Vulnerabilities > Freebsd > Medium

DATE CVE VULNERABILITY TITLE RISK
2003-12-15 CVE-2003-0914 ISC BIND 8.3.x before 8.3.7, and 8.4.x before 8.4.3, allows remote attackers to poison the cache via a malicious name server that returns negative responses with a large TTL (time-to-live) value. 4.3
2003-11-17 CVE-2003-0804 The arplookup function in FreeBSD 5.1 and earlier, Mac OS X before 10.2.8, and possibly other BSD-based systems, allows remote attackers on a local subnet to cause a denial of service (resource starvation and panic) via a flood of spoofed ARP requests.
network
low complexity
apple freebsd openbsd
5.0
2003-10-20 CVE-2003-0688 The DNS map code in Sendmail 8.12.8 and earlier, when using the "enhdnsbl" feature, does not properly initialize certain data structures, which allows remote attackers to cause a denial of service (process crash) via an invalid DNS response that causes Sendmail to free incorrect data.
network
low complexity
redhat sendmail sgi compaq freebsd openbsd
5.0
2003-01-17 CVE-2003-0001 Information Exposure vulnerability in multiple products
Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote attackers to obtain information from previous packets or kernel memory by using malformed packets, as demonstrated by Etherleak.
network
low complexity
freebsd linux microsoft netbsd CWE-200
5.0
2002-12-31 CVE-2002-2222 Denial-Of-Service vulnerability in OpenBSD
isakmpd/message.c in isakmpd in FreeBSD before isakmpd-20020403_1, and in OpenBSD 3.1, allows remote attackers to cause a denial of service (crash) by sending Internet Key Exchange (IKE) payloads out of sequence.
network
high complexity
freebsd openbsd
5.1
2002-12-31 CVE-2002-2199 Unspecified vulnerability in Freebsd Advanced Intrusion Detection Environment
The default aide.conf file in Advanced Intrusion Detection Environment (AIDE) before 0.7_1 on FreeBSD before 2002-08-28 does not properly check subdirectories, which could allow local users to bypass detection.
local
low complexity
freebsd
4.6
2002-12-31 CVE-2002-1915 Improper Locking vulnerability in multiple products
tip on multiple BSD-based operating systems allows local users to cause a denial of service (execution prevention) by using flock() to lock the /var/log/acculog file.
local
low complexity
openbsd netbsd freebsd CWE-667
5.5
2002-11-29 CVE-2002-1221 Denial Of Service vulnerability in ISC BIND 8 Invalid Expiry Time
BIND 8.x through 8.3.3 allows remote attackers to cause a denial of service (crash) via SIG RR elements with invalid expiry times, which are removed from the internal BIND database and later cause a null dereference.
network
low complexity
isc freebsd openbsd
5.0
2002-11-29 CVE-2002-1220 Denial of Service vulnerability in ISC BIND OPT Record Large UDP
BIND 8.3.x through 8.3.3 allows remote attackers to cause a denial of service (termination due to assertion failure) via a request for a subdomain that does not exist, with an OPT resource record with a large UDP payload size.
network
low complexity
isc freebsd openbsd
5.0
2002-11-04 CVE-2002-0666 Denial of Service vulnerability in Multiple Vendor IPSec Implementation
IPSEC implementations including (1) FreeS/WAN and (2) KAME do not properly calculate the length of authentication data, which allows remote attackers to cause a denial of service (kernel panic) via spoofed, short Encapsulating Security Payload (ESP) packets, which result in integer signedness errors.
5.0