Vulnerabilities > Freebsd > Freebsd > 10.1
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2016-01-29 | CVE-2016-1882 | Data Processing Errors vulnerability in Freebsd 10.1/10.2/9.3 FreeBSD 9.3 before p33, 10.1 before p26, and 10.2 before p9 allow remote attackers to cause a denial of service (kernel crash) via vectors related to creating a TCP connection with the TCP_MD5SIG and TCP_NOOPT socket options. | 7.8 |
2016-01-29 | CVE-2016-1879 | Denial of Service vulnerability in Freebsd 10.1/10.2/9.3 The Stream Control Transmission Protocol (SCTP) module in FreeBSD 9.3 before p33, 10.1 before p26, and 10.2 before p9, when the kernel is configured for IPv6, allows remote attackers to cause a denial of service (assertion failure or NULL pointer dereference and kernel panic) via a crafted ICMPv6 packet. | 7.8 |
2015-09-18 | CVE-2014-8611 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products The __sflush function in fflush.c in stdio in libc in FreeBSD 10.1 and the kernel in Apple iOS before 9 mishandles failures of the write system call, which allows context-dependent attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow) via a crafted application. | 6.9 |
2015-04-10 | CVE-2015-1415 | Information Exposure vulnerability in Freebsd The bsdinstall installer in FreeBSD 10.x before 10.1 p9, when configuring full disk encrypted ZFS, uses world-readable permissions for the GELI keyfile (/boot/encryption.key), which allows local users to obtain sensitive key information by reading the file. | 2.1 |
2015-02-27 | CVE-2015-1414 | Remote Denial of Service vulnerability in FreeBSD Integer overflow in FreeBSD before 8.4 p24, 9.x before 9.3 p10. | 7.8 |
2015-02-02 | CVE-2014-8613 | Remote Denial of Service vulnerability in Freebsd 10.1/8.4/9.3 The sctp module in FreeBSD 10.1 before p5, 10.0 before p17, 9.3 before p9, and 8.4 before p23 allows remote attackers to cause a denial of service (NULL pointer dereference and kernel panic) via a crafted RE_CONFIG chunk. | 7.8 |
2015-02-02 | CVE-2014-8612 | Permissions, Privileges, and Access Controls vulnerability in Freebsd Multiple array index errors in the Stream Control Transmission Protocol (SCTP) module in FreeBSD 10.1 before p5, 10.0 before p17, 9.3 before p9, and 8.4 before p23 allow local users to (1) gain privileges via the stream id to the setsockopt function, when setting the SCTIP_SS_VALUE option, or (2) read arbitrary kernel memory via the stream id to the getsockopt function, when getting the SCTP_SS_PRIORITY option. | 4.6 |
2015-02-02 | CVE-2014-0998 | Numeric Errors vulnerability in Freebsd 10.1 Integer signedness error in the vt console driver (formerly Newcons) in FreeBSD 9.3 before p10 and 10.1 before p6 allows local users to cause a denial of service (crash) and possibly gain privileges via a negative value in a VT_WAITACTIVE ioctl call, which triggers an array index error and out-of-bounds kernel memory access. | 7.2 |
2014-11-13 | CVE-2014-8476 | Information Exposure vulnerability in Freebsd The setlogin function in FreeBSD 8.4 through 10.1-RC4 does not initialize the buffer used to store the login name, which allows local users to obtain sensitive information from kernel memory via a call to getlogin, which returns the entire buffer. | 2.1 |
2014-10-27 | CVE-2014-3955 | Improper Input Validation vulnerability in Freebsd routed in FreeBSD 8.4 through 10.1-RC2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via an RIP request from a source not on a directly connected network. | 5.0 |