Show filters
20 Total Results
Displaying 11-20 of 20
Sort by:
Attacker Value
Unknown
CVE-2009-0689
Disclosure Date: July 01, 2009 (last updated October 04, 2023)
Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the (2) gdtoa (aka new dtoa) implementation in gdtoa/misc.c in libc, as used in multiple operating systems and products including in FreeBSD 6.4 and 7.2, NetBSD 5.0, OpenBSD 4.5, Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4, K-Meleon 1.5.3, SeaMonkey 1.1.8, and other products, allows context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a large precision value in the format argument to a printf function, which triggers incorrect memory allocation and a heap-based buffer overflow during conversion to a floating-point number.
0
Attacker Value
Unknown
CVE-2009-2208
Disclosure Date: June 25, 2009 (last updated October 04, 2023)
FreeBSD 6.3, 6.4, 7.1, and 7.2 does not enforce permissions on the SIOCSIFINFO_IN6 IOCTL, which allows local users to modify or disable IPv6 network interfaces, as demonstrated by modifying the MTU.
0
Attacker Value
Unknown
CVE-2009-1935
Disclosure Date: June 18, 2009 (last updated October 04, 2023)
Integer overflow in the pipe_build_write_buffer function (sys/kern/sys_pipe.c) in the direct write optimization feature in the pipe implementation in FreeBSD 7.1 through 7.2 and 6.3 through 6.4 allows local users to bypass virtual-to-physical address lookups and read sensitive information in memory pages via unspecified vectors.
0
Attacker Value
Unknown
CVE-2009-1436
Disclosure Date: April 27, 2009 (last updated October 04, 2023)
The db interface in libc in FreeBSD 6.3, 6.4, 7.0, 7.1, and 7.2-PRERELEASE does not properly initialize memory for Berkeley DB 1.85 database structures, which allows local users to obtain sensitive information by reading a database file.
0
Attacker Value
Unknown
CVE-2008-5736
Disclosure Date: December 26, 2008 (last updated October 04, 2023)
Multiple unspecified vulnerabilities in FreeBSD 6 before 6.4-STABLE, 6.3 before 6.3-RELEASE-p7, 6.4 before 6.4-RELEASE-p1, 7.0 before 7.0-RELEASE-p7, 7.1 before 7.1-RC2, and 7 before 7.1-PRERELEASE allow local users to gain privileges via unknown attack vectors related to function pointers that are "not properly initialized" for (1) netgraph sockets and (2) bluetooth sockets.
0
Attacker Value
Unknown
CVE-2002-0004
Disclosure Date: February 27, 2002 (last updated February 22, 2025)
Heap corruption vulnerability in the "at" program allows local users to execute arbitrary code via a malformed execution time, which causes at to free the same memory twice.
0
Attacker Value
Unknown
CVE-2001-0388
Disclosure Date: June 27, 2001 (last updated February 22, 2025)
time server daemon timed allows remote attackers to cause a denial of service via malformed packets.
0
Attacker Value
Unknown
CVE-1999-0040
Disclosure Date: May 01, 1997 (last updated February 22, 2025)
Buffer overflow in Xt library of X Windowing System allows local users to execute commands with root privileges.
0
Attacker Value
Unknown
CVE-1999-0032
Disclosure Date: October 25, 1996 (last updated February 22, 2025)
Buffer overflow in lpr, as used in BSD-based systems including Linux, allows local users to execute arbitrary code as root via a long -C (classification) command line option.
0
Attacker Value
Unknown
CVE-1999-0022
Disclosure Date: July 03, 1996 (last updated February 22, 2025)
Local user gains root privileges via buffer overflow in rdist, via expstr() function.
0