Show filters
30 Total Results
Displaying 1-10 of 30
Sort by:
Attacker Value
Unknown
CVE-2012-4576
Disclosure Date: December 02, 2019 (last updated November 27, 2024)
FreeBSD: Input Validation Flaw allows local users to gain elevated privileges
0
Attacker Value
Unknown
CVE-2018-6923
Disclosure Date: September 04, 2018 (last updated November 27, 2024)
In FreeBSD before 11.1-STABLE, 11.2-RELEASE-p2, 11.1-RELEASE-p13, ip fragment reassembly code is vulnerable to a denial of service due to excessive system resource consumption. This issue can allow a remote attacker who is able to send an arbitrary ip fragments to cause the machine to consume excessive resources.
0
Attacker Value
Unknown
CVE-2016-5766
Disclosure Date: August 07, 2016 (last updated November 25, 2024)
Integer overflow in the _gd2GetHeader function in gd_gd2.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8, allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via crafted chunk dimensions in an image.
0
Attacker Value
Unknown
CVE-2015-1414
Disclosure Date: February 27, 2015 (last updated October 05, 2023)
Integer overflow in FreeBSD before 8.4 p24, 9.x before 9.3 p10. 10.0 before p18, and 10.1 before p6 allows remote attackers to cause a denial of service (crash) via a crafted IGMP packet, which triggers an incorrect size calculation and allocation of insufficient memory.
0
Attacker Value
Unknown
CVE-2014-8475
Disclosure Date: November 18, 2014 (last updated October 05, 2023)
FreeBSD 9.1, 9.2, and 10.0, when compiling OpenSSH with Kerberos support, uses incorrect library ordering when linking sshd, which causes symbols to be resolved incorrectly and allows remote attackers to cause a denial of service (sshd deadlock and prevention of new connections) by ending multiple connections before authentication is completed.
0
Attacker Value
Unknown
CVE-2014-8476
Disclosure Date: November 13, 2014 (last updated October 05, 2023)
The setlogin function in FreeBSD 8.4 through 10.1-RC4 does not initialize the buffer used to store the login name, which allows local users to obtain sensitive information from kernel memory via a call to getlogin, which returns the entire buffer.
0
Attacker Value
Unknown
CVE-2014-3711
Disclosure Date: October 27, 2014 (last updated October 05, 2023)
namei in FreeBSD 9.1 through 10.1-RC2 allows remote attackers to cause a denial of service (memory exhaustion) via vectors that trigger a sandboxed process to look up a large number of nonexistent path names.
0
Attacker Value
Unknown
CVE-2014-3955
Disclosure Date: October 27, 2014 (last updated October 05, 2023)
routed in FreeBSD 8.4 through 10.1-RC2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via an RIP request from a source not on a directly connected network.
0
Attacker Value
Unknown
CVE-2014-3954
Disclosure Date: October 27, 2014 (last updated October 05, 2023)
Stack-based buffer overflow in rtsold in FreeBSD 9.1 through 10.1-RC2 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via crafted DNS parameters in a router advertisement message.
0
Attacker Value
Unknown
CVE-2014-3952
Disclosure Date: July 15, 2014 (last updated October 05, 2023)
FreeBSD 8.4 before p14, 9.1 before p17, 9.2 before p10, and 10.0 before p7 does not properly initialize the buffer between the header and data of a control message, which allows local users to obtain sensitive information from kernel memory via unspecified vectors.
0