Vulnerabilities > Freebsd > Freebsd > 9.2
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2014-06-10 | CVE-2014-3873 | Improper Input Validation vulnerability in Freebsd The ktrace utility in the FreeBSD kernel 8.4 before p11, 9.1 before p14, 9.2 before p7, and 9.3-BETA1 before p1 uses an incorrect page fault kernel trace entry size, which allows local users to obtain sensitive information from kernel memory via a kernel process trace. | 2.1 |
2014-06-04 | CVE-2014-3956 | Information Exposure vulnerability in multiple products The sm_close_on_exec function in conf.c in sendmail before 8.14.9 has arguments in the wrong order, and consequently skips setting expected FD_CLOEXEC flags, which allows local users to access unintended high-numbered file descriptors via a custom mail-delivery program. | 1.9 |
2014-05-02 | CVE-2014-3000 | Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Freebsd The TCP reassembly function in the inet module in FreeBSD 8.3 before p16, 8.4 before p9, 9.1 before p12, 9.2 before p5, and 10.0 before p2 allows remote attackers to cause a denial of service (undefined memory access and system crash) or possibly read system memory via multiple crafted packets, related to moving a reassemble queue entry to the segment list when the queue is full. | 7.8 |
2014-04-16 | CVE-2014-1453 | Resource Management Errors vulnerability in Freebsd The NFS server (nfsserver) in FreeBSD 8.3 through 10.0 does not acquire locks in the proper order when converting a directory file handle to a vnode, which allows remote authenticated users to cause a denial of service (deadlock) via vectors involving a thread that uses the correct locking order. | 4.0 |
2013-11-21 | CVE-2013-6834 | Improper Input Validation vulnerability in Freebsd The ql_eioctl function in sys/dev/qlxgbe/ql_ioctl.c in the kernel in FreeBSD 10 and earlier does not validate a certain size parameter, which allows local users to obtain sensitive information from kernel memory via a crafted ioctl call. | 4.9 |
2013-11-21 | CVE-2013-6833 | Improper Input Validation vulnerability in Freebsd The qls_eioctl function in sys/dev/qlxge/qls_ioctl.c in the kernel in FreeBSD 10 and earlier does not validate a certain size parameter, which allows local users to obtain sensitive information from kernel memory via a crafted ioctl call. | 4.9 |
2013-11-21 | CVE-2013-6832 | Information Exposure vulnerability in Freebsd The nand_ioctl function in sys/dev/nand/nand_geom.c in the nand driver in the kernel in FreeBSD 10 and earlier does not properly initialize a certain data structure, which allows local users to obtain sensitive information from kernel memory via a crafted ioctl call. | 4.9 |
2013-09-23 | CVE-2013-5710 | Permissions, Privileges, and Access Controls vulnerability in Freebsd The nullfs implementation in sys/fs/nullfs/null_vnops.c in the kernel in FreeBSD 8.3 through 9.2 allows local users with certain permissions to bypass access restrictions via a hardlink in a nullfs instance to a file in a different instance. | 3.7 |
2013-09-23 | CVE-2013-5666 | Information Exposure vulnerability in Freebsd 9.2 The sendfile system-call implementation in sys/kern/uipc_syscalls.c in the kernel in FreeBSD 9.2-RC1 and 9.2-RC2 does not properly pad transmissions, which allows local users to obtain sensitive information (kernel memory) via a length greater than the length of the file. | 4.7 |
2013-09-23 | CVE-2013-5691 | Permissions, Privileges, and Access Controls vulnerability in Freebsd The (1) IPv6 and (2) ATM ioctl request handlers in the kernel in FreeBSD 8.3 through 9.2-STABLE do not validate SIOCSIFADDR, SIOCSIFBRDADDR, SIOCSIFDSTADDR, and SIOCSIFNETMASK requests, which allows local users to perform link-layer actions, cause a denial of service (panic), or possibly gain privileges via a crafted application. | 6.9 |