CVE-2011-0419
- EPSS 48.78%
- Veröffentlicht 16.05.2011 17:55:02
- Zuletzt bearbeitet 29.04.2026 01:13:23
Stack consumption vulnerability in the fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library before 1.4.3 and the Apache HTTP Server before 2.2.18, and in fnmatch.c in libc in NetBSD 5.1, OpenBSD 4.8, FreeBSD, Apple Mac...
CVE-2011-1739
- EPSS 0.34%
- Veröffentlicht 03.05.2011 20:55:12
- Zuletzt bearbeitet 29.04.2026 01:13:23
The makemask function in mountd.c in mountd in FreeBSD 7.4 through 8.2 does not properly handle a -network field specifying a CIDR block with a prefix length that is not an integer multiple of 8, which allows remote attackers to bypass intended acces...
CVE-2011-1073
- EPSS 0.03%
- Veröffentlicht 04.03.2011 23:00:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
crontab.c in crontab in FreeBSD and Apple Mac OS X allows local users to (1) determine the existence of arbitrary files via a symlink attack on a /tmp/crontab.XXXXXXXXXX temporary file and (2) perform MD5 checksum comparisons on arbitrary pairs of fi...
CVE-2011-1074
- EPSS 0.01%
- Veröffentlicht 04.03.2011 23:00:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
crontab.c in crontab in FreeBSD allows local users to determine the existence of arbitrary directories via a command-line argument composed of a directory name concatenated with a directory traversal sequence that leads to the /etc/crontab pathname.
- EPSS 1.83%
- Veröffentlicht 02.03.2011 20:00:00
- Zuletzt bearbeitet 29.04.2026 01:13:23
The glob implementation in libc in FreeBSD 7.3 and 8.1, NetBSD 5.0.2, and OpenBSD 4.7, and Libsystem in Apple Mac OS X before 10.6.8, allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob express...
- EPSS 0.15%
- Veröffentlicht 02.03.2011 20:00:00
- Zuletzt bearbeitet 29.04.2026 01:13:23
The (1) remote_glob function in sftp-glob.c and the (2) process_put function in sftp.c in OpenSSH 5.8 and earlier, as used in FreeBSD 7.3 and 8.1, NetBSD 5.0.2, OpenBSD 4.7, and other products, allow remote authenticated users to cause a denial of se...
CVE-2010-4210
- EPSS 0.26%
- Veröffentlicht 22.11.2010 12:54:10
- Zuletzt bearbeitet 29.04.2026 01:13:23
The pfs_getextattr function in FreeBSD 7.x before 7.3-RELEASE and 8.x before 8.0-RC1 unlocks a mutex that was not previously locked, which allows local users to cause a denial of service (kernel panic), overwrite arbitrary memory locations, and possi...
CVE-2010-2530
- EPSS 0.04%
- Veröffentlicht 29.09.2010 17:00:04
- Zuletzt bearbeitet 29.04.2026 01:13:23
Multiple integer signedness errors in smb_subr.c in the netsmb module in the kernel in NetBSD 5.0.2 and earlier, FreeBSD, and Apple Mac OS X allow local users to cause a denial of service (panic) via a negative size value in a /dev/nsmb ioctl operati...
CVE-2010-3014
- EPSS 0.06%
- Veröffentlicht 20.08.2010 20:00:02
- Zuletzt bearbeitet 29.04.2026 01:13:23
The Coda filesystem kernel module, as used in NetBSD and FreeBSD, when Coda is loaded and Venus is running with /coda mounted, allows local users to read sensitive heap memory via a large out_size value in a ViceIoctl struct to a Coda ioctl, which tr...
CVE-2010-2693
- EPSS 0.17%
- Veröffentlicht 13.07.2010 20:30:12
- Zuletzt bearbeitet 29.04.2026 01:13:23
FreeBSD 7.1 through 8.1-PRERELEASE does not copy the read-only flag when creating a duplicate mbuf buffer reference, which allows local users to cause a denial of service (system file corruption) and gain privileges via the sendfile system call.