Vulnerabilities > Freebsd > Freebsd > 4.1

DATE CVE VULNERABILITY TITLE RISK
2002-12-31 CVE-2002-1674 Unspecified vulnerability in Freebsd
procfs on FreeBSD before 4.5 allows local users to cause a denial of service (kernel panic) by removing a file that the fstatfs function refers to.
local
high complexity
freebsd
1.2
2002-09-24 CVE-2002-0973 Buffer Overflow vulnerability in FreeBSD System Call Signed Integer
Integer signedness error in several system calls for FreeBSD 4.6.1 RELEASE-p10 and earlier may allow attackers to access sensitive kernel memory via large negative values to the (1) accept, (2) getsockname, and (3) getpeername system calls, and the (4) vesa FBIO_GETPALETTE ioctl.
local
low complexity
freebsd
4.6
2002-08-12 CVE-2002-0754 Privilege Escalation vulnerability in Kerberos 5 su
Kerberos 5 su (k5su) in FreeBSD 4.4 and earlier relies on the getlogin system call to determine if the user running k5su is root, which could allow a root-initiated process to regain its privileges after it has dropped them.
local
low complexity
freebsd kth
7.2
2002-08-12 CVE-2002-0391 Integer Overflow or Wraparound vulnerability in multiple products
Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, allows remote attackers to execute arbitrary code by passing a large number of arguments to xdr_array through RPC services such as rpc.cmsd and dmispd.
network
low complexity
openbsd sun freebsd microsoft CWE-190
critical
9.8
2002-06-25 CVE-2002-0381 The TCP implementation in various BSD operating systems (tcp_input.c) does not properly block connections to broadcast addresses, which could allow remote attackers to bypass intended filters via packets with a unicast link layer address and an IP broadcast address.
network
low complexity
freebsd netbsd openbsd
5.0
2001-10-03 CVE-2001-0670 Buffer Overflow vulnerability in Multiple BSD Vendor lpd
Buffer overflow in BSD line printer daemon (in.lpd or lpd) in various BSD-based operating systems allows remote attackers to execute arbitrary code via an incomplete print job followed by a request to display the printer queue.
network
low complexity
bsd freebsd netbsd openbsd
7.5
2001-09-20 CVE-2001-1029 libutil in OpenSSH on FreeBSD 4.4 and earlier does not drop privileges before verifying the capabilities for reading the copyright and welcome files, which allows local users to bypass the capabilities checks and read arbitrary files by specifying alternate copyright or welcome files.
local
low complexity
openbsd freebsd
2.1
2001-09-20 CVE-2001-0710 NetBSD 1.5 and earlier and FreeBSD 4.3 and earlier allows a remote attacker to cause a denial of service by sending a large number of IP fragments to the machine, exhausting the mbuf pool.
network
low complexity
freebsd netbsd
5.0
2001-08-21 CVE-2001-1166 Unspecified vulnerability in Freebsd
linprocfs on FreeBSD 4.3 and earlier does not properly restrict access to kernel memory, which allows one process with debugging rights on a privileged process to read restricted memory from that process.
network
low complexity
freebsd
5.0
2001-08-14 CVE-2001-0554 Classic Buffer Overflow vulnerability in multiple products
Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a set of options including AYT (Are You There), which is not properly handled by the telrcv function.
network
low complexity
netkit mit sgi freebsd ibm netbsd openbsd sun debian CWE-120
critical
10.0