Skip to main content

Vendor archive

freebsd CVEs

Beta · best-effort

542 CVEs tagged to vendor freebsd55 Critical, 224 High, 204 Medium, 59 Low, 0 Unrated.

CVE-2001-0424

Published Jul 2, 2001

BubbleMon 1.31 does not properly drop group privileges before executing programs, which allows local users to execute arbitrary commands with the kmem group id.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2001-0469

Published Jun 27, 2001

rwho daemon rwhod in FreeBSD 4.2 and earlier, and possibly other operating systems, allows remote attackers to cause a denial of service via malformed packets with a short length.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-0371

Published Jun 18, 2001

Race condition in the UFS and EXT2FS file systems in FreeBSD 4.2 and earlier, and possibly other operating systems, makes deleted data available to user processes before it is zer…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-0221

Published Jun 2, 2001

Buffer overflow in ja-xklock 2.7.1 and earlier allows local users to gain root privileges.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2001-0230

Published Jun 2, 2001

Buffer overflow in dc20ctrl before 0.4_1 in FreeBSD, and possibly other operating systems, allows local users to gain privileges.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-0310

Published Jun 2, 2001

sort in FreeBSD 4.1.1 and earlier, and possibly other operating systems, uses predictable temporary file names and does not properly handle when the temporary file already exists,…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2001-0196

Published May 3, 2001

inetd ident server in FreeBSD 4.x and earlier does not properly set group permissions, which allows remote attackers to read the first 16 bytes of files that are accessible by the…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-0183

Published Mar 26, 2001

ipfw and ip6fw in FreeBSD 4.2 and earlier allows remote attackers to bypass access restrictions by setting the ECE flag in a TCP packet, which makes the packet appear to be part o…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2000-0375

Published Mar 12, 2001

The kernel in FreeBSD 3.2 follows symbolic links when it creates core dump files, which allows local attackers to modify arbitrary files.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2000-0890

Published Feb 16, 2001

periodic in FreeBSD 4.1.1 and earlier, and possibly other operating systems, allows local users to overwrite arbitrary files via a symlink attack.

CVSS 1.2 · Low
Vendor/product tagsBeta · best-effort

CVE-2001-0061

Published Feb 12, 2001

procfs in FreeBSD and possibly other operating systems does not properly restrict access to per-process mem and ctl files, which allows local users to gain root privileges by fork…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2001-0062

Published Feb 12, 2001

procfs in FreeBSD and possibly other operating systems allows local users to cause a denial of service by calling mmap on the process' own mem file, which causes the kernel to han…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2001-0063

Published Feb 12, 2001

procfs in FreeBSD and possibly other operating systems allows local users to bypass access control restrictions for a jail environment and gain additional privileges.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2001-0093

Published Feb 12, 2001

Vulnerability in telnetd in FreeBSD 1.5 allows local users to gain root privileges by modifying critical environmental variables that affect the behavior of telnetd.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2001-0094

Published Feb 12, 2001

Buffer overflow in kdc_reply_cipher of libkrb (Kerberos 4 authentication library) in NetBSD 1.5 and FreeBSD 4.2 and earlier, as used in Kerberised applications such as telnetd and…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2000-1167

Published Jan 9, 2001

ppp utility in FreeBSD 4.1.1 and earlier does not properly restrict access as specified by the "nat deny_incoming" command, which allows remote attackers to connect to the target…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2000-1184

Published Jan 9, 2001

telnetd in FreeBSD 4.2 and earlier, and possibly other operating systems, allows remote attackers to cause a denial of service by specifying an arbitrary large file in the TERMCAP…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-0915

Published Dec 19, 2000

fingerd in FreeBSD 4.1.1 allows remote attackers to read arbitrary files by specifying the target file name instead of a regular user name.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-0916

Published Dec 19, 2000

FreeBSD 4.1.1 and earlier, and possibly other BSD-based OSes, uses an insufficient random number generator to generate initial TCP sequence numbers (ISN), which allows remote atta…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 476-500 of 542 CVEsPage 20 of 22