Freebsd

Freebsd

509 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.04%
  • Veröffentlicht 16.01.2008 02:00:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The script program in FreeBSD 5.0 through 7.0-PRERELEASE invokes openpty, which creates a pseudo-terminal with world-readable and world-writable permissions when it is not run as root, which allows local users to read data from the terminal of the us...

  • EPSS 0.07%
  • Veröffentlicht 30.11.2007 01:46:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The "internal state tracking" code for the random and urandom devices in FreeBSD 5.5, 6.1 through 6.3, and 7.0 beta 4 allows local users to obtain portions of previously-accessed random values, which could be leveraged to bypass protection mechanisms...

Exploit
  • EPSS 72.12%
  • Veröffentlicht 16.07.2007 22:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Integer overflow in print-bgp.c in the BGP dissector in tcpdump 3.9.6 and earlier allows remote attackers to execute arbitrary code via crafted TLVs in a BGP packet, related to an unchecked return value.

  • EPSS 0.07%
  • Veröffentlicht 12.07.2007 16:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The ULE process scheduler in the FreeBSD kernel gives preference to "interactive" processes that perform voluntary sleeps, which allows local users to cause a denial of service (CPU consumption), as described in "Secretly Monopolizing the CPU Without...

  • EPSS 0.07%
  • Veröffentlicht 12.07.2007 16:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The 4BSD process scheduler in the FreeBSD kernel performs scheduling based on CPU billing gathered from periodic process sampling ticks, which allows local users to cause a denial of service (CPU consumption) by performing voluntary nanosecond sleeps...

  • EPSS 0.46%
  • Veröffentlicht 17.01.2007 00:28:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The ufs_lookup function in the Mac OS X 10.4.8 and FreeBSD 6.1 kernels allows local users to cause a denial of service (kernel panic) and possibly corrupt other filesystems by mounting a crafted UNIX File System (UFS) DMG image that contains a corrup...

Exploit
  • EPSS 2.91%
  • Veröffentlicht 13.01.2007 02:28:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Integer overflow in the ffs_mountfs function in Mac OS X 10.4.8 and FreeBSD 6.1 allows local users to cause a denial of service (panic) and possibly gain privileges via a crafted DMG image that causes "allocation of a negative size buffer" leading to...

Exploit
  • EPSS 0.05%
  • Veröffentlicht 11.01.2007 20:28:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The jail rc.d script in FreeBSD 5.3 up to 6.2 does not verify pathnames when writing to /var/log/console.log during a jail start-up, or when file systems are mounted or unmounted, which allows local root users to overwrite arbitrary files, or mount/u...

  • EPSS 0.15%
  • Veröffentlicht 08.12.2006 01:28:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Integer overflow in banner/banner.c in FreeBSD, NetBSD, and OpenBSD might allow local users to modify memory via a long banner. NOTE: CVE and multiple third parties dispute this issue. Since banner is not setuid, an exploit would not cross privilege...

  • EPSS 0.14%
  • Veröffentlicht 29.11.2006 01:28:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

ld.so in FreeBSD, NetBSD, and possibly other BSD distributions does not remove certain harmful environment variables, which allows local users to gain privileges by passing certain environment variables to loading processes. NOTE: this issue has bee...