CVE-2010-3014
- EPSS 0.06%
- Veröffentlicht 20.08.2010 20:00:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
The Coda filesystem kernel module, as used in NetBSD and FreeBSD, when Coda is loaded and Venus is running with /coda mounted, allows local users to read sensitive heap memory via a large out_size value in a ViceIoctl struct to a Coda ioctl, which tr...
CVE-2010-2693
- EPSS 0.17%
- Veröffentlicht 13.07.2010 20:30:12
- Zuletzt bearbeitet 11.04.2025 00:51:21
FreeBSD 7.1 through 8.1-PRERELEASE does not copy the read-only flag when creating a duplicate mbuf buffer reference, which allows local users to cause a denial of service (system file corruption) and gain privileges via the sendfile system call.
CVE-2010-1938
- EPSS 65.73%
- Veröffentlicht 28.05.2010 18:30:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Off-by-one error in the __opiereadrec function in readrec.c in libopie in OPIE 2.4.1-test1 and earlier, as used on FreeBSD 6.4 through 8.1-PRERELEASE and other platforms, allows remote attackers to cause a denial of service (daemon crash) or possibly...
CVE-2010-2020
- EPSS 0.31%
- Veröffentlicht 28.05.2010 18:30:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
sys/nfsclient/nfs_vfsops.c in the NFS client in the kernel in FreeBSD 7.2 through 8.1-PRERELEASE, when vfs.usermount is enabled, does not validate the length of a certain fhsize parameter, which allows local users to gain privileges via a crafted mou...
CVE-2010-2022
- EPSS 0.14%
- Veröffentlicht 28.05.2010 18:30:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
jail.c in jail in FreeBSD 8.0 and 8.1-PRERELEASE, when the "-l -U root" options are omitted, does not properly restrict access to the current working directory, which might allow local users to read, modify, or create arbitrary files via standard fil...
CVE-2010-0318
- EPSS 0.03%
- Veröffentlicht 15.01.2010 18:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The replay functionality for ZFS Intent Log (ZIL) in FreeBSD 7.1, 7.2, and 8.0, when creating files during replay of a setattr transaction, uses 7777 permissions instead of the original permissions, which might allow local users to read or modify una...
CVE-2009-4358
- EPSS 0.05%
- Veröffentlicht 20.12.2009 02:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
freebsd-update in FreeBSD 8.0, 7.2, 7.1, 6.4, and 6.3 uses insecure permissions in its working directory (/var/db/freebsd-update by default), which allows local users to read copies of sensitive files after a (1) freebsd-update fetch (fetch) or (2) f...
CVE-2009-4147
- EPSS 12.58%
- Veröffentlicht 02.12.2009 19:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The _rtld function in the Run-Time Link-Editor (rtld) in libexec/rtld-elf/rtld.c in FreeBSD 7.1 and 8.0 does not clear the (1) LD_LIBMAP, (2) LD_LIBRARY_PATH, (3) LD_LIBMAP_DISABLE, (4) LD_DEBUG, and (5) LD_ELF_HINTS_PATH environment variables, which...
CVE-2009-4146
- EPSS 18.17%
- Veröffentlicht 02.12.2009 18:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The _rtld function in the Run-Time Link-Editor (rtld) in libexec/rtld-elf/rtld.c in FreeBSD 7.1, 7.2, and 8.0 does not clear the LD_PRELOAD environment variable, which allows local users to gain privileges by executing a setuid or setguid program wit...
CVE-2009-3527
- EPSS 0.28%
- Veröffentlicht 06.10.2009 22:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Race condition in the Pipe (IPC) close function in FreeBSD 6.3 and 6.4 allows local users to cause a denial of service (crash) or gain privileges via vectors related to kqueues, which triggers a use after free, leading to a NULL pointer dereference o...