Show filters
51 Total Results
Displaying 41-50 of 51
Sort by:
Attacker Value
Unknown
CVE-2002-0754
Disclosure Date: August 12, 2002 (last updated February 22, 2025)
Kerberos 5 su (k5su) in FreeBSD 4.4 and earlier relies on the getlogin system call to determine if the user running k5su is root, which could allow a root-initiated process to regain its privileges after it has dropped them.
0
Attacker Value
Unknown
CVE-2002-0004
Disclosure Date: February 27, 2002 (last updated February 22, 2025)
Heap corruption vulnerability in the "at" program allows local users to execute arbitrary code via a malformed execution time, which causes at to free the same memory twice.
0
Attacker Value
Unknown
CVE-2001-1017
Disclosure Date: September 04, 2001 (last updated February 22, 2025)
rmuser utility in FreeBSD 4.2 and 4.3 creates a copy of the master.passwd file with world-readable permissions while updating the original file, which could allow local users to gain privileges by reading the copied file while rmuser is running, obtain the password hashes, and crack the passwords.
0
Attacker Value
Unknown
CVE-2001-0969
Disclosure Date: August 31, 2001 (last updated February 22, 2025)
ipfw in FreeBSD does not properly handle the use of "me" in its rules when point to point interfaces are used, which causes ipfw to allow connections from arbitrary remote hosts.
0
Attacker Value
Unknown
CVE-2001-1166
Disclosure Date: August 21, 2001 (last updated February 22, 2025)
linprocfs on FreeBSD 4.3 and earlier does not properly restrict access to kernel memory, which allows one process with debugging rights on a privileged process to read restricted memory from that process.
0
Attacker Value
Unknown
CVE-2001-1145
Disclosure Date: August 17, 2001 (last updated February 22, 2025)
fts routines in FreeBSD 4.3 and earlier, NetBSD before 1.5.2, and OpenBSD 2.9 and earlier can be forced to change (chdir) into a different directory than intended when the directory above the current directory is moved, which could cause scripts to perform dangerous actions on the wrong directories.
0
Attacker Value
Unknown
CVE-2001-0554
Disclosure Date: August 14, 2001 (last updated February 22, 2025)
Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a set of options including AYT (Are You There), which is not properly handled by the telrcv function.
0
Attacker Value
Unknown
CVE-2001-1180
Disclosure Date: July 10, 2001 (last updated February 22, 2025)
FreeBSD 4.3 does not properly clear shared signal handlers when executing a process, which allows local users to gain privileges by calling rfork with a shared signal handler, having the child process execute a setuid program, and sending a signal to the child.
0
Attacker Value
Unknown
CVE-2001-1244
Disclosure Date: July 07, 2001 (last updated February 22, 2025)
Multiple TCP implementations could allow remote attackers to cause a denial of service (bandwidth and CPU exhaustion) by setting the maximum segment size (MSS) to a very small number and requesting large amounts of data, which generates more packets with less TCP-level data that amplify network traffic and consume more server CPU to process.
0
Attacker Value
Unknown
CVE-1999-0405
Disclosure Date: February 18, 1999 (last updated February 22, 2025)
A buffer overflow in lsof allows local users to obtain root privilege.
0