Skip to main content

Vendor archive

freebsd CVEs

Beta · best-effort

542 CVEs tagged to vendor freebsd55 Critical, 224 High, 204 Medium, 59 Low, 0 Unrated.

CVE-2013-2171

Published Jul 2, 2013

The vm_map_lookup function in sys/vm/vm_map.c in the mmap implementation in the kernel in FreeBSD 9.0 through 9.1-RELEASE-p4 does not properly determine whether a task should have…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-3266

Published May 2, 2013

The nfsrvd_readdir function in sys/fs/nfsserver/nfs_nfsdport.c in the new NFS server in FreeBSD 8.0 through 9.1-RELEASE-p3 does not verify that a READDIR request is for a director…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-3549

Published Oct 9, 2012

The SCTP implementation in FreeBSD 8.2 allows remote attackers to cause a denial of service (NULL pointer dereference and kernel panic) via a crafted ASCONF chunk.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2012-4578

Published Aug 21, 2012

The geli encryption provider 7 before r239184 on FreeBSD 10 uses a weak Master Key, which makes it easier for local users to defeat a cryptographic protection mechanism via a brut…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-6754

Published Jul 25, 2012

The ipalloc function in libc/stdlib/malloc.c in jemalloc in libc for FreeBSD 6.4 and NetBSD does not properly allocate memory, which makes it easier for context-dependent attacker…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-7252

Published Jul 25, 2012

Integer overflow in the calloc function in libc/stdlib/malloc.c in jemalloc in libc for FreeBSD 6.4 and NetBSD makes it easier for context-dependent attackers to perform memory-re…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0217

Published Jun 12, 2012

The x86-64 kernel system-call functionality in Xen 4.1.2 and earlier, as used in Citrix XenServer 6.0.2 and earlier and other products; Oracle Solaris 11 and earlier; illumos befo…

CVSS 7.2 · High
evidence mentions
3
Buzz score
21.9

CVE-2011-1779

Published Apr 13, 2012

Multiple use-after-free vulnerabilities in libarchive 2.8.4 and 2.8.5 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other im…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-1778

Published Apr 13, 2012

Buffer overflow in libarchive through 2.8.5 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted TAR archive.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1777

Published Apr 13, 2012

Multiple buffer overflows in the (1) heap_add_entry and (2) relocate_dir functions in archive_read_support_format_iso9660.c in libarchive through 2.8.5 allow remote attackers to c…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4666

Published Apr 13, 2012

Buffer overflow in libarchive 3.0 pre-release code allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-2393

Published Feb 2, 2012

The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in FreeBSD, NetBSD, and possibly other BSD-based operating systems allows remote attackers to cause a denial…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2011-4862

Published Dec 25, 2011

Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and earlier, Heimdal 1.5.1 and earlier, GNU…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2011-4122

Published Nov 17, 2011

Directory traversal vulnerability in openpam_configure.c in OpenPAM before r478 on FreeBSD 8.1 allows local users to load arbitrary DSOs and gain privileges via a .. (dot dot) in…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4062

Published Oct 18, 2011

Buffer overflow in the kernel in FreeBSD 7.3 through 9.0-RC1 allows local users to cause a denial of service (panic) or possibly gain privileges via a bind system call with a long…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2011-1739

Published May 3, 2011

The makemask function in mountd.c in mountd in FreeBSD 7.4 through 8.2 does not properly handle a -network field specifying a CIDR block with a prefix length that is not an intege…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1074

Published Mar 4, 2011

crontab.c in crontab in FreeBSD allows local users to determine the existence of arbitrary directories via a command-line argument composed of a directory name concatenated with a…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2011-1073

Published Mar 4, 2011

crontab.c in crontab in FreeBSD and Apple Mac OS X allows local users to (1) determine the existence of arbitrary files via a symlink attack on a /tmp/crontab.XXXXXXXXXX temporary…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort
Showing 276-300 of 542 CVEsPage 12 of 22