Vulnerability index

Browse CVEs

387 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

FreeBSD HIGH 7.5
CVE-2016-1888

The telnetd service in FreeBSD 9.3, 10.1, 10.2, 10.3, and 11.0 allows remote attackers to inject arguments to login and bypass authentication via vec…

Mitigation only
Fix from $1,950 2017-02-15
FreeBSD MEDIUM 5.5
CVE-2015-5677

bsnmpd, as used in FreeBSD 9.3, 10.1, and 10.2, uses world-readable permissions on the snmpd.config file, which allows local users to obtain the secr…

Patch available
Fix from $1,600 2017-02-07
FreeBSD MEDIUM 6.5
CVE-2015-7973

NTP before 4.2.8p6 and 4.3.x before 4.3.90, when configured in broadcast mode, allows man-in-the-middle attackers to conduct replay attacks by sniffi…

Fix: 4.2.8 / 4.3.90+
Fix from $1,600 2017-01-30
FreeBSD HIGH 7.8
CVE-2016-1887

Integer signedness error in the sockargs function in sys/kern/uipc_syscalls.c in FreeBSD 10.1 before p34, 10.2 before p17, and 10.3 before p3 allows …

No fix yet
Fix from $1,950 2016-05-25
FreeBSD HIGH 7.8
CVE-2016-1886

Integer signedness error in the genkbd_commonioctl function in sys/dev/kbd/kbd.c in FreeBSD 9.3 before p42, 10.1 before p34, 10.2 before p17, and 10.…

Patch available
Fix from $1,950 2016-05-25
FreeBSD MEDIUM 6.2
CVE-2016-1885

Integer signedness error in the amd64_set_ldt function in sys/amd64/amd64/sys_machdep.c in FreeBSD 9.3 before p39, 10.1 before p31, and 10.2 before p…

No fix yet
Fix from $1,600 2016-04-12
FreeBSD HIGH 7.5
CVE-2016-1882

FreeBSD 9.3 before p33, 10.1 before p26, and 10.2 before p9 allow remote attackers to cause a denial of service (kernel crash) via vectors related to…

Patch available
Fix from $1,950 2016-01-29
FreeBSD HIGH 7.5
CVE-2016-1879EPSS 13%

The Stream Control Transmission Protocol (SCTP) module in FreeBSD 9.3 before p33, 10.1 before p26, and 10.2 before p9, when the kernel is configured …

No fix yet
Fix from $1,950 2016-01-29
FreeBSD MEDIUM 6.9
CVE-2014-8611

The __sflush function in fflush.c in stdio in libc in FreeBSD 10.1 and the kernel in Apple iOS before 9 mishandles failures of the write system call,…

Fix: after 10.10.5
Fix from $1,600 2015-09-18
FreeBSD HIGH 7.8
CVE-2014-8613

The sctp module in FreeBSD 10.1 before p5, 10.0 before p17, 9.3 before p9, and 8.4 before p23 allows remote attackers to cause a denial of service (N…

Mitigation only
Fix from $1,950 2015-02-02
FreeBSD HIGH 7.2
CVE-2014-0998

Integer signedness error in the vt console driver (formerly Newcons) in FreeBSD 9.3 before p10 and 10.1 before p6 allows local users to cause a denia…

No fix yet
Fix from $1,950 2015-02-02
FreeBSD MEDIUM 5.0
CVE-2014-8117EPSS 6%

softmagic.c in file before 5.21 does not properly limit recursion, which allows remote attackers to cause a denial of service (CPU consumption or cra…

Fix: after 5.20
Fix from $1,600 2014-12-17
FreeBSD MEDIUM 5.0
CVE-2014-8116

The ELF parser (readelf.c) in file before 5.21 allows remote attackers to cause a denial of service (CPU consumption or crash) via a large number of …

Patch available
Fix from $1,600 2014-12-17
FreeBSD MEDIUM 5.0
CVE-2014-7250

The TCP stack in 4.3BSD Net/2, as used in FreeBSD 5.4, NetBSD possibly 2.0, and OpenBSD possibly 3.6, does not properly implement the session timer, …

Mitigation only
Fix from $1,600 2014-12-12
FreeBSD HIGH 10.0
CVE-2014-3954

Stack-based buffer overflow in rtsold in FreeBSD 9.1 through 10.1-RC2 allows remote attackers to cause a denial of service (crash) or possibly execut…

Patch available
Fix from $1,950 2014-10-27
FreeBSD MEDIUM 5.0
CVE-2014-3711

namei in FreeBSD 9.1 through 10.1-RC2 allows remote attackers to cause a denial of service (memory exhaustion) via vectors that trigger a sandboxed p…

Patch available
Fix from $1,600 2014-10-27
FreeBSD MEDIUM 5.0
CVE-2014-3955

routed in FreeBSD 8.4 through 10.1-RC2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via an RIP request fr…

Patch available
Fix from $1,600 2014-10-27
FreeBSD MEDIUM 5.0
CVE-2014-3951

The HZ module in the iconv implementation in FreeBSD 10.0 before p6 and NetBSD allows context-dependent attackers to cause a denial of service (NULL …

Mitigation only
Fix from $1,600 2014-08-21
FreeBSD MEDIUM 5.0
CVE-2014-5384

The VIQR module in the iconv implementation in FreeBSD 10.0 before p6 and NetBSD allows context-dependent attackers to cause a denial of service (out…

Mitigation only
Fix from $1,600 2014-08-21
FreeBSD HIGH 7.8
CVE-2014-3000EPSS 13%

The TCP reassembly function in the inet module in FreeBSD 8.3 before p16, 8.4 before p9, 9.1 before p12, 9.2 before p5, and 10.0 before p2 allows rem…

Mitigation only
Fix from $1,950 2014-05-02
FreeBSD MEDIUM 5.8
CVE-2014-3001

The device file system (aka devfs) in FreeBSD 10.0 before p2 does not load default rulesets when booting, which allows context-dependent attackers to…

Mitigation only
Fix from $1,600 2014-05-02
FreeBSD MEDIUM 5.8
CVE-2014-1452

Stack-based buffer overflow in lib/snmpagent.c in bsnmpd, as used in FreeBSD 8.3 through 10.0, allows remote attackers to cause a denial of service (…

Mitigation only
Fix from $1,600 2014-01-21
FreeBSD MEDIUM 6.9
CVE-2013-5691

The (1) IPv6 and (2) ATM ioctl request handlers in the kernel in FreeBSD 8.3 through 9.2-STABLE do not validate SIOCSIFADDR, SIOCSIFBRDADDR, SIOCSIFD…

Patch available
Fix from $1,600 2013-09-23
FreeBSD HIGH 7.8
CVE-2013-5209

The sctp_send_initiate_ack function in sys/netinet/sctp_output.c in the SCTP implementation in the kernel in FreeBSD 8.3 through 9.2-PRERELEASE does …

Patch available
Fix from $1,950 2013-08-29
FreeBSD HIGH 7.2
CVE-2013-3077

Multiple integer overflows in the IP_MSFILTER and IPV6_MSFILTER features in (1) sys/netinet/in_mcast.c and (2) sys/netinet6/in6_mcast.c in the multic…

Patch available
Fix from $1,950 2013-08-28
FreeBSD MEDIUM 6.4
CVE-2013-4851

The vfs_hang_addrlist function in sys/kern/vfs_export.c in the NFS server implementation in the kernel in FreeBSD 8.3 and 9.x through 9.1-RELEASE-p5 …

Mitigation only
Fix from $1,600 2013-07-29
FreeBSD HIGH 7.8
CVE-2013-4854EPSS 34%

The RFC 5011 implementation in rdata.c in ISC BIND 9.7.x and 9.8.x before 9.8.5-P2, 9.8.6b1, 9.9.x before 9.9.3-P2, and 9.9.4b1, and DNSco BIND 9.9.3…

Mitigation only
Fix from $1,950 2013-07-29
FreeBSD MEDIUM 6.9
CVE-2013-2171EPSS 7%

The vm_map_lookup function in sys/vm/vm_map.c in the mmap implementation in the kernel in FreeBSD 9.0 through 9.1-RELEASE-p4 does not properly determ…

Mitigation only
Fix from $1,600 2013-07-02
FreeBSD HIGH 7.5
CVE-2013-3266

The nfsrvd_readdir function in sys/fs/nfsserver/nfs_nfsdport.c in the new NFS server in FreeBSD 8.0 through 9.1-RELEASE-p3 does not verify that a REA…

Patch available
Fix from $1,950 2013-05-02
FreeBSD HIGH 7.8
CVE-2012-3549EPSS 8%

The SCTP implementation in FreeBSD 8.2 allows remote attackers to cause a denial of service (NULL pointer dereference and kernel panic) via a crafted…

No fix yet
Fix from $1,950 2012-10-09