Skip to main content

Vendor archive

freebsd CVEs

Beta · best-effort

542 CVEs tagged to vendor freebsd55 Critical, 224 High, 204 Medium, 59 Low, 0 Unrated.

CVE-2003-0015

Published Feb 7, 2003

Double-free vulnerability in CVS 1.11.4 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a malformed Directory request, as…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2002-1667

Published Dec 31, 2002

The virtual memory management system in FreeBSD 4.5-RELEASE and earlier does not properly check the existence of a VM object during page invalidation, which allows local users to…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2002-1669

Published Dec 31, 2002

pkg_add in FreeBSD 4.2 through 4.4 creates a temporary directory with world-searchable permissions, which may allow local users to modify world-writable parts of the package durin…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2002-1674

Published Dec 31, 2002

procfs on FreeBSD before 4.5 allows local users to cause a denial of service (kernel panic) by removing a file that the fstatfs function refers to.

CVSS 1.2 · Low
Vendor/product tagsBeta · best-effort

CVE-2002-2092

Published Dec 31, 2002

Race condition in exec in OpenBSD 4.0 and earlier, NetBSD 1.5.2 and earlier, and FreeBSD 4.4 and earlier allows local users to gain privileges by attaching a debugger to a process…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2002-2199

Published Dec 31, 2002

The default aide.conf file in Advanced Intrusion Detection Environment (AIDE) before 0.7_1 on FreeBSD before 2002-08-28 does not properly check subdirectories, which could allow l…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-2222

Published Dec 31, 2002

isakmpd/message.c in isakmpd in FreeBSD before isakmpd-20020403_1, and in OpenBSD 3.1, allows remote attackers to cause a denial of service (crash) by sending Internet Key Exchang…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-1219

Published Nov 29, 2002

Buffer overflow in named in BIND 4 versions 4.9.10 and earlier, and 8 versions 8.3.3 and earlier, allows remote attackers to execute arbitrary code via a certain DNS server respon…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2002-1220

Published Nov 29, 2002

BIND 8.3.x through 8.3.3 allows remote attackers to cause a denial of service (termination due to assertion failure) via a request for a subdomain that does not exist, with an OPT…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-1221

Published Nov 29, 2002

BIND 8.x through 8.3.3 allows remote attackers to cause a denial of service (crash) via SIG RR elements with invalid expiry times, which are removed from the internal BIND databas…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-0973

Published Sep 24, 2002

Integer signedness error in several system calls for FreeBSD 4.6.1 RELEASE-p10 and earlier may allow attackers to access sensitive kernel memory via large negative values to the (…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-1125

Published Sep 24, 2002

FreeBSD port programs that use libkvm for FreeBSD 4.6.2-RELEASE and earlier, including (1) asmon, (2) ascpu, (3) bubblemon, (4) wmmon, and (5) wmnet2, leave open file descriptors…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2002-0414

Published Aug 12, 2002

KAME-derived implementations of IPsec on NetBSD 1.5.2, FreeBSD 4.5, and other operating systems, does not properly consult the Security Policy Database (SPD), which could cause a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2002-0518

Published Aug 12, 2002

The SYN cache (syncache) and SYN cookie (syncookie) mechanism in FreeBSD 4.5 and earlier allows remote attackers to cause a denial of service (crash) (1) via a SYN packet that is…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-0754

Published Aug 12, 2002

Kerberos 5 su (k5su) in FreeBSD 4.4 and earlier relies on the getlogin system call to determine if the user running k5su is root, which could allow a root-initiated process to reg…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2002-0755

Published Aug 12, 2002

Kerberos 5 su (k5su) in FreeBSD 4.5 and earlier does not verify that a user is a member of the wheel group before granting superuser privileges, which could allow unauthorized use…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2002-0794

Published Aug 12, 2002

The accept_filter mechanism in FreeBSD 4 through 4.5 does not properly remove entries from the incomplete listen queue when adding a syncache, which allows remote attackers to cau…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-0795

Published Aug 12, 2002

The rc system startup script for FreeBSD 4 through 4.5 allows local users to delete arbitrary files via a symlink attack on X Windows lock files.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort
Showing 426-450 of 542 CVEsPage 18 of 22