Vulnerabilities > Freebsd > High

DATE CVE VULNERABILITY TITLE RISK
2017-02-15 CVE-2017-0321 NULL Pointer Dereference vulnerability in Nvidia GPU Driver
All versions of NVIDIA GPU Display Driver contain a vulnerability in the kernel mode layer handler where a NULL pointer dereference caused by invalid user input may lead to denial of service or potential escalation of privileges.
local
low complexity
nvidia freebsd linux microsoft oracle CWE-476
7.2
2017-02-15 CVE-2017-0311 Incorrect Permission Assignment for Critical Resource vulnerability in Nvidia GPU Driver
NVIDIA GPU Display Driver R378 contains a vulnerability in the kernel mode layer handler where improper access control may lead to denial of service or possible escalation of privileges.
local
low complexity
nvidia freebsd linux microsoft oracle CWE-732
7.2
2017-02-15 CVE-2017-0309 Integer Overflow or Wraparound vulnerability in Nvidia GPU Driver
All versions of NVIDIA GPU Display Driver contain a vulnerability in the kernel mode layer handler where multiple integer overflows may cause improper memory allocation leading to a denial of service or potential escalation of privileges.
local
low complexity
nvidia freebsd linux microsoft oracle CWE-190
7.2
2017-02-15 CVE-2016-1889 Integer Overflow or Wraparound vulnerability in Freebsd
Integer overflow in the bhyve hypervisor in FreeBSD 10.1, 10.2, 10.3, and 11.0 when configured with a large amount of guest memory, allows local users to gain privilege via a crafted device descriptor.
local
low complexity
freebsd CWE-190
7.2
2017-02-15 CVE-2016-1883 Permissions, Privileges, and Access Controls vulnerability in Freebsd 10.1/10.2/9.3
The issetugid system call in the Linux compatibility layer in FreeBSD 9.3, 10.1, and 10.2 allows local users to gain privilege via unspecified vectors.
local
low complexity
freebsd CWE-264
7.2
2017-02-15 CVE-2016-1881 Permissions, Privileges, and Access Controls vulnerability in Freebsd 10.1/10.2/9.3
The kernel in FreeBSD 9.3, 10.1, and 10.2 allows local users to cause a denial of service (crash) or potentially gain privilege via a crafted Linux compatibility layer setgroups system call.
local
low complexity
freebsd CWE-264
7.2
2017-02-15 CVE-2016-1880 Permissions, Privileges, and Access Controls vulnerability in Freebsd 10.1/10.2/9.3
The Linux compatibility layer in the kernel in FreeBSD 9.3, 10.1, and 10.2 allows local users to read portions of kernel memory and potentially gain privilege via unspecified vectors, related to "handling of Linux futex robust lists."
local
low complexity
freebsd CWE-264
7.2
2016-05-25 CVE-2016-1887 Permissions, Privileges, and Access Controls vulnerability in Freebsd 10.1/10.2/10.3
Integer signedness error in the sockargs function in sys/kern/uipc_syscalls.c in FreeBSD 10.1 before p34, 10.2 before p17, and 10.3 before p3 allows local users to cause a denial of service (memory overwrite and kernel panic) or gain privileges via a negative buflen argument, which triggers a heap-based buffer overflow.
local
low complexity
freebsd CWE-264
7.2
2016-05-25 CVE-2016-1886 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Freebsd
Integer signedness error in the genkbd_commonioctl function in sys/dev/kbd/kbd.c in FreeBSD 9.3 before p42, 10.1 before p34, 10.2 before p17, and 10.3 before p3 allows local users to obtain sensitive information from kernel memory, cause a denial of service (memory overwrite and kernel crash), or gain privileges via a negative value in the flen structure member in the arg argument in a SETFKEY ioctl call, which triggers a "two way heap and stack overflow."
local
low complexity
freebsd CWE-119
7.2
2016-01-29 CVE-2016-1882 Data Processing Errors vulnerability in Freebsd 10.1/10.2/9.3
FreeBSD 9.3 before p33, 10.1 before p26, and 10.2 before p9 allow remote attackers to cause a denial of service (kernel crash) via vectors related to creating a TCP connection with the TCP_MD5SIG and TCP_NOOPT socket options.
network
low complexity
freebsd CWE-19
7.8