Show filters
531 Total Results
Displaying 291-300 of 531
Sort by:
Attacker Value
Unknown
CVE-2008-1215
Disclosure Date: March 09, 2008 (last updated October 04, 2023)
Stack-based buffer overflow in the command_Expand_Interpret function in command.c in ppp (aka user-ppp), as distributed in FreeBSD 6.3 and 7.0, OpenBSD 4.1 and 4.2, and the net/userppp package for NetBSD, allows local users to gain privileges via long commands containing "~" characters.
0
Attacker Value
Unknown
CVE-2008-0777
Disclosure Date: February 15, 2008 (last updated October 04, 2023)
The sendfile system call in FreeBSD 5.5 through 7.0 does not check the access flags of the file descriptor used for sending a file, which allows local users to read the contents of write-only files.
0
Attacker Value
Unknown
CVE-2008-0217
Disclosure Date: January 16, 2008 (last updated October 04, 2023)
The script program in FreeBSD 5.0 through 7.0-PRERELEASE invokes openpty, which creates a pseudo-terminal with world-readable and world-writable permissions when it is not run as root, which allows local users to read data from the terminal of the user running script.
0
Attacker Value
Unknown
CVE-2008-0216
Disclosure Date: January 16, 2008 (last updated October 04, 2023)
The ptsname function in FreeBSD 6.0 through 7.0-PRERELEASE does not properly verify that a certain portion of a device name is associated with a pty of a user who is calling the pt_chown function, which might allow local users to read data from the pty from another user.
0
Attacker Value
Unknown
CVE-2007-6150
Disclosure Date: November 30, 2007 (last updated October 04, 2023)
The "internal state tracking" code for the random and urandom devices in FreeBSD 5.5, 6.1 through 6.3, and 7.0 beta 4 allows local users to obtain portions of previously-accessed random values, which could be leveraged to bypass protection mechanisms that rely on secrecy of those values.
0
Attacker Value
Unknown
CVE-2007-3798
Disclosure Date: July 16, 2007 (last updated January 13, 2024)
Integer overflow in print-bgp.c in the BGP dissector in tcpdump 3.9.6 and earlier allows remote attackers to execute arbitrary code via crafted TLVs in a BGP packet, related to an unchecked return value.
0
Attacker Value
Unknown
CVE-2007-3645
Disclosure Date: July 15, 2007 (last updated October 04, 2023)
archive_read_support_format_tar.c in libarchive before 2.2.4 allows user-assisted remote attackers to cause a denial of service (crash) via (1) an end-of-file condition within a tar header that follows a pax extension header or (2) a malformed pax extension header in an (a) PAX or a (b) TAR archive, which results in a NULL pointer dereference, a different issue than CVE-2007-3644.
0
Attacker Value
Unknown
CVE-2007-3641
Disclosure Date: July 14, 2007 (last updated October 04, 2023)
archive_read_support_format_tar.c in libarchive before 2.2.4 does not properly compute the length of a certain buffer when processing a malformed pax extension header, which allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) PAX or (2) TAR archive that triggers a buffer overflow.
0
Attacker Value
Unknown
CVE-2007-3644
Disclosure Date: July 14, 2007 (last updated October 04, 2023)
archive_read_support_format_tar.c in libarchive before 2.2.4 allows user-assisted remote attackers to cause a denial of service (infinite loop) via (1) an end-of-file condition within a pax extension header or (2) a malformed pax extension header in an (a) PAX or a (b) TAR archive.
0
Attacker Value
Unknown
CVE-2007-3722
Disclosure Date: July 12, 2007 (last updated October 04, 2023)
The 4BSD process scheduler in the FreeBSD kernel performs scheduling based on CPU billing gathered from periodic process sampling ticks, which allows local users to cause a denial of service (CPU consumption) by performing voluntary nanosecond sleeps that result in the process not being active during a clock interrupt, as described in "Secretly Monopolizing the CPU Without Superuser Privileges."
0