CVE-2020-7464
- EPSS 0.28%
- Veröffentlicht 26.03.2021 21:15:13
- Zuletzt bearbeitet 21.11.2024 05:37:11
In FreeBSD 12.2-STABLE before r365730, 11.4-STABLE before r365738, 12.1-RELEASE before p10, 11.4-RELEASE before p4, and 11.3-RELEASE before p14, a programming error in the ure(4) device driver caused some Realtek USB Ethernet interfaces to incorrectl...
CVE-2020-7467
- EPSS 0.04%
- Veröffentlicht 26.03.2021 21:15:13
- Zuletzt bearbeitet 21.11.2024 05:37:12
In FreeBSD 12.2-STABLE before r365767, 11.4-STABLE before r365769, 12.1-RELEASE before p10, 11.4-RELEASE before p4 and 11.3-RELEASE before p14 a number of AMD virtualization instructions operate on host physical addresses, are not subject to nested p...
- EPSS 0.64%
- Veröffentlicht 26.03.2021 21:15:13
- Zuletzt bearbeitet 21.11.2024 05:37:12
In FreeBSD 12.2-STABLE before r365772, 11.4-STABLE before r365773, 12.1-RELEASE before p10, 11.4-RELEASE before p4 and 11.3-RELEASE before p14 a ftpd(8) bug in the implementation of the file system sandbox, combined with capabilities available to an ...
CVE-2020-25578
- EPSS 6.55%
- Veröffentlicht 26.03.2021 21:15:12
- Zuletzt bearbeitet 21.11.2024 05:18:09
In FreeBSD 12.2-STABLE before r368969, 11.4-STABLE before r369047, 12.2-RELEASE before p3, 12.1-RELEASE before p13 and 11.4-RELEASE before p7 several file systems were not properly initializing the d_off field of the dirent structures returned by VOP...
CVE-2020-25579
- EPSS 0.34%
- Veröffentlicht 26.03.2021 21:15:12
- Zuletzt bearbeitet 21.11.2024 05:18:09
In FreeBSD 12.2-STABLE before r368969, 11.4-STABLE before r369047, 12.2-RELEASE before p3, 12.1-RELEASE before p13 and 11.4-RELEASE before p7 msdosfs(5) was failing to zero-fill a pair of padding fields in the dirent structure, resulting in a leak of...
CVE-2020-25580
- EPSS 0.24%
- Veröffentlicht 26.03.2021 21:15:12
- Zuletzt bearbeitet 21.11.2024 05:18:09
In FreeBSD 12.2-STABLE before r369346, 11.4-STABLE before r369345, 12.2-RELEASE before p4 and 11.4-RELEASE before p8 a regression in the login.access(5) rule processor has the effect of causing rules to fail to match even when they should not. This m...
CVE-2020-25581
- EPSS 0.52%
- Veröffentlicht 26.03.2021 21:15:12
- Zuletzt bearbeitet 21.11.2024 05:18:10
In FreeBSD 12.2-STABLE before r369312, 11.4-STABLE before r369313, 12.2-RELEASE before p4 and 11.4-RELEASE before p8 due to a race condition in the jail_remove(2) implementation, it may fail to kill some of the processes.
CVE-2020-25582
- EPSS 0.39%
- Veröffentlicht 26.03.2021 21:15:12
- Zuletzt bearbeitet 21.11.2024 05:18:10
In FreeBSD 12.2-STABLE before r369334, 11.4-STABLE before r369335, 12.2-RELEASE before p4 and 11.4-RELEASE before p8 when a process, such as jexec(8) or killall(1), calls jail_attach(2) to enter a jail, the jailed root can attach to it using ptrace(2...
CVE-2021-3449
- EPSS 8.36%
- Veröffentlicht 25.03.2021 15:15:13
- Zuletzt bearbeitet 21.11.2024 06:21:33
An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but incl...
CVE-2021-3450
- EPSS 0.5%
- Veröffentlicht 25.03.2021 15:15:13
- Zuletzt bearbeitet 21.11.2024 06:21:33
The X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present in a certificate chain. It is not set by default. Starting from OpenSSL version 1.1.1h a check to disallow certificates in the chain that have explicitly ...