Vulnerability index

Browse CVEs

387 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

FreeBSD MEDIUM 5.0
CVE-2006-7252

Integer overflow in the calloc function in libc/stdlib/malloc.c in jemalloc in libc for FreeBSD 6.4 and NetBSD makes it easier for context-dependent …

Patch available
Fix from $1,600 2012-07-25
FreeBSD MEDIUM 5.0
CVE-2007-6754

The ipalloc function in libc/stdlib/malloc.c in jemalloc in libc for FreeBSD 6.4 and NetBSD does not properly allocate memory, which makes it easier …

Patch available
Fix from $1,600 2012-07-25
FreeBSD HIGH 7.2
CVE-2012-0217EPSS 37%

The x86-64 kernel system-call functionality in Xen 4.1.2 and earlier, as used in Citrix XenServer 6.0.2 and earlier and other products; Oracle Solari…

Fix: after 20120614
Fix from $1,950 2012-06-12
Libarchive HIGH 7.5
CVE-2010-4666

Buffer overflow in libarchive 3.0 pre-release code allows remote attackers to cause a denial of service (application crash) or possibly have unspecif…

Mitigation only
Fix from $1,950 2012-04-13
Libarchive HIGH 7.5
CVE-2011-1779

Multiple use-after-free vulnerabilities in libarchive 2.8.4 and 2.8.5 allow remote attackers to cause a denial of service (application crash) or poss…

Mitigation only
Fix from $1,950 2012-04-13
Libarchive MEDIUM 6.8
CVE-2011-1777

Multiple buffer overflows in the (1) heap_add_entry and (2) relocate_dir functions in archive_read_support_format_iso9660.c in libarchive through 2.8…

Fix: after 2.8.5
Fix from $1,600 2012-04-13
Libarchive MEDIUM 6.8
CVE-2011-1778

Buffer overflow in libarchive through 2.8.5 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary co…

Fix: after 2.8.5
Fix from $1,600 2012-04-13
FreeBSD HIGH 7.8
CVE-2011-2393

The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in FreeBSD, NetBSD, and possibly other BSD-based operating systems allows remot…

Mitigation only
Fix from $1,950 2012-02-02
FreeBSD HIGH 10.0
CVE-2011-4862EPSS 95%

Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and earlier, …

Fix: 1.9+
Fix from $1,950 2011-12-25
FreeBSD MEDIUM 6.9
CVE-2011-4122

Directory traversal vulnerability in openpam_configure.c in OpenPAM before r478 on FreeBSD 8.1 allows local users to load arbitrary DSOs and gain pri…

No fix yet
Fix from $1,600 2011-11-17
FreeBSD HIGH 7.2
CVE-2011-4062

Buffer overflow in the kernel in FreeBSD 7.3 through 9.0-RC1 allows local users to cause a denial of service (panic) or possibly gain privileges via …

Patch available
Fix from $1,950 2011-10-18
FreeBSD HIGH 9.3
CVE-2011-2895EPSS 8%

The LZW decompressor in (1) the BufCompressedFill function in fontfile/decompress.c in X.Org libXfont before 1.4.4 and (2) compress/compress.c in 4.3…

Fix: after 3.7
Fix from $1,950 2011-08-19
FreeBSD HIGH 7.8
CVE-2010-4210

The pfs_getextattr function in FreeBSD 7.x before 7.3-RELEASE and 8.x before 8.0-RC1 unlocks a mutex that was not previously locked, which allows loc…

Fix: 7.3+
Fix from $1,950 2010-11-22
FreeBSD HIGH 7.2
CVE-2010-2693

FreeBSD 7.1 through 8.1-PRERELEASE does not copy the read-only flag when creating a duplicate mbuf buffer reference, which allows local users to caus…

Patch available
Fix from $1,950 2010-07-13
FreeBSD HIGH 9.3
CVE-2010-1938EPSS 22%

Off-by-one error in the __opiereadrec function in readrec.c in libopie in OPIE 2.4.1-test1 and earlier, as used on FreeBSD 6.4 through 8.1-PRERELEASE…

Fix: after 2.4.1
Fix from $1,950 2010-05-28
FreeBSD MEDIUM 6.9
CVE-2010-2020

sys/nfsclient/nfs_vfsops.c in the NFS client in the kernel in FreeBSD 7.2 through 8.1-PRERELEASE, when vfs.usermount is enabled, does not validate th…

No fix yet
Fix from $1,600 2010-05-28
FreeBSD MEDIUM 6.9
CVE-2010-0318

The replay functionality for ZFS Intent Log (ZIL) in FreeBSD 7.1, 7.2, and 8.0, when creating files during replay of a setattr transaction, uses 7777…

Patch available
Fix from $1,600 2010-01-15
FreeBSD HIGH 7.2
CVE-2009-4147

The _rtld function in the Run-Time Link-Editor (rtld) in libexec/rtld-elf/rtld.c in FreeBSD 7.1 and 8.0 does not clear the (1) LD_LIBMAP, (2) LD_LIBR…

Patch available
Fix from $1,950 2009-12-02
FreeBSD HIGH 7.2
CVE-2009-4146

The _rtld function in the Run-Time Link-Editor (rtld) in libexec/rtld-elf/rtld.c in FreeBSD 7.1, 7.2, and 8.0 does not clear the LD_PRELOAD environme…

Patch available
Fix from $1,950 2009-12-02
FreeBSD MEDIUM 6.9
CVE-2009-3527

Race condition in the Pipe (IPC) close function in FreeBSD 6.3 and 6.4 allows local users to cause a denial of service (crash) or gain privileges via…

Patch available
Fix from $1,600 2009-10-06
FreeBSD HIGH 7.2
CVE-2009-1041

The ktimer feature (sys/kern/kern_time.c) in FreeBSD 7.0, 7.1, and 7.2 allows local users to overwrite arbitrary kernel memory via an out-of-bounds t…

No fix yet
Fix from $1,950 2009-03-26
FreeBSD HIGH 9.3
CVE-2009-0641EPSS 9%

sys_term.c in telnetd in FreeBSD 7.0-RELEASE and other 7.x versions deletes dangerous environment variables with a method that was valid only in olde…

Patch available
Fix from $1,950 2009-02-20
FreeBSD HIGH 7.2
CVE-2008-5736

Multiple unspecified vulnerabilities in FreeBSD 6 before 6.4-STABLE, 6.3 before 6.3-RELEASE-p7, 6.4 before 6.4-RELEASE-p1, 7.0 before 7.0-RELEASE-p7,…

No fix yet
Fix from $1,950 2008-12-26
FreeBSD HIGH 7.0
CVE-2008-5162

The arc4random function in the kernel in FreeBSD 6.3 through 7.1 does not have a proper entropy source for a short time period immediately after boot…

Fix: 7.0+
Fix from $1,950 2008-11-26
Freebsd Sendpr MEDIUM 6.9
CVE-2008-5142

sendbug in freebsd-sendpr 3.113+5.3 on Debian GNU/Linux allows local users to overwrite arbitrary files via a symlink attack on a /tmp/pr.##### tempo…

Mitigation only
Fix from $1,600 2008-11-18
FreeBSD HIGH 9.3
CVE-2008-2476EPSS 7%

The IPv6 Neighbor Discovery Protocol (NDP) implementation in (1) FreeBSD 6.3 through 7.1, (2) OpenBSD 4.2 and 4.3, (3) NetBSD, (4) Force10 FTOS befor…

Fix: after 6.4
Fix from $1,950 2008-10-03
FreeBSD HIGH 7.5
CVE-2008-4247

ftpd in OpenBSD 4.3, FreeBSD 7.0, NetBSD 4.0, Solaris, and possibly other operating systems interprets long commands from an FTP client as multiple c…

No fix yet
Fix from $1,950 2008-09-25
FreeBSD HIGH 7.1
CVE-2008-2464

The mld_input function in sys/netinet6/mld6.c in the kernel in NetBSD 4.0, FreeBSD, and KAME, when INET6 is enabled, allows remote attackers to cause…

No fix yet
Fix from $1,950 2008-09-11
FreeBSD HIGH 7.2
CVE-2008-3890

The kernel in FreeBSD 6.3 through 7.0 on amd64 platforms can make an extra swapgs call after a General Protection Fault (GPF), which allows local use…

Mitigation only
Fix from $1,950 2008-09-05
FreeBSD HIGH 7.1
CVE-2008-3530

sys/netinet6/icmp6.c in the kernel in FreeBSD 6.3 through 7.1, NetBSD 3.0 through 4.0, and possibly other operating systems does not properly check t…

Patch available
Fix from $1,950 2008-09-05