Vulnerabilities > Freebsd > Critical

DATE CVE VULNERABILITY TITLE RISK
2005-05-02 CVE-2005-0708 The sendfile system call in FreeBSD 4.8 through 4.11 and 5 through 5.4 can transfer portions of kernel memory if a file is truncated while it is being sent, which could allow remote attackers to obtain sensitive information.
network
low complexity
dragonflybsd freebsd
critical
10.0
2005-03-01 CVE-2004-1053 Remote Buffer Overflow vulnerability in FreeBSD Fetch
Integer overflow in fetch on FreeBSD 4.1 through 5.3 allows remote malicious servers to execute arbitrary code via certain HTTP headers in an HTTP response, which lead to a buffer overflow.
network
low complexity
freebsd
critical
10.0
2004-03-03 CVE-2004-0002 Unspecified vulnerability in Freebsd
The TCP MSS (maximum segment size) functionality in netinet allows remote attackers to cause a denial of service (resource exhaustion) via (1) a low MTU, which causes a large number of small packets to be produced, or (2) via a large number of packets with a small TCP payload, which cause a large number of calls to the resource-intensive sowakeup function.
network
low complexity
freebsd
critical
10.0
2003-10-06 CVE-2003-0694 The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c.
network
low complexity
sendmail sgi apple compaq freebsd gentoo hp ibm netbsd sun turbolinux
critical
10.0
2003-08-27 CVE-2003-0466 Off-by-one Error vulnerability in multiple products
Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code, as demonstrated in wu-ftpd 2.5.0 through 2.6.2 via commands that cause pathnames of length MAXPATHLEN+1 to trigger a buffer overflow, including (1) STOR, (2) RETR, (3) APPE, (4) DELE, (5) MKD, (6) RMD, (7) STOU, or (8) RNTO.
network
low complexity
wuftpd redhat apple sun freebsd netbsd openbsd CWE-193
critical
9.8
2002-08-12 CVE-2002-0391 Integer Overflow or Wraparound vulnerability in multiple products
Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, allows remote attackers to execute arbitrary code by passing a large number of arguments to xdr_array through RPC services such as rpc.cmsd and dmispd.
network
low complexity
openbsd sun freebsd microsoft CWE-190
critical
9.8
2001-08-31 CVE-2001-0969 Unspecified vulnerability in Freebsd 4.3
ipfw in FreeBSD does not properly handle the use of "me" in its rules when point to point interfaces are used, which causes ipfw to allow connections from arbitrary remote hosts.
network
low complexity
freebsd
critical
10.0
2001-08-23 CVE-2001-1155 Incorrect Authorization vulnerability in Freebsd 4.1.1/4.2/4.3
TCP Wrappers (tcp_wrappers) in FreeBSD 4.1.1 through 4.3 with the PARANOID ACL option enabled does not properly check the result of a reverse DNS lookup, which could allow remote attackers to bypass intended access restrictions via DNS spoofing.
network
low complexity
freebsd CWE-863
critical
9.8
2001-08-14 CVE-2001-0554 Classic Buffer Overflow vulnerability in multiple products
Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a set of options including AYT (Are You There), which is not properly handled by the telrcv function.
network
low complexity
netkit mit sgi freebsd ibm netbsd openbsd sun debian CWE-120
critical
10.0
2001-06-27 CVE-2001-0388 time server daemon timed allows remote attackers to cause a denial of service via malformed packets.
network
low complexity
freebsd mandrakesoft suse
critical
10.0