Vulnerabilities > Freebsd > Freebsd > 6.2

DATE CVE VULNERABILITY TITLE RISK
2007-01-11 CVE-2007-0166 Local Symbolic Link vulnerability in FreeBSD Jail RC.D
The jail rc.d script in FreeBSD 5.3 up to 6.2 does not verify pathnames when writing to /var/log/console.log during a jail start-up, or when file systems are mounted or unmounted, which allows local root users to overwrite arbitrary files, or mount/unmount files, outside of the jail via a symlink attack.
local
freebsd
6.6
2002-07-23 CVE-2002-0701 ktrace in BSD-based operating systems allows the owner of a process with special privileges to trace the process after its privileges have been lowered, which may allow the owner to obtain sensitive information that the process obtained while it was running with the extra privileges.
local
low complexity
freebsd openbsd
2.1
2001-07-02 CVE-2001-0424 BubbleMon 1.31 does not properly drop group privileges before executing programs, which allows local users to execute arbitrary commands with the kmem group id.
local
low complexity
timecop freebsd
7.2
2001-03-12 CVE-2001-0128 Zope before 2.2.4 does not properly compute local roles, which could allow users to bypass specified access restrictions and gain privileges. 7.2
2001-02-16 CVE-2000-0890 Unspecified vulnerability in Freebsd 6.2
periodic in FreeBSD 4.1.1 and earlier, and possibly other operating systems, allows local users to overwrite arbitrary files via a symlink attack.
local
high complexity
freebsd
1.2
1998-12-04 CVE-1999-0798 Buffer overflow in bootpd on OpenBSD, FreeBSD, and Linux systems via a malformed header type.
network
low complexity
bsdi freebsd openbsd redhat sco
critical
10.0
1998-11-18 CVE-1999-0782 KDE kppp allows local users to create a directory in an arbitrary location via the HOME environmental variable.
local
low complexity
freebsd kde linux
2.1
1998-11-18 CVE-1999-0781 KDE allows local users to execute arbitrary commands by setting the KDEDIR environmental variable to modify the search path that KDE uses to locate its executables.
local
low complexity
freebsd kde linux
7.2
1998-11-18 CVE-1999-0780 KDE klock allows local users to kill arbitrary processes by specifying an arbitrary PID in the .kss.pid file.
local
low complexity
freebsd kde linux
4.6
1998-11-16 CVE-1999-0057 Vacation program allows command execution by remote users through a sendmail command.
network
low complexity
eric-allman freebsd hp ibm sun
7.5