CVE-2020-7458
- EPSS 1.57%
- Veröffentlicht 09.07.2020 14:15:10
- Zuletzt bearbeitet 21.11.2024 05:37:11
In FreeBSD 12.1-STABLE before r362281, 11.4-STABLE before r362281, and 11.4-RELEASE before p1, long values in the user-controlled PATH environment variable cause posix_spawnp to write beyond the end of the heap allocated stack possibly leading to arb...
CVE-2020-7456
- EPSS 0.15%
- Veröffentlicht 09.06.2020 19:15:10
- Zuletzt bearbeitet 21.11.2024 05:37:10
In FreeBSD 12.1-STABLE before r361918, 12.1-RELEASE before p6, 11.4-STABLE before r361919, 11.3-RELEASE before p10, and 11.4-RC2 before p1, an invalid memory location may be used for HID items if the push/pop level is not restored within the processi...
CVE-2020-13434
- EPSS 0.06%
- Veröffentlicht 24.05.2020 22:15:10
- Zuletzt bearbeitet 21.11.2024 05:01:15
SQLite through 3.32.0 has an integer overflow in sqlite3_str_vappendf in printf.c.
CVE-2020-7454
- EPSS 0.63%
- Veröffentlicht 13.05.2020 16:15:13
- Zuletzt bearbeitet 21.11.2024 05:37:10
In FreeBSD 12.1-STABLE before r360971, 12.1-RELEASE before p5, 11.4-STABLE before r360971, 11.4-BETA1 before p1 and 11.3-RELEASE before p9, libalias does not properly validate packet length resulting in modules causing an out of bounds read/write con...
CVE-2020-7455
- EPSS 0.1%
- Veröffentlicht 13.05.2020 16:15:13
- Zuletzt bearbeitet 21.11.2024 05:37:10
In FreeBSD 12.1-STABLE before r360973, 12.1-RELEASE before p5, 11.4-STABLE before r360973, 11.4-BETA1 before p1 and 11.3-RELEASE before p9, the FTP packet handler in libalias incorrectly calculates some packet length allowing disclosure of small amou...
CVE-2019-15878
- EPSS 0.05%
- Veröffentlicht 13.05.2020 16:15:12
- Zuletzt bearbeitet 21.11.2024 04:29:39
In FreeBSD 12.1-STABLE before r352509, 11.3-STABLE before r352509, and 11.3-RELEASE before p9, an unprivileged local user can trigger a use-after-free situation due to improper checking in SCTP when an application tries to update an SCTP-AUTH shared ...
CVE-2019-15879
- EPSS 0.33%
- Veröffentlicht 13.05.2020 16:15:12
- Zuletzt bearbeitet 21.11.2024 04:29:39
In FreeBSD 12.1-STABLE before r356908, 12.1-RELEASE before p5, 11.3-STABLE before r356908, and 11.3-RELEASE before p9, a race condition in the cryptodev module permitted a data structure in the kernel to be used after it was freed, allowing an unpriv...
CVE-2019-15880
- EPSS 0.61%
- Veröffentlicht 13.05.2020 16:15:12
- Zuletzt bearbeitet 21.11.2024 04:29:40
In FreeBSD 12.1-STABLE before r356911, and 12.1-RELEASE before p5, insufficient checking in the cryptodev module allocated the size of a kernel buffer based on a user-supplied length allowing an unprivileged process to trigger a kernel panic.
CVE-2020-7452
- EPSS 0.98%
- Veröffentlicht 29.04.2020 00:15:12
- Zuletzt bearbeitet 21.11.2024 05:37:10
In FreeBSD 12.1-STABLE before r357490, 12.1-RELEASE before 12.1-RELEASE-p3, 11.3-STABLE before r357489, and 11.3-RELEASE before 11.3-RELEASE-p7, incorrect use of a user-controlled pointer in the epair virtual network module allowed vnet jailed privil...
- EPSS 0.06%
- Veröffentlicht 29.04.2020 00:15:12
- Zuletzt bearbeitet 21.11.2024 05:37:10
In FreeBSD 12.1-STABLE before r359021, 12.1-RELEASE before 12.1-RELEASE-p3, 11.3-STABLE before r359020, and 11.3-RELEASE before 11.3-RELEASE-p7, a missing null termination check in the jail_set configuration option "osrelease" may return more bytes w...