CVE-2020-25581
- EPSS 0.52%
- Veröffentlicht 26.03.2021 21:15:12
- Zuletzt bearbeitet 21.11.2024 05:18:10
In FreeBSD 12.2-STABLE before r369312, 11.4-STABLE before r369313, 12.2-RELEASE before p4 and 11.4-RELEASE before p8 due to a race condition in the jail_remove(2) implementation, it may fail to kill some of the processes.
CVE-2020-25582
- EPSS 0.46%
- Veröffentlicht 26.03.2021 21:15:12
- Zuletzt bearbeitet 21.11.2024 05:18:10
In FreeBSD 12.2-STABLE before r369334, 11.4-STABLE before r369335, 12.2-RELEASE before p4 and 11.4-RELEASE before p8 when a process, such as jexec(8) or killall(1), calls jail_attach(2) to enter a jail, the jailed root can attach to it using ptrace(2...
CVE-2021-3449
- EPSS 10.19%
- Veröffentlicht 25.03.2021 15:15:13
- Zuletzt bearbeitet 21.11.2024 06:21:33
An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but incl...
CVE-2021-3450
- EPSS 0.57%
- Veröffentlicht 25.03.2021 15:15:13
- Zuletzt bearbeitet 21.11.2024 06:21:33
The X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present in a certificate chain. It is not set by default. Starting from OpenSSL version 1.1.1h a check to disallow certificates in the chain that have explicitly ...
CVE-2020-24718
- EPSS 0.1%
- Veröffentlicht 25.09.2020 04:23:04
- Zuletzt bearbeitet 21.11.2024 05:15:57
bhyve, as used in FreeBSD through 12.1 and illumos (e.g., OmniOS CE through r151034 and OpenIndiana through Hipster 2020.04), does not properly restrict VMCS and VMCB read/write operations, as demonstrated by a root user in a container on an Intel sy...
CVE-2020-24385
- EPSS 0.04%
- Veröffentlicht 03.09.2020 15:15:11
- Zuletzt bearbeitet 21.11.2024 05:14:42
In MidnightBSD before 1.2.6 and 1.3 before August 2020, and FreeBSD before 7, a NULL pointer dereference was found in the Linux emulation layer that allows attackers to crash the running kernel. During binary interaction, td->td_emuldata in sys/compa...
CVE-2020-24863
- EPSS 0.1%
- Veröffentlicht 03.09.2020 15:15:11
- Zuletzt bearbeitet 21.11.2024 05:16:08
A memory corruption vulnerability was found in the kernel function kern_getfsstat in MidnightBSD before 1.2.7 and 1.3 through 2020-08-19, and FreeBSD through 11.4, that allows an attacker to trigger an invalid free and crash the system via a crafted ...
CVE-2020-7459
- EPSS 0.06%
- Veröffentlicht 06.08.2020 17:15:11
- Zuletzt bearbeitet 21.11.2024 05:37:11
In FreeBSD 12.1-STABLE before r362166, 12.1-RELEASE before p8, 11.4-STABLE before r362167, 11.4-RELEASE before p2, and 11.3-RELEASE before p12, missing length validation code common to mulitple USB network drivers allows a malicious USB device to wri...
- EPSS 1.51%
- Veröffentlicht 06.08.2020 17:15:11
- Zuletzt bearbeitet 21.11.2024 05:37:11
In FreeBSD 12.1-STABLE before r363918, 12.1-RELEASE before p8, 11.4-STABLE before r363919, 11.4-RELEASE before p2, and 11.3-RELEASE before p12, the sendmsg system call in the compat32 subsystem on 64-bit platforms has a time-of-check to time-of-use v...
CVE-2020-7457
- EPSS 36.84%
- Veröffentlicht 09.07.2020 14:15:10
- Zuletzt bearbeitet 21.11.2024 05:37:10
In FreeBSD 12.1-STABLE before r359565, 12.1-RELEASE before p7, 11.4-STABLE before r362975, 11.4-RELEASE before p1, and 11.3-RELEASE before p11, missing synchronization in the IPV6_2292PKTOPTIONS socket option set handler contained a race condition al...