Show filters
27 Total Results
Displaying 21-27 of 27
Sort by:
Attacker Value
Unknown

CVE-2014-8613

Disclosure Date: February 02, 2015 (last updated October 05, 2023)
The sctp module in FreeBSD 10.1 before p5, 10.0 before p17, 9.3 before p9, and 8.4 before p23 allows remote attackers to cause a denial of service (NULL pointer dereference and kernel panic) via a crafted RE_CONFIG chunk.
0
Attacker Value
Unknown

CVE-2014-8476

Disclosure Date: November 13, 2014 (last updated October 05, 2023)
The setlogin function in FreeBSD 8.4 through 10.1-RC4 does not initialize the buffer used to store the login name, which allows local users to obtain sensitive information from kernel memory via a call to getlogin, which returns the entire buffer.
0
Attacker Value
Unknown

CVE-2014-3711

Disclosure Date: October 27, 2014 (last updated October 05, 2023)
namei in FreeBSD 9.1 through 10.1-RC2 allows remote attackers to cause a denial of service (memory exhaustion) via vectors that trigger a sandboxed process to look up a large number of nonexistent path names.
0
Attacker Value
Unknown

CVE-2014-3955

Disclosure Date: October 27, 2014 (last updated October 05, 2023)
routed in FreeBSD 8.4 through 10.1-RC2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via an RIP request from a source not on a directly connected network.
0
Attacker Value
Unknown

CVE-2014-3954

Disclosure Date: October 27, 2014 (last updated October 05, 2023)
Stack-based buffer overflow in rtsold in FreeBSD 9.1 through 10.1-RC2 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via crafted DNS parameters in a router advertisement message.
0
Attacker Value
Unknown

CVE-2014-3873

Disclosure Date: June 10, 2014 (last updated October 05, 2023)
The ktrace utility in the FreeBSD kernel 8.4 before p11, 9.1 before p14, 9.2 before p7, and 9.3-BETA1 before p1 uses an incorrect page fault kernel trace entry size, which allows local users to obtain sensitive information from kernel memory via a kernel process trace.
0
Attacker Value
Unknown

CVE-2013-0211

Disclosure Date: September 30, 2013 (last updated October 05, 2023)
Integer signedness error in the archive_write_zip_data function in archive_write_set_format_zip.c in libarchive 3.1.2 and earlier, when running on 64-bit machines, allows context-dependent attackers to cause a denial of service (crash) via unspecified vectors, which triggers an improper conversion between unsigned and signed types, leading to a buffer overflow.
0