CVE-2009-0641
- EPSS 5.75%
- Published 20.02.2009 06:47:48
- Last modified 09.04.2025 00:30:58
sys_term.c in telnetd in FreeBSD 7.0-RELEASE and other 7.x versions deletes dangerous environment variables with a method that was valid only in older FreeBSD distributions, which might allow remote attackers to execute arbitrary code by passing a cr...
CVE-2008-5736
- EPSS 0.31%
- Published 26.12.2008 18:30:03
- Last modified 09.04.2025 00:30:58
Multiple unspecified vulnerabilities in FreeBSD 6 before 6.4-STABLE, 6.3 before 6.3-RELEASE-p7, 6.4 before 6.4-RELEASE-p1, 7.0 before 7.0-RELEASE-p7, 7.1 before 7.1-RC2, and 7 before 7.1-PRERELEASE allow local users to gain privileges via unknown att...
- EPSS 0.06%
- Published 26.11.2008 23:30:00
- Last modified 09.04.2025 00:30:58
The arc4random function in the kernel in FreeBSD 6.3 through 7.1 does not have a proper entropy source for a short time period immediately after boot, which makes it easier for attackers to predict the function's return values and conduct certain att...
CVE-2008-4609
- EPSS 0.48%
- Published 20.10.2008 17:59:26
- Last modified 09.04.2025 00:30:58
The TCP implementation in (1) Linux, (2) platforms based on BSD Unix, (3) Microsoft Windows, (4) Cisco products, and probably other operating systems allows remote attackers to cause a denial of service (connection queue exhaustion) via multiple vect...
CVE-2008-2476
- EPSS 14.85%
- Published 03.10.2008 15:07:10
- Last modified 09.04.2025 00:30:58
The IPv6 Neighbor Discovery Protocol (NDP) implementation in (1) FreeBSD 6.3 through 7.1, (2) OpenBSD 4.2 and 4.3, (3) NetBSD, (4) Force10 FTOS before E7.7.1.1, (5) Juniper JUNOS, and (6) Wind River VxWorks 5.x through 6.4 does not validate the origi...
CVE-2008-4247
- EPSS 11.1%
- Published 25.09.2008 19:25:18
- Last modified 09.04.2025 00:30:58
ftpd in OpenBSD 4.3, FreeBSD 7.0, NetBSD 4.0, Solaris, and possibly other operating systems interprets long commands from an FTP client as multiple commands, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and execu...
CVE-2008-2464
- EPSS 3.59%
- Published 11.09.2008 01:10:39
- Last modified 09.04.2025 00:30:58
The mld_input function in sys/netinet6/mld6.c in the kernel in NetBSD 4.0, FreeBSD, and KAME, when INET6 is enabled, allows remote attackers to cause a denial of service (divide-by-zero error and panic) via a malformed ICMPv6 Multicast Listener Disco...
CVE-2008-3530
- EPSS 6.71%
- Published 05.09.2008 16:08:00
- Last modified 09.04.2025 00:30:58
sys/netinet6/icmp6.c in the kernel in FreeBSD 6.3 through 7.1, NetBSD 3.0 through 4.0, and possibly other operating systems does not properly check the proposed new MTU in an ICMPv6 Packet Too Big Message, which allows remote attackers to cause a den...
CVE-2008-3531
- EPSS 0.32%
- Published 05.09.2008 16:08:00
- Last modified 09.04.2025 00:30:58
Stack-based buffer overflow in sys/kern/vfs_mount.c in the kernel in FreeBSD 7.0 and 7.1, when vfs.usermount is enabled, allows local users to gain privileges via a crafted (1) mount or (2) nmount system call, related to copying of "user defined data...
CVE-2008-3890
- EPSS 0.05%
- Published 05.09.2008 16:08:00
- Last modified 09.04.2025 00:30:58
The kernel in FreeBSD 6.3 through 7.0 on amd64 platforms can make an extra swapgs call after a General Protection Fault (GPF), which allows local users to gain privileges by triggering a GPF during the kernel's return from (1) an interrupt, (2) a tra...