Skip to main content

Vendor archive

freebsd CVEs

Beta · best-effort

542 CVEs tagged to vendor freebsd55 Critical, 224 High, 204 Medium, 59 Low, 0 Unrated.

CVE-2014-3955

Published Oct 27, 2014

routed in FreeBSD 8.4 through 10.1-RC2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via an RIP request from a source not on a directly…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3954

Published Oct 27, 2014

Stack-based buffer overflow in rtsold in FreeBSD 9.1 through 10.1-RC2 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via crafted D…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-3711

Published Oct 27, 2014

namei in FreeBSD 9.1 through 10.1-RC2 allows remote attackers to cause a denial of service (memory exhaustion) via vectors that trigger a sandboxed process to look up a large numb…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-5384

Published Aug 21, 2014

The VIQR module in the iconv implementation in FreeBSD 10.0 before p6 and NetBSD allows context-dependent attackers to cause a denial of service (out-of-bounds array access) via a…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3951

Published Aug 21, 2014

The HZ module in the iconv implementation in FreeBSD 10.0 before p6 and NetBSD allows context-dependent attackers to cause a denial of service (NULL pointer dereference) via a cra…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3953

Published Jul 15, 2014

FreeBSD 8.4 before p14, 9.1 before p17, 9.2 before p10, and 10.0 before p7 does not properly initialize certain data structures, which allows local users to obtain sensitive infor…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3952

Published Jul 15, 2014

FreeBSD 8.4 before p14, 9.1 before p17, 9.2 before p10, and 10.0 before p7 does not properly initialize the buffer between the header and data of a control message, which allows l…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3880

Published Jun 10, 2014

The (1) execve and (2) fexecve system calls in the FreeBSD kernel 8.4 before p11, 9.1 before p14, 9.2 before p7, and 10.0 before p4 destroys the virtual memory address space and m…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3873

Published Jun 10, 2014

The ktrace utility in the FreeBSD kernel 8.4 before p11, 9.1 before p14, 9.2 before p7, and 9.3-BETA1 before p1 uses an incorrect page fault kernel trace entry size, which allows…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-3001

Published May 2, 2014

The device file system (aka devfs) in FreeBSD 10.0 before p2 does not load default rulesets when booting, which allows context-dependent attackers to bypass intended restrictions…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3000

Published May 2, 2014

The TCP reassembly function in the inet module in FreeBSD 8.3 before p16, 8.4 before p9, 9.1 before p12, 9.2 before p5, and 10.0 before p2 allows remote attackers to cause a denia…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2014-1453

Published Apr 16, 2014

The NFS server (nfsserver) in FreeBSD 8.3 through 10.0 does not acquire locks in the proper order when converting a directory file handle to a vnode, which allows remote authentic…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-1452

Published Jan 21, 2014

Stack-based buffer overflow in lib/snmpagent.c in bsnmpd, as used in FreeBSD 8.3 through 10.0, allows remote attackers to cause a denial of service (daemon crash) and possibly exe…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6834

Published Nov 21, 2013

The ql_eioctl function in sys/dev/qlxgbe/ql_ioctl.c in the kernel in FreeBSD 10 and earlier does not validate a certain size parameter, which allows local users to obtain sensitiv…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6833

Published Nov 21, 2013

The qls_eioctl function in sys/dev/qlxge/qls_ioctl.c in the kernel in FreeBSD 10 and earlier does not validate a certain size parameter, which allows local users to obtain sensiti…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6832

Published Nov 21, 2013

The nand_ioctl function in sys/dev/nand/nand_geom.c in the nand driver in the kernel in FreeBSD 10 and earlier does not properly initialize a certain data structure, which allows…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-5710

Published Sep 23, 2013

The nullfs implementation in sys/fs/nullfs/null_vnops.c in the kernel in FreeBSD 8.3 through 9.2 allows local users with certain permissions to bypass access restrictions via a ha…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-5666

Published Sep 23, 2013

The sendfile system-call implementation in sys/kern/uipc_syscalls.c in the kernel in FreeBSD 9.2-RC1 and 9.2-RC2 does not properly pad transmissions, which allows local users to o…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-5691

Published Sep 23, 2013

The (1) IPv6 and (2) ATM ioctl request handlers in the kernel in FreeBSD 8.3 through 9.2-STABLE do not validate SIOCSIFADDR, SIOCSIFBRDADDR, SIOCSIFDSTADDR, and SIOCSIFNETMASK req…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-5209

Published Aug 29, 2013

The sctp_send_initiate_ack function in sys/netinet/sctp_output.c in the SCTP implementation in the kernel in FreeBSD 8.3 through 9.2-PRERELEASE does not properly initialize the st…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2013-3077

Published Aug 28, 2013

Multiple integer overflows in the IP_MSFILTER and IPV6_MSFILTER features in (1) sys/netinet/in_mcast.c and (2) sys/netinet6/in6_mcast.c in the multicast implementation in the kern…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2013-4851

Published Jul 29, 2013

The vfs_hang_addrlist function in sys/kern/vfs_export.c in the NFS server implementation in the kernel in FreeBSD 8.3 and 9.x through 9.1-RELEASE-p5 controls authorization for hos…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-4854

Published Jul 29, 2013

The RFC 5011 implementation in rdata.c in ISC BIND 9.7.x and 9.8.x before 9.8.5-P2, 9.8.6b1, 9.9.x before 9.9.3-P2, and 9.9.4b1, and DNSco BIND 9.9.3-S1 before 9.9.3-S1-P1 and 9.9…

CVSS 7.8 · High
Showing 251-275 of 542 CVEsPage 11 of 22