform MD5 checksum comparisons on arbitrary pairs of fi...
CVE-2011-1074
- EPSS 0.01%
- Veröffentlicht 04.03.2011 23:00:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
crontab.c in crontab in FreeBSD allows local users to determine the existence of arbitrary directories via a command-line argument composed of a directory name concatenated with a directory traversal sequence that leads to the /etc/crontab pathname.
- EPSS 1.83%
- Veröffentlicht 02.03.2011 20:00:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
The glob implementation in libc in FreeBSD 7.3 and 8.1, NetBSD 5.0.2, and OpenBSD 4.7, and Libsystem in Apple Mac OS X before 10.6.8, allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob express...
- EPSS 0.15%
- Veröffentlicht 02.03.2011 20:00:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
The (1) remote_glob function in sftp-glob.c and the (2) process_put function in sftp.c in OpenSSH 5.8 and earlier, as used in FreeBSD 7.3 and 8.1, NetBSD 5.0.2, OpenBSD 4.7, and other products, allow remote authenticated users to cause a denial of se...
CVE-2010-4210
- EPSS 0.26%
- Veröffentlicht 22.11.2010 12:54:10
- Zuletzt bearbeitet 11.04.2025 00:51:21
The pfs_getextattr function in FreeBSD 7.x before 7.3-RELEASE and 8.x before 8.0-RC1 unlocks a mutex that was not previously locked, which allows local users to cause a denial of service (kernel panic), overwrite arbitrary memory locations, and possi...
CVE-2010-2530
- EPSS 0.04%
- Veröffentlicht 29.09.2010 17:00:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
Multiple integer signedness errors in smb_subr.c in the netsmb module in the kernel in NetBSD 5.0.2 and earlier, FreeBSD, and Apple Mac OS X allow local users to cause a denial of service (panic) via a negative size value in a /dev/nsmb ioctl operati...
CVE-2010-3014
- EPSS 0.06%
- Veröffentlicht 20.08.2010 20:00:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
The Coda filesystem kernel module, as used in NetBSD and FreeBSD, when Coda is loaded and Venus is running with /coda mounted, allows local users to read sensitive heap memory via a large out_size value in a ViceIoctl struct to a Coda ioctl, which tr...
CVE-2010-2693
- EPSS 0.17%
- Veröffentlicht 13.07.2010 20:30:12
- Zuletzt bearbeitet 11.04.2025 00:51:21
FreeBSD 7.1 through 8.1-PRERELEASE does not copy the read-only flag when creating a duplicate mbuf buffer reference, which allows local users to cause a denial of service (system file corruption) and gain privileges via the sendfile system call.
CVE-2010-1938
- EPSS 39.54%
- Veröffentlicht 28.05.2010 18:30:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Off-by-one error in the __opiereadrec function in readrec.c in libopie in OPIE 2.4.1-test1 and earlier, as used on FreeBSD 6.4 through 8.1-PRERELEASE and other platforms, allows remote attackers to cause a denial of service (daemon crash) or possibly...
CVE-2010-2020
- EPSS 0.05%
- Veröffentlicht 28.05.2010 18:30:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
sys/nfsclient/nfs_vfsops.c in the NFS client in the kernel in FreeBSD 7.2 through 8.1-PRERELEASE, when vfs.usermount is enabled, does not validate the length of a certain fhsize parameter, which allows local users to gain privileges via a crafted mou...