Vulnerability index

Browse CVEs

387 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

FreeBSD MEDIUM 6.9
CVE-2008-3531

Stack-based buffer overflow in sys/kern/vfs_mount.c in the kernel in FreeBSD 7.0 and 7.1, when vfs.usermount is enabled, allows local users to gain p…

Patch available
Fix from $1,600 2008-09-05
FreeBSD HIGH 7.5
CVE-2008-1391EPSS 19%

Multiple integer overflows in libc in NetBSD 4.x, FreeBSD 6.x and 7.x, and probably other BSD and Apple Mac OS platforms allow context-dependent atta…

No fix yet
Fix from $1,950 2008-03-27
FreeBSD MEDIUM 6.9
CVE-2008-0217

The script program in FreeBSD 5.0 through 7.0-PRERELEASE invokes openpty, which creates a pseudo-terminal with world-readable and world-writable perm…

Patch available
Fix from $1,600 2008-01-16
Libarchive HIGH 9.3
CVE-2007-3641EPSS 7%

archive_read_support_format_tar.c in libarchive before 2.2.4 does not properly compute the length of a certain buffer when processing a malformed pax…

Fix: after 2.2.3
Fix from $1,950 2007-07-14
FreeBSD MEDIUM 6.6
CVE-2007-0267

The ufs_lookup function in the Mac OS X 10.4.8 and FreeBSD 6.1 kernels allows local users to cause a denial of service (kernel panic) and possibly co…

Mitigation only
Fix from $1,600 2007-01-17
FreeBSD HIGH 7.2
CVE-2007-0229

Integer overflow in the ffs_mountfs function in Mac OS X 10.4.8 and FreeBSD 6.1 allows local users to cause a denial of service (panic) and possibly …

No fix yet
Fix from $1,950 2007-01-13
FreeBSD MEDIUM 6.6
CVE-2007-0166

The jail rc.d script in FreeBSD 5.3 up to 6.2 does not verify pathnames when writing to /var/log/console.log during a jail start-up, or when file sys…

Fix: after 6.2
Fix from $1,600 2007-01-11
FreeBSD HIGH 7.8
CVE-2006-6165

ld.so in FreeBSD, NetBSD, and possibly other BSD distributions does not remove certain harmful environment variables, which allows local users to gai…

Mitigation only
Fix from $1,950 2006-11-29
FreeBSD MEDIUM 5.0
CVE-2006-5680

The libarchive library in FreeBSD 6-STABLE after 2006-09-05 and before 2006-11-08 allows context-dependent attackers to cause a denial of service (CP…

No fix yet
Fix from $1,600 2006-11-09
FreeBSD HIGH 7.2
CVE-2006-4172

Integer overflow vulnerability in the i386_set_ldt call in FreeBSD 5.5, and possibly earlier versions down to 5.2, allows local users to cause a deni…

Fix: after 5.5
Fix from $1,950 2006-09-26
FreeBSD HIGH 10.0
CVE-2006-4304EPSS 12%

Buffer overflow in the sppp driver in FreeBSD 4.11 through 6.1, NetBSD 2.0 through 4.0 beta before 20060823, and OpenBSD 3.8 and 3.9 before 20060902 …

Patch available
Fix from $1,950 2006-08-24
FreeBSD MEDIUM 6.4
CVE-2006-2654

Directory traversal vulnerability in smbfs smbfs on FreeBSD 4.10 up to 6.1 allows local users to escape chroot restrictions for an SMB-mounted filesy…

Mitigation only
Fix from $1,600 2006-06-02
FreeBSD MEDIUM 6.4
CVE-2006-2655

The build process for ypserv in FreeBSD 5.3 up to 6.1 accidentally disables access restrictions when using the /var/yp/securenets file, which allows …

Patch available
Fix from $1,600 2006-06-02
FreeBSD HIGH 7.2
CVE-2006-1283

opiepasswd in One-Time Passwords in Everything (OPIE) in FreeBSD 4.10-RELEASE-p22 through 6.1-STABLE before 20060322 uses the getlogin function to de…

Patch available
Fix from $1,950 2006-03-23
FreeBSD HIGH 7.5
CVE-2006-0905

A "programming error" in fast_ipsec in FreeBSD 4.8-RELEASE through 6.1-STABLE and NetBSD 2 through 3 does not properly update the sequence number ass…

Patch available
Fix from $1,950 2006-03-23
FreeBSD MEDIUM 5.0
CVE-2006-0883

OpenSSH on FreeBSD 5.3 and 5.4, when used with OpenPAM, does not properly handle when a forked child process terminates during PAM authentication, wh…

Patch available
Fix from $1,600 2006-03-07
FreeBSD HIGH 7.8
CVE-2006-0900EPSS 65%

nfsd in FreeBSD 6.0 kernel allows remote attackers to cause a denial of service via a crafted NFS mount request, as demonstrated by the ProtoVer NFS …

Mitigation only
Fix from $1,950 2006-02-27
FreeBSD MEDIUM 5.0
CVE-2006-0433

Selective Acknowledgement (SACK) in FreeBSD 5.3 and 5.4 does not properly handle an incoming selective acknowledgement when there is insufficient mem…

Patch available
Fix from $1,600 2006-02-02
FreeBSD MEDIUM 5.0
CVE-2006-0381EPSS 7%

A logic error in the IP fragment cache functionality in pf in FreeBSD 5.3, 5.4, and 6.0, and OpenBSD, when a 'scrub fragment crop' or 'scrub fragment…

Patch available
Fix from $1,600 2006-01-25
FreeBSD HIGH 10.0
CVE-2006-0226EPSS 6%

Integer overflow in IEEE 802.11 network subsystem (ieee80211_ioctl.c) in FreeBSD before 6.0-STABLE, while scanning for wireless networks, allows remo…

Patch available
Fix from $1,950 2006-01-19
FreeBSD MEDIUM 5.3
CVE-2006-0054

The ipfw firewall in FreeBSD 6.0-RELEASE allows remote attackers to cause a denial of service (firewall crash) via ICMP IP fragments that match a res…

Patch available
Fix from $1,600 2006-01-11
FreeBSD MEDIUM 5.0
CVE-2005-2359

The AES-XCBC-MAC algorithm in IPsec in FreeBSD 5.3 and 5.4, when used for authentication without other encryption, uses a constant key instead of the…

Patch available
Fix from $1,600 2005-08-05
FreeBSD HIGH 7.2
CVE-2005-2218

The device file system (devfs) in FreeBSD 5.x does not properly check parameters of the node type when creating a device node, which makes hidden dev…

Mitigation only
Fix from $1,950 2005-07-26
FreeBSD MEDIUM 5.0
CVE-2005-2019

ipfw in FreeBSD 5.4, when running on Symmetric Multi-Processor (SMP) or Uni Processor (UP) systems with the PREEMPTION kernel option enabled, does no…

Mitigation only
Fix from $1,600 2005-07-05
FreeBSD MEDIUM 5.0
CVE-2005-2068

FreeBSD 4.x through 4.11 and 5.x through 5.4 allows remote attackers to modify certain TCP options via a TCP packet with the SYN flag set for an alre…

Mitigation only
Fix from $1,600 2005-07-05
FreeBSD HIGH 10.0
CVE-2005-0708

The sendfile system call in FreeBSD 4.8 through 4.11 and 5 through 5.4 can transfer portions of kernel memory if a file is truncated while it is bein…

Mitigation only
Fix from $1,950 2005-05-02
FreeBSD HIGH 7.8
CVE-2005-1036

FreeBSD 5.x to 5.4 on AMD64 does not properly initialize the IO permission bitmap used to allow user access to certain hardware, which allows local u…

Fix: after 5.4
Fix from $1,950 2005-05-02
FreeBSD HIGH 7.2
CVE-2005-0610

Multiple symlink vulnerabilities in portupgrade before 20041226_2 in FreeBSD allow local users to (1) overwrite arbitrary files and possibly replace …

Patch available
Fix from $1,950 2005-04-12
FreeBSD MEDIUM 5.6
CVE-2005-0109

Hyper-Threading technology, as used in FreeBSD and other operating systems that are run on Intel Pentium and other processors, allows local users to …

Patch available
Fix from $1,600 2005-03-05
Fetch HIGH 10.0
CVE-2004-1053

Integer overflow in fetch on FreeBSD 4.1 through 5.3 allows remote malicious servers to execute arbitrary code via certain HTTP headers in an HTTP re…

Patch available
Fix from $1,950 2005-03-01