Show filters
99 Total Results
Displaying 51-60 of 99
Sort by:
Attacker Value
Unknown
CVE-2002-2092
Disclosure Date: December 31, 2002 (last updated February 22, 2025)
Race condition in exec in OpenBSD 4.0 and earlier, NetBSD 1.5.2 and earlier, and FreeBSD 4.4 and earlier allows local users to gain privileges by attaching a debugger to a process before the kernel has determined that the process is setuid or setgid.
0
Attacker Value
Unknown
CVE-2002-1915
Disclosure Date: December 31, 2002 (last updated February 22, 2025)
tip on multiple BSD-based operating systems allows local users to cause a denial of service (execution prevention) by using flock() to lock the /var/log/acculog file.
0
Attacker Value
Unknown
CVE-2002-1669
Disclosure Date: December 31, 2002 (last updated February 22, 2025)
pkg_add in FreeBSD 4.2 through 4.4 creates a temporary directory with world-searchable permissions, which may allow local users to modify world-writable parts of the package during installation.
0
Attacker Value
Unknown
CVE-2002-1125
Disclosure Date: September 24, 2002 (last updated February 22, 2025)
FreeBSD port programs that use libkvm for FreeBSD 4.6.2-RELEASE and earlier, including (1) asmon, (2) ascpu, (3) bubblemon, (4) wmmon, and (5) wmnet2, leave open file descriptors for /dev/mem and /dev/kmem, which allows local users to read kernel memory.
0
Attacker Value
Unknown
CVE-2002-0973
Disclosure Date: September 24, 2002 (last updated February 22, 2025)
Integer signedness error in several system calls for FreeBSD 4.6.1 RELEASE-p10 and earlier may allow attackers to access sensitive kernel memory via large negative values to the (1) accept, (2) getsockname, and (3) getpeername system calls, and the (4) vesa FBIO_GETPALETTE ioctl.
0
Attacker Value
Unknown
CVE-2002-0414
Disclosure Date: August 12, 2002 (last updated February 22, 2025)
KAME-derived implementations of IPsec on NetBSD 1.5.2, FreeBSD 4.5, and other operating systems, does not properly consult the Security Policy Database (SPD), which could cause a Security Gateway (SG) that does not use Encapsulating Security Payload (ESP) to forward forged IPv4 packets.
0
Attacker Value
Unknown
CVE-2002-0754
Disclosure Date: August 12, 2002 (last updated February 22, 2025)
Kerberos 5 su (k5su) in FreeBSD 4.4 and earlier relies on the getlogin system call to determine if the user running k5su is root, which could allow a root-initiated process to regain its privileges after it has dropped them.
0
Attacker Value
Unknown
CVE-2002-0004
Disclosure Date: February 27, 2002 (last updated February 22, 2025)
Heap corruption vulnerability in the "at" program allows local users to execute arbitrary code via a malformed execution time, which causes at to free the same memory twice.
0
Attacker Value
Unknown
CVE-2001-1541
Disclosure Date: December 31, 2001 (last updated February 22, 2025)
Buffer overflow in Unix-to-Unix Copy Protocol (UUCP) in BSDI BSD/OS 3.0 through 4.2 allows local users to execute arbitrary code via a long command line argument.
0
Attacker Value
Unknown
CVE-2001-1017
Disclosure Date: September 04, 2001 (last updated February 22, 2025)
rmuser utility in FreeBSD 4.2 and 4.3 creates a copy of the master.passwd file with world-readable permissions while updating the original file, which could allow local users to gain privileges by reading the copied file while rmuser is running, obtain the password hashes, and crack the passwords.
0