Lucene search

K

Freebsd Security Vulnerabilities

cve
cve

CVE-2006-0905

A "programming error" in fast_ipsec in FreeBSD 4.8-RELEASE through 6.1-STABLE and NetBSD 2 through 3 does not properly update the sequence number associated with a Security Association, which allows packets to pass sequence number checks and allows remote attackers to capture IPSec packets and...

6.4AI Score

0.018EPSS

2006-03-23 11:06 AM
19
cve
cve

CVE-2006-0883

OpenSSH on FreeBSD 5.3 and 5.4, when used with OpenPAM, does not properly handle when a forked child process terminates during PAM authentication, which allows remote attackers to cause a denial of service (client connection refusal) by connecting multiple times to the SSH server, waiting for the.....

6.6AI Score

0.045EPSS

2006-03-07 02:02 AM
51
cve
cve

CVE-2006-0900

nfsd in FreeBSD 6.0 kernel allows remote attackers to cause a denial of service via a crafted NFS mount request, as demonstrated by the ProtoVer NFS test...

6AI Score

0.966EPSS

2006-02-27 07:06 PM
91
cve
cve

CVE-2006-0433

Selective Acknowledgement (SACK) in FreeBSD 5.3 and 5.4 does not properly handle an incoming selective acknowledgement when there is insufficient memory, which might allow remote attackers to cause a denial of service (infinite...

6.5AI Score

0.066EPSS

2006-02-02 11:02 AM
16
cve
cve

CVE-2006-0380

A logic error in FreeBSD kernel 5.4-STABLE and 6.0 causes the kernel to calculate an incorrect buffer length, which causes more data to be copied to userland than intended, which could allow local users to read portions of kernel...

6AI Score

0.0004EPSS

2006-01-25 10:03 PM
23
cve
cve

CVE-2006-0381

A logic error in the IP fragment cache functionality in pf in FreeBSD 5.3, 5.4, and 6.0, and OpenBSD, when a 'scrub fragment crop' or 'scrub fragment drop-ovl' rule is being used, allows remote attackers to cause a denial of service (crash) via crafted packets that cause a packet fragment to be...

6.4AI Score

0.042EPSS

2006-01-25 10:03 PM
23
cve
cve

CVE-2006-0379

FreeBSD kernel 5.4-STABLE and 6.0 does not completely initialize a buffer before making it available to userland, which could allow local users to read portions of kernel...

6.1AI Score

0.0004EPSS

2006-01-25 10:03 PM
21
cve
cve

CVE-2006-0226

Integer overflow in IEEE 802.11 network subsystem (ieee80211_ioctl.c) in FreeBSD before 6.0-STABLE, while scanning for wireless networks, allows remote attackers to execute arbitrary code by broadcasting crafted (1) beacon or (2) probe response...

7.8AI Score

0.084EPSS

2006-01-19 01:03 AM
24
cve
cve

CVE-2006-0055

The ispell_op function in ee on FreeBSD 4.10 to 6.0 uses predictable filenames and does not confirm which file is being written, which allows local users to overwrite arbitrary files via a symlink attack when ee invokes...

6.2AI Score

0.0004EPSS

2006-01-11 09:03 PM
20
cve
cve

CVE-2005-4351

The securelevels implementation in FreeBSD 7.0 and earlier, OpenBSD up to 3.8, DragonFly up to 1.2, and Linux up to 2.6.15 allows root users to bypass immutable settings for files by mounting another filesystem that masks the immutable files while the system is...

6.5AI Score

0.001EPSS

2006-01-09 08:00 PM
28
2
cve
cve

CVE-2003-1289

The iBCS2 system call translator for statfs in NetBSD 1.5 through 1.5.3 and FreeBSD 4 up to 4.8-RELEASE-p2 and 5 up to 5.1-RELEASE-p1 allows local users to read portions of kernel memory (memory disclosure) via a large length parameter, which copies additional kernel memory into userland...

6.5AI Score

0.0004EPSS

2005-12-17 09:00 PM
20
cve
cve

CVE-2003-1234

Integer overflow in the f_count counter in FreeBSD before 4.2 through 5.0 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via multiple calls to (1) fpathconf and (2) lseek, which do not properly decrement f_count through a call to...

7.9AI Score

0.001EPSS

2005-11-16 07:37 AM
16
cve
cve

CVE-2003-1230

The implementation of SYN cookies (syncookies) in FreeBSD 4.5 through 5.0-RELEASE-p3 uses only 32-bit internal keys when generating syncookies, which makes it easier for remote attackers to conduct brute force ISN guessing attacks and spoof legitimate...

7.5AI Score

0.009EPSS

2005-08-17 04:00 AM
24
cve
cve

CVE-2002-2092

Race condition in exec in OpenBSD 4.0 and earlier, NetBSD 1.5.2 and earlier, and FreeBSD 4.4 and earlier allows local users to gain privileges by attaching a debugger to a process before the kernel has determined that the process is setuid or...

6.9AI Score

0.0004EPSS

2005-08-05 04:00 AM
32
cve
cve

CVE-2005-2359

The AES-XCBC-MAC algorithm in IPsec in FreeBSD 5.3 and 5.4, when used for authentication without other encryption, uses a constant key instead of the one that was assigned by the system administrator, which can allow remote attackers to spoof packets to establish an IPsec...

6.7AI Score

0.011EPSS

2005-08-05 04:00 AM
19
cve
cve

CVE-2005-2218

The device file system (devfs) in FreeBSD 5.x does not properly check parameters of the node type when creating a device node, which makes hidden devices available to attackers, who can then bypass restrictions on a jailed...

6.4AI Score

0.001EPSS

2005-07-26 04:00 AM
25
cve
cve

CVE-2002-1674

procfs on FreeBSD before 4.5 allows local users to cause a denial of service (kernel panic) by removing a file that the fstatfs function refers...

6.6AI Score

0.0004EPSS

2005-06-21 04:00 AM
31
cve
cve

CVE-2002-1669

pkg_add in FreeBSD 4.2 through 4.4 creates a temporary directory with world-searchable permissions, which may allow local users to modify world-writable parts of the package during...

6.6AI Score

0.0004EPSS

2005-06-21 04:00 AM
24
cve
cve

CVE-2002-1667

The virtual memory management system in FreeBSD 4.5-RELEASE and earlier does not properly check the existence of a VM object during page invalidation, which allows local users to cause a denial of service (crash) by calling msync on an unaccessed memory map created with MAP_ANON and MAP_NOSYNC...

6.6AI Score

0.0004EPSS

2005-06-21 04:00 AM
23
cve
cve

CVE-2005-0356

Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connection loss) via a spoofed packet with a large timer value, which causes the host to discard later packets because they...

6.2AI Score

0.931EPSS

2005-05-31 04:00 AM
44
2
cve
cve

CVE-2005-1406

The kernel in FreeBSD 4.x to 4.11 and 5.x to 5.4 does not properly clear certain fixed-length buffers when copying variable-length data for use by applications, which could allow those applications to read previously used sensitive...

6AI Score

0.001EPSS

2005-05-06 04:00 AM
23
cve
cve

CVE-2005-0988

Race condition in gzip 1.2.4, 1.3.3, and earlier, when decompressing a gzipped file, allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by gzip after the decompression is...

5.9AI Score

0.001EPSS

2005-05-02 04:00 AM
50
cve
cve

CVE-2005-0708

The sendfile system call in FreeBSD 4.8 through 4.11 and 5 through 5.4 can transfer portions of kernel memory if a file is truncated while it is being sent, which could allow remote attackers to obtain sensitive...

6.1AI Score

0.007EPSS

2005-05-02 04:00 AM
25
cve
cve

CVE-2005-1126

The SIOCGIFCONF ioctl (ifconf function) in FreeBSD 4.x through 4.11 and 5.x through 5.4 does not properly clear a buffer before using it, which allows local users to obtain portions of sensitive kernel...

6AI Score

0.0004EPSS

2005-04-16 04:00 AM
16
cve
cve

CVE-2005-0610

Multiple symlink vulnerabilities in portupgrade before 20041226_2 in FreeBSD allow local users to (1) overwrite arbitrary files and possibly replace packages to execute arbitrary code via pkg_fetch, (2) overwrite arbitrary files via temporary files when portupgrade upgrades a port or package, or...

7.4AI Score

0.0004EPSS

2005-04-13 04:00 AM
20
cve
cve

CVE-2005-0109

Hyper-Threading technology, as used in FreeBSD and other operating systems that are run on Intel Pentium and other processors, allows local users to use a malicious thread to create covert channels, monitor the execution of other threads, and obtain sensitive information such as cryptographic...

5.6CVSS

5.4AI Score

0.001EPSS

2005-03-08 05:00 AM
51
cve
cve

CVE-2004-1053

Integer overflow in fetch on FreeBSD 4.1 through 5.3 allows remote malicious servers to execute arbitrary code via certain HTTP headers in an HTTP response, which lead to a buffer...

8AI Score

0.005EPSS

2005-03-01 05:00 AM
21
cve
cve

CVE-2004-0919

The syscons CONS_SCRSHOT ioctl in FreeBSD 5.x allows local users to read arbitrary kernel memory via (1) negative coordinates or (2) large...

6AI Score

0.0004EPSS

2005-02-13 05:00 AM
24
cve
cve

CVE-2004-1471

Format string vulnerability in wrapper.c in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16 allows remote attackers with CVSROOT commit access to cause a denial of service (application crash) and possibly execute arbitrary code via format string specifiers in a wrapper...

7.7AI Score

0.014EPSS

2005-02-13 05:00 AM
26
cve
cve

CVE-2004-1066

The cmdline pseudofiles in (1) procfs on FreeBSD 4.8 through 5.3, and (2) linprocfs on FreeBSD 5.x through 5.3, do not properly validate a process argument vector, which allows local users to cause a denial of service (panic) or read portions of kernel memory. NOTE: this candidate might be SPLIT...

6AI Score

0.0004EPSS

2005-01-10 05:00 AM
19
cve
cve

CVE-2004-0602

The binary compatibility mode for FreeBSD 4.x and 5.x does not properly handle certain Linux system calls, which could allow local users to access kernel memory to gain privileges or cause a system...

6.4AI Score

0.0004EPSS

2004-12-06 05:00 AM
33
cve
cve

CVE-2004-0618

FreeBSD 5.1 for the Alpha processor allows local users to cause a denial of service (crash) via an execve system call with an unaligned memory address as an...

6.6AI Score

0.0004EPSS

2004-12-06 05:00 AM
23
cve
cve

CVE-2004-0081

OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test...

7.2AI Score

0.003EPSS

2004-11-23 05:00 AM
50
cve
cve

CVE-2004-0114

The shmat system call in the System V Shared Memory interface for FreeBSD 5.2 and earlier, NetBSD 1.3 and earlier, and OpenBSD 2.6 and earlier, does not properly decrement a shared memory segment's reference count when the vm_map_find function fails, which could allow local users to gain read or...

6.2AI Score

0.0004EPSS

2004-09-01 04:00 AM
21
cve
cve

CVE-2001-1029

libutil in OpenSSH on FreeBSD 4.4 and earlier does not drop privileges before verifying the capabilities for reading the copyright and welcome files, which allows local users to bypass the capabilities checks and read arbitrary files by specifying alternate copyright or welcome...

6.5AI Score

0.0004EPSS

2004-09-01 04:00 AM
33
cve
cve

CVE-2002-1221

BIND 8.x through 8.3.3 allows remote attackers to cause a denial of service (crash) via SIG RR elements with invalid expiry times, which are removed from the internal BIND database and later cause a null...

6.2AI Score

0.054EPSS

2004-09-01 04:00 AM
36
cve
cve

CVE-2002-1219

Buffer overflow in named in BIND 4 versions 4.9.10 and earlier, and 8 versions 8.3.3 and earlier, allows remote attackers to execute arbitrary code via a certain DNS server response containing SIG resource records...

7.5AI Score

0.136EPSS

2004-09-01 04:00 AM
35
cve
cve

CVE-2004-0171

FreeBSD 5.1 and earlier, and Mac OS X before 10.3.4, allows remote attackers to cause a denial of service (resource exhaustion of memory buffers and system crash) via a large number of out-of-sequence TCP packets, which prevents the operating system from creating new...

6.3AI Score

0.037EPSS

2004-09-01 04:00 AM
24
cve
cve

CVE-2004-0099

mksnap_ffs in FreeBSD 5.1 and 5.2 only sets the snapshot flag when creating a snapshot for a file system, which causes default values for other flags to be used, possibly disabling security-critical settings and allowing a local user to bypass intended access...

6.3AI Score

0.0004EPSS

2004-09-01 04:00 AM
20
cve
cve

CVE-2004-0126

The jail_attach system call in FreeBSD 5.1 and 5.2 changes the directory of a calling process even if the process doesn't have permission to change directory, which allows local users to gain read/write privileges to files and directories within another...

6.3AI Score

0.0004EPSS

2004-09-01 04:00 AM
16
cve
cve

CVE-2002-1220

BIND 8.3.x through 8.3.3 allows remote attackers to cause a denial of service (termination due to assertion failure) via a request for a subdomain that does not exist, with an OPT resource record with a large UDP payload...

6.3AI Score

0.152EPSS

2004-09-01 04:00 AM
55
cve
cve

CVE-2003-0015

Double-free vulnerability in CVS 1.11.4 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a malformed Directory request, as demonstrated by bypassing write checks to execute Update-prog and Checkin-prog...

7.5AI Score

0.296EPSS

2004-09-01 04:00 AM
32
cve
cve

CVE-2004-0435

Certain "programming errors" in the msync system call for FreeBSD 5.2.1 and earlier, and 4.10 and earlier, do not properly handle the MS_INVALIDATE operation, which leads to cache consistency problems that allow a local user to prevent certain changes to files from being committed to...

6.2AI Score

0.0004EPSS

2004-08-18 04:00 AM
19
cve
cve

CVE-2004-0125

The jail system call in FreeBSD 4.x before 4.10-RELEASE does not verify that an attempt to manipulate routing tables originated from a non-jailed process, which could allow local users to modify the routing...

6AI Score

0.0004EPSS

2004-08-06 04:00 AM
22
cve
cve

CVE-2004-0370

The setsockopt call in the KAME Project IPv6 implementation, as used in FreeBSD 5.2, does not properly handle certain IPv6 socket options, which could allow attackers to read kernel memory and cause a system...

6.1AI Score

0.001EPSS

2004-05-04 04:00 AM
23
cve
cve

CVE-2004-0002

The TCP MSS (maximum segment size) functionality in netinet allows remote attackers to cause a denial of service (resource exhaustion) via (1) a low MTU, which causes a large number of small packets to be produced, or (2) via a large number of packets with a small TCP payload, which cause a large.....

7AI Score

0.004EPSS

2004-03-03 05:00 AM
24
cve
cve

CVE-2003-0914

ISC BIND 8.3.x before 8.3.7, and 8.4.x before 8.4.3, allows remote attackers to poison the cache via a malicious name server that returns negative responses with a large TTL (time-to-live)...

6.2AI Score

0.02EPSS

2003-12-15 05:00 AM
35
cve
cve

CVE-2003-0804

The arplookup function in FreeBSD 5.1 and earlier, Mac OS X before 10.2.8, and possibly other BSD-based systems, allows remote attackers on a local subnet to cause a denial of service (resource starvation and panic) via a flood of spoofed ARP...

6.6AI Score

0.011EPSS

2003-11-17 05:00 AM
26
cve
cve

CVE-2003-0688

The DNS map code in Sendmail 8.12.8 and earlier, when using the "enhdnsbl" feature, does not properly initialize certain data structures, which allows remote attackers to cause a denial of service (process crash) via an invalid DNS response that causes Sendmail to free incorrect...

6.7AI Score

0.129EPSS

2003-10-20 04:00 AM
22
cve
cve

CVE-2003-0694

The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in...

7.7AI Score

0.057EPSS

2003-10-06 04:00 AM
60
Total number of security vulnerabilities498