Vulnerabilities > Freebsd > High

DATE CVE VULNERABILITY TITLE RISK
2019-04-17 CVE-2019-9498 Improper Authentication vulnerability in multiple products
The implementations of EAP-PWD in hostapd EAP Server, when built against a crypto library missing explicit validation on imported elements, do not validate the scalar and element values in EAP-pwd-Commit.
8.1
2019-02-12 CVE-2019-5596 Unspecified vulnerability in Freebsd 11.2/12.0
In FreeBSD 11.2-STABLE after r338618 and before r343786, 12.0-STABLE before r343781, and 12.0-RELEASE before 12.0-RELEASE-p3, a bug in the reference count implementation for UNIX domain sockets can cause a file structure to be incorrectly released potentially allowing a malicious local user to gain root privileges or escape from a jail.
local
low complexity
freebsd
8.8
2018-12-04 CVE-2018-17159 Resource Exhaustion vulnerability in Freebsd
In FreeBSD before 11.2-STABLE(r340854) and 11.2-RELEASE-p5, the NFS server lacks a bounds check in the READDIRPLUS NFS request.
network
low complexity
freebsd CWE-400
7.5
2018-12-04 CVE-2018-17158 Integer Overflow or Wraparound vulnerability in Freebsd
In FreeBSD before 11.2-STABLE(r340854) and 11.2-RELEASE-p5, an integer overflow error can occur when handling the client address length field in an NFSv4 request.
network
low complexity
freebsd CWE-190
7.5
2018-09-12 CVE-2018-6924 Improper Input Validation vulnerability in Freebsd
In FreeBSD before 11.1-STABLE, 11.2-RELEASE-p3, 11.1-RELEASE-p14, 10.4-STABLE, and 10.4-RELEASE-p12, insufficient validation in the ELF header parser could allow a malicious ELF binary to cause a kernel crash or disclose kernel memory.
local
low complexity
freebsd CWE-20
7.1
2018-09-12 CVE-2017-1085 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Freebsd
In FreeBSD before 11.2-RELEASE, an application which calls setrlimit() to increase RLIMIT_STACK may turn a read-only memory region below the stack into a read-write region.
local
low complexity
freebsd CWE-119
7.8
2018-09-12 CVE-2017-1084 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Freebsd
In FreeBSD before 11.2-RELEASE, multiple issues with the implementation of the stack guard-page reduce the protections afforded by the guard-page.
network
low complexity
freebsd CWE-119
7.5
2018-09-12 CVE-2017-1083 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Freebsd
In FreeBSD before 11.2-RELEASE, a stack guard-page is available but is disabled by default.
network
low complexity
freebsd CWE-119
7.5
2018-09-12 CVE-2017-1082 Improper Input Validation vulnerability in Freebsd
In FreeBSD 11.x before 11.1-RELEASE and 10.x before 10.4-RELEASE, the qsort algorithm has a deterministic recursion pattern.
network
low complexity
freebsd CWE-20
7.5
2018-09-04 CVE-2018-6923 Resource Exhaustion vulnerability in Freebsd
In FreeBSD before 11.1-STABLE, 11.2-RELEASE-p2, 11.1-RELEASE-p13, ip fragment reassembly code is vulnerable to a denial of service due to excessive system resource consumption.
network
low complexity
freebsd CWE-400
7.5