Show filters
52 Total Results
Displaying 41-50 of 52
Sort by:
Attacker Value
Unknown

CVE-2002-0973

Disclosure Date: September 24, 2002 (last updated February 22, 2025)
Integer signedness error in several system calls for FreeBSD 4.6.1 RELEASE-p10 and earlier may allow attackers to access sensitive kernel memory via large negative values to the (1) accept, (2) getsockname, and (3) getpeername system calls, and the (4) vesa FBIO_GETPALETTE ioctl.
0
Attacker Value
Unknown

CVE-2002-0755

Disclosure Date: August 12, 2002 (last updated February 22, 2025)
Kerberos 5 su (k5su) in FreeBSD 4.5 and earlier does not verify that a user is a member of the wheel group before granting superuser privileges, which could allow unauthorized users to execute commands as root.
0
Attacker Value
Unknown

CVE-2002-0831

Disclosure Date: August 12, 2002 (last updated February 22, 2025)
The kqueue mechanism in FreeBSD 4.3 through 4.6 STABLE allows local users to cause a denial of service (kernel panic) via a pipe call in which one end is terminated and an EVFILT_WRITE filter is registered for the other end.
0
Attacker Value
Unknown

CVE-2002-0414

Disclosure Date: August 12, 2002 (last updated February 22, 2025)
KAME-derived implementations of IPsec on NetBSD 1.5.2, FreeBSD 4.5, and other operating systems, does not properly consult the Security Policy Database (SPD), which could cause a Security Gateway (SG) that does not use Encapsulating Security Payload (ESP) to forward forged IPv4 packets.
0
Attacker Value
Unknown

CVE-2002-0754

Disclosure Date: August 12, 2002 (last updated February 22, 2025)
Kerberos 5 su (k5su) in FreeBSD 4.4 and earlier relies on the getlogin system call to determine if the user running k5su is root, which could allow a root-initiated process to regain its privileges after it has dropped them.
0
Attacker Value
Unknown

CVE-2002-0572

Disclosure Date: July 03, 2002 (last updated February 22, 2025)
FreeBSD 4.5 and earlier, and possibly other BSD-based operating systems, allows local users to write to or read from restricted files by closing the file descriptors 0 (standard input), 1 (standard output), or 2 (standard error), which may then be reused by a called setuid process that intended to perform I/O on normal files.
0
Attacker Value
Unknown

CVE-2002-0004

Disclosure Date: February 27, 2002 (last updated February 22, 2025)
Heap corruption vulnerability in the "at" program allows local users to execute arbitrary code via a malformed execution time, which causes at to free the same memory twice.
0
Attacker Value
Unknown

CVE-2001-1185

Disclosure Date: December 10, 2001 (last updated February 22, 2025)
Some AIO operations in FreeBSD 4.4 may be delayed until after a call to execve, which could allow a local user to overwrite memory of the new process and gain privileges.
0
Attacker Value
Unknown

CVE-2001-1034

Disclosure Date: September 23, 2001 (last updated February 22, 2025)
Format string vulnerability in Hylafax on FreeBSD allows local users to execute arbitrary code via format specifiers in the -h hostname argument for (1) faxrm or (2) faxalter.
0
Attacker Value
Unknown

CVE-2000-0186

Disclosure Date: February 28, 2000 (last updated February 22, 2025)
Buffer overflow in the dump utility in the Linux ext2fs backup package allows local users to gain privileges via a long command line argument.
0