Vulnerability index

Browse CVEs

387 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

FreeBSD HIGH 7.1
CVE-2004-1471EPSS 8%

Format string vulnerability in wrapper.c in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16 allows remote attackers with CVSROOT commit access …

Patch available
Fix from $1,950 2004-12-31
FreeBSD HIGH 7.2
CVE-2004-0125

The jail system call in FreeBSD 4.x before 4.10-RELEASE does not verify that an attempt to manipulate routing tables originated from a non-jailed pro…

Patch available
Fix from $1,950 2004-08-06
FreeBSD MEDIUM 5.0
CVE-2004-0171

FreeBSD 5.1 and earlier, and Mac OS X before 10.3.4, allows remote attackers to cause a denial of service (resource exhaustion of memory buffers and …

Patch available
Fix from $1,600 2004-03-15
FreeBSD HIGH 10.0
CVE-2004-0002

The TCP MSS (maximum segment size) functionality in netinet allows remote attackers to cause a denial of service (resource exhaustion) via (1) a low …

Patch available
Fix from $1,950 2004-03-03
Slashem Tty HIGH 7.2
CVE-2003-1474

slashem-tty in the FreeBSD Ports Collection is installed with write permissions for the games group, which allows local users with group games privil…

Mitigation only
Fix from $1,950 2003-12-31
FreeBSD MEDIUM 5.0
CVE-2003-0804

The arplookup function in FreeBSD 5.1 and earlier, Mac OS X before 10.2.8, and possibly other BSD-based systems, allows remote attackers on a local s…

Mitigation only
Fix from $1,600 2003-11-17
FreeBSD HIGH 10.0
CVE-2003-0694EPSS 66%

The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the pars…

Patch available
Fix from $1,950 2003-10-06
FreeBSD HIGH 7.2
CVE-2003-0144

Buffer overflow in the lprm command in the lprold lpr package on SuSE 7.1 through 7.3, OpenBSD 3.2 and earlier, and possibly other operating systems,…

Patch available
Fix from $1,950 2003-03-31
FreeBSD HIGH 7.5
CVE-2003-0028EPSS 15%

Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC…

Patch available
Fix from $1,950 2003-03-25
FreeBSD HIGH 7.5
CVE-2003-0015EPSS 24%

Double-free vulnerability in CVS 1.11.4 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a ma…

Patch available
Fix from $1,950 2003-02-07
FreeBSD MEDIUM 5.0
CVE-2003-0001EPSS 73%

Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote attackers to obtain information …

Mitigation only
Fix from $1,600 2003-01-17
FreeBSD MEDIUM 5.5
CVE-2002-1915

tip on multiple BSD-based operating systems allows local users to cause a denial of service (execution prevention) by using flock() to lock the /var/…

Mitigation only
Fix from $1,600 2002-12-31
Ports Collection MEDIUM 5.1
CVE-2002-2222

isakmpd/message.c in isakmpd in FreeBSD before isakmpd-20020403_1, and in OpenBSD 3.1, allows remote attackers to cause a denial of service (crash) b…

Fix: after 2002-08-28
Fix from $1,600 2002-12-31
FreeBSD HIGH 7.5
CVE-2002-1219EPSS 12%

Buffer overflow in named in BIND 4 versions 4.9.10 and earlier, and 8 versions 8.3.3 and earlier, allows remote attackers to execute arbitrary code v…

Patch available
Fix from $1,950 2002-11-29
FreeBSD MEDIUM 5.0
CVE-2002-1220EPSS 10%

BIND 8.3.x through 8.3.3 allows remote attackers to cause a denial of service (termination due to assertion failure) via a request for a subdomain th…

Patch available
Fix from $1,600 2002-11-29
FreeBSD MEDIUM 5.0
CVE-2002-1221EPSS 8%

BIND 8.x through 8.3.3 allows remote attackers to cause a denial of service (crash) via SIG RR elements with invalid expiry times, which are removed …

Patch available
Fix from $1,600 2002-11-29
FreeBSD MEDIUM 5.0
CVE-2002-0666

IPSEC implementations including (1) FreeS/WAN and (2) KAME do not properly calculate the length of authentication data, which allows remote attackers…

No fix yet
Fix from $1,600 2002-11-04
FreeBSD CRITICAL 9.8
CVE-2002-0391EPSS 58%

Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, a…

Fix: after 4.6.1
Fix from $2,300 2002-08-12
FreeBSD HIGH 7.5
CVE-2002-0414

KAME-derived implementations of IPsec on NetBSD 1.5.2, FreeBSD 4.5, and other operating systems, does not properly consult the Security Policy Databa…

Patch available
Fix from $1,950 2002-08-12
Heimdal HIGH 7.2
CVE-2002-0754

Kerberos 5 su (k5su) in FreeBSD 4.4 and earlier relies on the getlogin system call to determine if the user running k5su is root, which could allow a…

Patch available
Fix from $1,950 2002-08-12
FreeBSD HIGH 7.2
CVE-2002-0755

Kerberos 5 su (k5su) in FreeBSD 4.5 and earlier does not verify that a user is a member of the wheel group before granting superuser privileges, whic…

Patch available
Fix from $1,950 2002-08-12
FreeBSD HIGH 7.2
CVE-2002-0820

FreeBSD kernel 4.6 and earlier closes the file descriptors 0, 1, and 2 after they have already been assigned to /dev/null when the descriptors refere…

Mitigation only
Fix from $1,950 2002-08-12
Point To Point Protocol Daemon MEDIUM 6.9
CVE-2002-0824

BSD pppd allows local users to change the permissions of arbitrary files via a symlink attack on a file that is specified as a tty device.

Mitigation only
Fix from $1,600 2002-08-12
FreeBSD MEDIUM 5.0
CVE-2002-0518

The SYN cache (syncache) and SYN cookie (syncookie) mechanism in FreeBSD 4.5 and earlier allows remote attackers to cause a denial of service (crash)…

Patch available
Fix from $1,600 2002-08-12
FreeBSD MEDIUM 5.0
CVE-2002-0794

The accept_filter mechanism in FreeBSD 4 through 4.5 does not properly remove entries from the incomplete listen queue when adding a syncache, which …

Patch available
Fix from $1,600 2002-08-12
FreeBSD MEDIUM 5.0
CVE-2002-0830

Network File System (NFS) in FreeBSD 4.6.1 RELEASE-p7 and earlier, NetBSD 1.5.3 and earlier, and possibly other operating systems, allows remote atta…

Fix: after 4.6.1
Fix from $1,600 2002-08-12
FreeBSD HIGH 7.2
CVE-2002-0572

FreeBSD 4.5 and earlier, and possibly other BSD-based operating systems, allows local users to write to or read from restricted files by closing the …

Patch available
Fix from $1,950 2002-07-03
FreeBSD MEDIUM 5.0
CVE-2002-0574

Memory leak in FreeBSD 4.5 and earlier allows remote attackers to cause a denial of service (memory exhaustion) via ICMP echo packets that trigger a …

Fix: after 4.5
Fix from $1,600 2002-07-03
FreeBSD MEDIUM 5.0
CVE-2002-0381

The TCP implementation in various BSD operating systems (tcp_input.c) does not properly block connections to broadcast addresses, which could allow r…

Fix: after 4.5
Fix from $1,600 2002-06-25
FreeBSD MEDIUM 6.2
CVE-2001-1185

Some AIO operations in FreeBSD 4.4 may be delayed until after a call to execve, which could allow a local user to overwrite memory of the new process…

Patch available
Fix from $1,600 2001-12-10