CVE-2001-0371
- EPSS 0.05%
- Veröffentlicht 18.06.2001 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Race condition in the UFS and EXT2FS file systems in FreeBSD 4.2 and earlier, and possibly other operating systems, makes deleted data available to user processes before it is zeroed out, which allows a local user to access otherwise restricted infor...
CVE-2001-0402
- EPSS 2.71%
- Veröffentlicht 18.06.2001 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
IPFilter 3.4.16 and earlier does not include sufficient session information in its cache, which allows remote attackers to bypass access restrictions by sending fragmented packets to a restricted port after sending unfragmented packets to an unrestri...
CVE-2001-0230
- EPSS 0.08%
- Veröffentlicht 02.06.2001 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Buffer overflow in dc20ctrl before 0.4_1 in FreeBSD, and possibly other operating systems, allows local users to gain privileges.
CVE-2001-0310
- EPSS 0.09%
- Veröffentlicht 02.06.2001 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
sort in FreeBSD 4.1.1 and earlier, and possibly other operating systems, uses predictable temporary file names and does not properly handle when the temporary file already exists, which causes sort to crash and possibly impacts security-sensitive scr...
- EPSS 0.57%
- Veröffentlicht 03.05.2001 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
inetd ident server in FreeBSD 4.x and earlier does not properly set group permissions, which allows remote attackers to read the first 16 bytes of files that are accessible by the wheel group.
CVE-2001-0183
- EPSS 8.91%
- Veröffentlicht 26.03.2001 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
ipfw and ip6fw in FreeBSD 4.2 and earlier allows remote attackers to bypass access restrictions by setting the ECE flag in a TCP packet, which makes the packet appear to be part of an established connection.
CVE-2000-0375
- EPSS 0.11%
- Veröffentlicht 12.03.2001 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
The kernel in FreeBSD 3.2 follows symbolic links when it creates core dump files, which allows local attackers to modify arbitrary files.
CVE-2001-0128
- EPSS 0.06%
- Veröffentlicht 12.03.2001 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Zope before 2.2.4 does not properly compute local roles, which could allow users to bypass specified access restrictions and gain privileges.
CVE-2000-0890
- EPSS 0.78%
- Veröffentlicht 16.02.2001 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
periodic in FreeBSD 4.1.1 and earlier, and possibly other operating systems, allows local users to overwrite arbitrary files via a symlink attack.
CVE-2001-0061
- EPSS 0.05%
- Veröffentlicht 12.02.2001 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
procfs in FreeBSD and possibly other operating systems does not properly restrict access to per-process mem and ctl files, which allows local users to gain root privileges by forking a child process and executing a privileged process from the child, ...