Vulnerabilities > Freebsd > Freebsd > 9.2

DATE CVE VULNERABILITY TITLE RISK
2015-04-10 CVE-2015-1415 Information Exposure vulnerability in Freebsd
The bsdinstall installer in FreeBSD 10.x before 10.1 p9, when configuring full disk encrypted ZFS, uses world-readable permissions for the GELI keyfile (/boot/encryption.key), which allows local users to obtain sensitive key information by reading the file.
local
low complexity
freebsd CWE-200
2.1
2015-02-27 CVE-2015-1414 Remote Denial of Service vulnerability in FreeBSD
Integer overflow in FreeBSD before 8.4 p24, 9.x before 9.3 p10.
network
low complexity
netgate debian freebsd
7.8
2014-11-18 CVE-2014-8475 Code vulnerability in Freebsd 10.0/9.1/9.2
FreeBSD 9.1, 9.2, and 10.0, when compiling OpenSSH with Kerberos support, uses incorrect library ordering when linking sshd, which causes symbols to be resolved incorrectly and allows remote attackers to cause a denial of service (sshd deadlock and prevention of new connections) by ending multiple connections before authentication is completed.
network
freebsd CWE-17
4.3
2014-11-13 CVE-2014-8476 Information Exposure vulnerability in Freebsd
The setlogin function in FreeBSD 8.4 through 10.1-RC4 does not initialize the buffer used to store the login name, which allows local users to obtain sensitive information from kernel memory via a call to getlogin, which returns the entire buffer.
local
low complexity
freebsd CWE-200
2.1
2014-10-27 CVE-2014-3955 Improper Input Validation vulnerability in Freebsd
routed in FreeBSD 8.4 through 10.1-RC2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via an RIP request from a source not on a directly connected network.
network
low complexity
freebsd CWE-20
5.0
2014-10-27 CVE-2014-3954 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Freebsd
Stack-based buffer overflow in rtsold in FreeBSD 9.1 through 10.1-RC2 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via crafted DNS parameters in a router advertisement message.
network
low complexity
freebsd CWE-119
critical
10.0
2014-10-27 CVE-2014-3711 Resource Management Errors vulnerability in Freebsd
namei in FreeBSD 9.1 through 10.1-RC2 allows remote attackers to cause a denial of service (memory exhaustion) via vectors that trigger a sandboxed process to look up a large number of nonexistent path names.
network
low complexity
freebsd CWE-399
5.0
2014-07-15 CVE-2014-3953 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Freebsd
FreeBSD 8.4 before p14, 9.1 before p17, 9.2 before p10, and 10.0 before p7 does not properly initialize certain data structures, which allows local users to obtain sensitive information from kernel memory via a (1) SCTP_SNDRCV, (2) SCTP_EXTRCV, or (3) SCTP_RCVINFO SCTP cmsg or a (4) SCTP_PEER_ADDR_CHANGE, (5) SCTP_REMOTE_ERROR, or (6) SCTP_AUTHENTICATION_EVENT notification.
local
low complexity
freebsd CWE-119
4.9
2014-07-15 CVE-2014-3952 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Freebsd
FreeBSD 8.4 before p14, 9.1 before p17, 9.2 before p10, and 10.0 before p7 does not properly initialize the buffer between the header and data of a control message, which allows local users to obtain sensitive information from kernel memory via unspecified vectors.
local
low complexity
freebsd CWE-119
4.9
2014-06-10 CVE-2014-3880 Improper Input Validation vulnerability in Freebsd
The (1) execve and (2) fexecve system calls in the FreeBSD kernel 8.4 before p11, 9.1 before p14, 9.2 before p7, and 10.0 before p4 destroys the virtual memory address space and mappings for a process before all threads have terminated, which allows local users to cause a denial of service (triple-fault and system reboot) via a crafted system call, which triggers an invalid page table pointer dereference.
local
low complexity
freebsd CWE-20
4.9