CVEs (535)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
linprocfs on FreeBSD 4.3 and earlier does not properly restrict access to kernel memory, which allows one process with debugging rights on a privileged process to read restricted memory from that process. |
3Freebsd NetbsdOpenbsd3Freebsd NetbsdOpenbsdApr 16, 2026 Aug 17, 2001 N/A· v4 N/A· v3 6.2 MEDIUM· v2 fts routines in FreeBSD 4.3 and earlier, NetBSD before 1.5.2, and OpenBSD 2.9 and earlier can be forced to change (chdir) into a different directory than intended when the directory above the current directory is moved,...Show more |
9Debian FreebsdIbm+6 more11Aix Debian LinuxFreebsd+8 moreApr 16, 2026 Aug 14, 2001 N/A· v4 N/A· v3 10.0 HIGH· v2 Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a set of options including AYT (Are You There), which is not properly handled by t...Show more |
FreeBSD 4.3 does not properly clear shared signal handlers when executing a process, which allows local users to gain privileges by calling rfork with a shared signal handler, having the child process execute a setuid pr...Show more |
7Freebsd HpLinux+4 more9Freebsd Hp UxLinux Kernel+6 moreApr 16, 2026 Jul 7, 2001 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Multiple TCP implementations could allow remote attackers to cause a denial of service (bandwidth and CPU exhaustion) by setting the maximum segment size (MSS) to a very small number and requesting large amounts of data,...Show more |
5Conectiva FreebsdLicq+2 more6Freebsd LicqLinux+3 moreApr 16, 2026 Jul 2, 2001 N/A· v4 N/A· v3 7.5 HIGH· v2 licq before 1.0.3 allows remote attackers to execute arbitrary commands via shell metacharacters in a URL. |
BubbleMon 1.31 does not properly drop group privileges before executing programs, which allows local users to execute arbitrary commands with the kmem group id. |
rwho daemon rwhod in FreeBSD 4.2 and earlier, and possibly other operating systems, allows remote attackers to cause a denial of service via malformed packets with a short length. |
3Freebsd MandrakesoftSuse3Freebsd Mandrake LinuxSuse LinuxApr 16, 2026 Jun 27, 2001 N/A· v4 N/A· v3 10.0 HIGH· v2 time server daemon timed allows remote attackers to cause a denial of service via malformed packets. |
3Darren Reed FreebsdOpenbsd3Freebsd IpfilterOpenbsdApr 16, 2026 Jun 18, 2001 N/A· v4 N/A· v3 7.5 HIGH· v2 IPFilter 3.4.16 and earlier does not include sufficient session information in its cache, which allows remote attackers to bypass access restrictions by sending fragmented packets to a restricted port after sending unfra...Show more |
Race condition in the UFS and EXT2FS file systems in FreeBSD 4.2 and earlier, and possibly other operating systems, makes deleted data available to user processes before it is zeroed out, which allows a local user to acc...Show more |
5Freebsd MitNetbsd+2 more5Freebsd IrixKerberos 5+2 moreApr 16, 2026 Jun 18, 2001 N/A· v4 N/A· v3 10.0 HIGH· v2 Buffer overflows in BSD-based FTP servers allows remote attackers to execute arbitrary commands via a long pattern string containing a {} sequence, as seen in (1) g_opendir, (2) g_lstat, (3) g_stat, and (4) the glob0 buf...Show more |
sort in FreeBSD 4.1.1 and earlier, and possibly other operating systems, uses predictable temporary file names and does not properly handle when the temporary file already exists, which causes sort to crash and possibly...Show more |
Buffer overflow in dc20ctrl before 0.4_1 in FreeBSD, and possibly other operating systems, allows local users to gain privileges. |
inetd ident server in FreeBSD 4.x and earlier does not properly set group permissions, which allows remote attackers to read the first 16 bytes of files that are accessible by the wheel group. |
ipfw and ip6fw in FreeBSD 4.2 and earlier allows remote attackers to bypass access restrictions by setting the ECE flag in a TCP packet, which makes the packet appear to be part of an established connection. |
6Conectiva DebianFreebsd+3 more7Debian Linux FreebsdLinux+4 moreApr 16, 2026 Mar 12, 2001 N/A· v4 N/A· v3 7.2 HIGH· v2 Zope before 2.2.4 does not properly compute local roles, which could allow users to bypass specified access restrictions and gain privileges. |
The kernel in FreeBSD 3.2 follows symbolic links when it creates core dump files, which allows local attackers to modify arbitrary files. |
periodic in FreeBSD 4.1.1 and earlier, and possibly other operating systems, allows local users to overwrite arbitrary files via a symlink attack. |
Buffer overflow in kdc_reply_cipher of libkrb (Kerberos 4 authentication library) in NetBSD 1.5 and FreeBSD 4.2 and earlier, as used in Kerberised applications such as telnetd and login, allows local users to gain root p...Show more |