Show filters
51 Total Results
Displaying 31-40 of 51
Sort by:
Attacker Value
Unknown
CVE-2003-0078
Disclosure Date: March 03, 2003 (last updated February 22, 2025)
ssl3_get_record in s3_pkt.c for OpenSSL before 0.9.7a and 0.9.6 before 0.9.6i does not perform a MAC computation if an incorrect block cipher padding is used, which causes an information leak (timing discrepancy) that may make it easier to launch cryptographic attacks that rely on distinguishing between padding and MAC verification errors, possibly leading to extraction of the original plaintext, aka the "Vaudenay timing attack."
0
Attacker Value
Unknown
CVE-2003-0001
Disclosure Date: January 17, 2003 (last updated February 22, 2025)
Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote attackers to obtain information from previous packets or kernel memory by using malformed packets, as demonstrated by Etherleak.
0
Attacker Value
Unknown
CVE-2002-1674
Disclosure Date: December 31, 2002 (last updated February 22, 2025)
procfs on FreeBSD before 4.5 allows local users to cause a denial of service (kernel panic) by removing a file that the fstatfs function refers to.
0
Attacker Value
Unknown
CVE-2002-2092
Disclosure Date: December 31, 2002 (last updated February 22, 2025)
Race condition in exec in OpenBSD 4.0 and earlier, NetBSD 1.5.2 and earlier, and FreeBSD 4.4 and earlier allows local users to gain privileges by attaching a debugger to a process before the kernel has determined that the process is setuid or setgid.
0
Attacker Value
Unknown
CVE-2002-1915
Disclosure Date: December 31, 2002 (last updated February 22, 2025)
tip on multiple BSD-based operating systems allows local users to cause a denial of service (execution prevention) by using flock() to lock the /var/log/acculog file.
0
Attacker Value
Unknown
CVE-2002-1669
Disclosure Date: December 31, 2002 (last updated February 22, 2025)
pkg_add in FreeBSD 4.2 through 4.4 creates a temporary directory with world-searchable permissions, which may allow local users to modify world-writable parts of the package during installation.
0
Attacker Value
Unknown
CVE-2002-1125
Disclosure Date: September 24, 2002 (last updated February 22, 2025)
FreeBSD port programs that use libkvm for FreeBSD 4.6.2-RELEASE and earlier, including (1) asmon, (2) ascpu, (3) bubblemon, (4) wmmon, and (5) wmnet2, leave open file descriptors for /dev/mem and /dev/kmem, which allows local users to read kernel memory.
0
Attacker Value
Unknown
CVE-2002-0973
Disclosure Date: September 24, 2002 (last updated February 22, 2025)
Integer signedness error in several system calls for FreeBSD 4.6.1 RELEASE-p10 and earlier may allow attackers to access sensitive kernel memory via large negative values to the (1) accept, (2) getsockname, and (3) getpeername system calls, and the (4) vesa FBIO_GETPALETTE ioctl.
0
Attacker Value
Unknown
CVE-2002-0831
Disclosure Date: August 12, 2002 (last updated February 22, 2025)
The kqueue mechanism in FreeBSD 4.3 through 4.6 STABLE allows local users to cause a denial of service (kernel panic) via a pipe call in which one end is terminated and an EVFILT_WRITE filter is registered for the other end.
0
Attacker Value
Unknown
CVE-2002-0414
Disclosure Date: August 12, 2002 (last updated February 22, 2025)
KAME-derived implementations of IPsec on NetBSD 1.5.2, FreeBSD 4.5, and other operating systems, does not properly consult the Security Policy Database (SPD), which could cause a Security Gateway (SG) that does not use Encapsulating Security Payload (ESP) to forward forged IPv4 packets.
0