Show filters
531 Total Results
Displaying 241-250 of 531
Sort by:
Attacker Value
Unknown

CVE-2012-3549

Disclosure Date: October 09, 2012 (last updated October 05, 2023)
The SCTP implementation in FreeBSD 8.2 allows remote attackers to cause a denial of service (NULL pointer dereference and kernel panic) via a crafted ASCONF chunk.
0
Attacker Value
Unknown

CVE-2007-6754

Disclosure Date: July 25, 2012 (last updated October 04, 2023)
The ipalloc function in libc/stdlib/malloc.c in jemalloc in libc for FreeBSD 6.4 and NetBSD does not properly allocate memory, which makes it easier for context-dependent attackers to perform memory-related attacks such as buffer overflows via a large size value, related to "integer rounding and overflow" errors.
0
Attacker Value
Unknown

CVE-2006-7252

Disclosure Date: July 25, 2012 (last updated October 04, 2023)
Integer overflow in the calloc function in libc/stdlib/malloc.c in jemalloc in libc for FreeBSD 6.4 and NetBSD makes it easier for context-dependent attackers to perform memory-related attacks such as buffer overflows via a large size value, which triggers a memory allocation of one byte.
0
Attacker Value
Unknown

CVE-2012-2143

Disclosure Date: July 05, 2012 (last updated March 15, 2024)
The crypt_des (aka DES-based crypt) function in FreeBSD before 9.0-RELEASE-p2, as used in PHP, PostgreSQL, and other products, does not process the complete cleartext password if this password contains a 0x80 character, which makes it easier for context-dependent attackers to obtain access via an authentication attempt with an initial substring of the intended password, as demonstrated by a Unicode password.
0
Attacker Value
Unknown

CVE-2012-0217

Disclosure Date: June 12, 2012 (last updated October 04, 2023)
The x86-64 kernel system-call functionality in Xen 4.1.2 and earlier, as used in Citrix XenServer 6.0.2 and earlier and other products; Oracle Solaris 11 and earlier; illumos before r13724; Joyent SmartOS before 20120614T184600Z; FreeBSD before 9.0-RELEASE-p3; NetBSD 6.0 Beta and earlier; Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1; and possibly other operating systems, when running on an Intel processor, incorrectly uses the sysret path in cases where a certain address is not a canonical address, which allows local users to gain privileges via a crafted application. NOTE: because this issue is due to incorrect use of the Intel specification, it should have been split into separate identifiers; however, there was some value in preserving the original mapping of the multi-codebase coordinated-disclosure effort to a single identifier.
0
Attacker Value
Unknown

CVE-2011-1779

Disclosure Date: April 13, 2012 (last updated October 04, 2023)
Multiple use-after-free vulnerabilities in libarchive 2.8.4 and 2.8.5 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted (1) TAR archive or (2) ISO9660 image.
0
Attacker Value
Unknown

CVE-2010-4666

Disclosure Date: April 13, 2012 (last updated October 04, 2023)
Buffer overflow in libarchive 3.0 pre-release code allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted CAB file, which is not properly handled during the reading of Huffman code data within LZX compressed data.
0
Attacker Value
Unknown

CVE-2011-1777

Disclosure Date: April 13, 2012 (last updated October 04, 2023)
Multiple buffer overflows in the (1) heap_add_entry and (2) relocate_dir functions in archive_read_support_format_iso9660.c in libarchive through 2.8.5 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted ISO9660 image.
0
Attacker Value
Unknown

CVE-2011-1778

Disclosure Date: April 13, 2012 (last updated October 04, 2023)
Buffer overflow in libarchive through 2.8.5 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted TAR archive.
0
Attacker Value
Unknown

CVE-2011-2393

Disclosure Date: February 02, 2012 (last updated October 04, 2023)
The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in FreeBSD, NetBSD, and possibly other BSD-based operating systems allows remote attackers to cause a denial of service (CPU consumption and device hang) by sending many Router Advertisement (RA) messages with different source addresses, a similar vulnerability to CVE-2010-4670.
0