Freebsd

Freebsd

515 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.1%
  • Veröffentlicht 25.09.2020 04:23:04
  • Zuletzt bearbeitet 21.11.2024 05:15:57

bhyve, as used in FreeBSD through 12.1 and illumos (e.g., OmniOS CE through r151034 and OpenIndiana through Hipster 2020.04), does not properly restrict VMCS and VMCB read/write operations, as demonstrated by a root user in a container on an Intel sy...

  • EPSS 0.04%
  • Veröffentlicht 03.09.2020 15:15:11
  • Zuletzt bearbeitet 21.11.2024 05:14:42

In MidnightBSD before 1.2.6 and 1.3 before August 2020, and FreeBSD before 7, a NULL pointer dereference was found in the Linux emulation layer that allows attackers to crash the running kernel. During binary interaction, td->td_emuldata in sys/compa...

Exploit
  • EPSS 0.1%
  • Veröffentlicht 03.09.2020 15:15:11
  • Zuletzt bearbeitet 21.11.2024 05:16:08

A memory corruption vulnerability was found in the kernel function kern_getfsstat in MidnightBSD before 1.2.7 and 1.3 through 2020-08-19, and FreeBSD through 11.4, that allows an attacker to trigger an invalid free and crash the system via a crafted ...

  • EPSS 0.06%
  • Veröffentlicht 06.08.2020 17:15:11
  • Zuletzt bearbeitet 21.11.2024 05:37:11

In FreeBSD 12.1-STABLE before r362166, 12.1-RELEASE before p8, 11.4-STABLE before r362167, 11.4-RELEASE before p2, and 11.3-RELEASE before p12, missing length validation code common to mulitple USB network drivers allows a malicious USB device to wri...

  • EPSS 1.51%
  • Veröffentlicht 06.08.2020 17:15:11
  • Zuletzt bearbeitet 21.11.2024 05:37:11

In FreeBSD 12.1-STABLE before r363918, 12.1-RELEASE before p8, 11.4-STABLE before r363919, 11.4-RELEASE before p2, and 11.3-RELEASE before p12, the sendmsg system call in the compat32 subsystem on 64-bit platforms has a time-of-check to time-of-use v...

Exploit
  • EPSS 44.58%
  • Veröffentlicht 09.07.2020 14:15:10
  • Zuletzt bearbeitet 21.11.2024 05:37:10

In FreeBSD 12.1-STABLE before r359565, 12.1-RELEASE before p7, 11.4-STABLE before r362975, 11.4-RELEASE before p1, and 11.3-RELEASE before p11, missing synchronization in the IPV6_2292PKTOPTIONS socket option set handler contained a race condition al...

  • EPSS 1.57%
  • Veröffentlicht 09.07.2020 14:15:10
  • Zuletzt bearbeitet 21.11.2024 05:37:11

In FreeBSD 12.1-STABLE before r362281, 11.4-STABLE before r362281, and 11.4-RELEASE before p1, long values in the user-controlled PATH environment variable cause posix_spawnp to write beyond the end of the heap allocated stack possibly leading to arb...

  • EPSS 0.15%
  • Veröffentlicht 09.06.2020 19:15:10
  • Zuletzt bearbeitet 21.11.2024 05:37:10

In FreeBSD 12.1-STABLE before r361918, 12.1-RELEASE before p6, 11.4-STABLE before r361919, 11.3-RELEASE before p10, and 11.4-RC2 before p1, an invalid memory location may be used for HID items if the push/pop level is not restored within the processi...

Exploit
  • EPSS 0.06%
  • Veröffentlicht 24.05.2020 22:15:10
  • Zuletzt bearbeitet 21.11.2024 05:01:15

SQLite through 3.32.0 has an integer overflow in sqlite3_str_vappendf in printf.c.

  • EPSS 0.63%
  • Veröffentlicht 13.05.2020 16:15:13
  • Zuletzt bearbeitet 21.11.2024 05:37:10

In FreeBSD 12.1-STABLE before r360971, 12.1-RELEASE before p5, 11.4-STABLE before r360971, 11.4-BETA1 before p1 and 11.3-RELEASE before p9, libalias does not properly validate packet length resulting in modules causing an out of bounds read/write con...