Freebsd

Freebsd

527 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.04%
  • Veröffentlicht 25.06.2009 02:00:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

FreeBSD 6.3, 6.4, 7.1, and 7.2 does not enforce permissions on the SIOCSIFINFO_IN6 IOCTL, which allows local users to modify or disable IPv6 network interfaces, as demonstrated by modifying the MTU.

Exploit
  • EPSS 0.07%
  • Veröffentlicht 18.06.2009 18:30:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

Integer overflow in the pipe_build_write_buffer function (sys/kern/sys_pipe.c) in the direct write optimization feature in the pipe implementation in FreeBSD 7.1 through 7.2 and 6.3 through 6.4 allows local users to bypass virtual-to-physical address...

Exploit
  • EPSS 0.26%
  • Veröffentlicht 27.04.2009 18:00:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

The db interface in libc in FreeBSD 6.3, 6.4, 7.0, 7.1, and 7.2-PRERELEASE does not properly initialize memory for Berkeley DB 1.85 database structures, which allows local users to obtain sensitive information by reading a database file.

Exploit
  • EPSS 0.11%
  • Veröffentlicht 26.03.2009 05:51:47
  • Zuletzt bearbeitet 23.04.2026 00:35:47

The ktimer feature (sys/kern/kern_time.c) in FreeBSD 7.0, 7.1, and 7.2 allows local users to overwrite arbitrary kernel memory via an out-of-bounds timer value.

Exploit
  • EPSS 10.15%
  • Veröffentlicht 20.02.2009 06:47:48
  • Zuletzt bearbeitet 23.04.2026 00:35:47

sys_term.c in telnetd in FreeBSD 7.0-RELEASE and other 7.x versions deletes dangerous environment variables with a method that was valid only in older FreeBSD distributions, which might allow remote attackers to execute arbitrary code by passing a cr...

  • EPSS 0.39%
  • Veröffentlicht 26.12.2008 18:30:03
  • Zuletzt bearbeitet 23.04.2026 00:35:47

Multiple unspecified vulnerabilities in FreeBSD 6 before 6.4-STABLE, 6.3 before 6.3-RELEASE-p7, 6.4 before 6.4-RELEASE-p1, 7.0 before 7.0-RELEASE-p7, 7.1 before 7.1-RC2, and 7 before 7.1-PRERELEASE allow local users to gain privileges via unknown att...

  • EPSS 0.06%
  • Veröffentlicht 26.11.2008 23:30:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

The arc4random function in the kernel in FreeBSD 6.3 through 7.1 does not have a proper entropy source for a short time period immediately after boot, which makes it easier for attackers to predict the function's return values and conduct certain att...

  • EPSS 1.88%
  • Veröffentlicht 20.10.2008 17:59:26
  • Zuletzt bearbeitet 23.04.2026 00:35:47

The TCP implementation in (1) Linux, (2) platforms based on BSD Unix, (3) Microsoft Windows, (4) Cisco products, and probably other operating systems allows remote attackers to cause a denial of service (connection queue exhaustion) via multiple vect...

  • EPSS 10.5%
  • Veröffentlicht 03.10.2008 15:07:10
  • Zuletzt bearbeitet 23.04.2026 00:35:47

The IPv6 Neighbor Discovery Protocol (NDP) implementation in (1) FreeBSD 6.3 through 7.1, (2) OpenBSD 4.2 and 4.3, (3) NetBSD, (4) Force10 FTOS before E7.7.1.1, (5) Juniper JUNOS, and (6) Wind River VxWorks 5.x through 6.4 does not validate the origi...

Exploit
  • EPSS 12.61%
  • Veröffentlicht 25.09.2008 19:25:18
  • Zuletzt bearbeitet 23.04.2026 00:35:47

ftpd in OpenBSD 4.3, FreeBSD 7.0, NetBSD 4.0, Solaris, and possibly other operating systems interprets long commands from an FTP client as multiple commands, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and execu...