Vulnerabilities > Freebsd > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-03-26 CVE-2020-7462 Use After Free vulnerability in Freebsd 11.3/11.4
In 11.4-PRERELEASE before r360733 and 11.3-RELEASE before p13, improper mbuf handling in the kernel causes a use-after-free bug by sending IPv6 Hop-by-Hop options over the loopback interface.
local
low complexity
freebsd CWE-416
5.5
2021-03-26 CVE-2020-25580 Incorrect Comparison vulnerability in Freebsd 11.4/12.2
In FreeBSD 12.2-STABLE before r369346, 11.4-STABLE before r369345, 12.2-RELEASE before p4 and 11.4-RELEASE before p8 a regression in the login.access(5) rule processor has the effect of causing rules to fail to match even when they should not.
network
low complexity
freebsd CWE-697
5.3
2021-03-26 CVE-2020-25579 Missing Initialization of Resource vulnerability in Freebsd 11.4/12.1/12.2
In FreeBSD 12.2-STABLE before r368969, 11.4-STABLE before r369047, 12.2-RELEASE before p3, 12.1-RELEASE before p13 and 11.4-RELEASE before p7 msdosfs(5) was failing to zero-fill a pair of padding fields in the dirent structure, resulting in a leak of three uninitialized bytes.
network
low complexity
freebsd CWE-909
5.3
2021-03-26 CVE-2020-25578 Improper Initialization vulnerability in Freebsd 11.4/12.1/12.2
In FreeBSD 12.2-STABLE before r368969, 11.4-STABLE before r369047, 12.2-RELEASE before p3, 12.1-RELEASE before p13 and 11.4-RELEASE before p7 several file systems were not properly initializing the d_off field of the dirent structures returned by VOP_READDIR.
network
low complexity
freebsd CWE-665
5.3
2021-03-25 CVE-2021-3449 NULL Pointer Dereference vulnerability in multiple products
An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client.
5.9
2020-09-03 CVE-2020-24863 Out-of-bounds Write vulnerability in multiple products
A memory corruption vulnerability was found in the kernel function kern_getfsstat in MidnightBSD before 1.2.7 and 1.3 through 2020-08-19, and FreeBSD through 11.4, that allows an attacker to trigger an invalid free and crash the system via a crafted size value in conjunction with an invalid mode.
local
low complexity
midnightbsd freebsd CWE-787
5.5
2020-09-03 CVE-2020-24385 NULL Pointer Dereference vulnerability in multiple products
In MidnightBSD before 1.2.6 and 1.3 before August 2020, and FreeBSD before 7, a NULL pointer dereference was found in the Linux emulation layer that allows attackers to crash the running kernel.
local
low complexity
midnightbsd freebsd CWE-476
5.5
2020-08-06 CVE-2020-7459 Improper Input Validation vulnerability in Freebsd 11.3/11.4/12.1
In FreeBSD 12.1-STABLE before r362166, 12.1-RELEASE before p8, 11.4-STABLE before r362167, 11.4-RELEASE before p2, and 11.3-RELEASE before p12, missing length validation code common to mulitple USB network drivers allows a malicious USB device to write beyond the end of an allocated network packet buffer.
low complexity
freebsd CWE-20
6.8
2020-06-09 CVE-2020-7456 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
In FreeBSD 12.1-STABLE before r361918, 12.1-RELEASE before p6, 11.4-STABLE before r361919, 11.3-RELEASE before p10, and 11.4-RC2 before p1, an invalid memory location may be used for HID items if the push/pop level is not restored within the processing of that HID item allowing an attacker with physical access to a USB port to be able to use a specially crafted USB device to gain kernel or user-space code execution.
low complexity
freebsd netapp CWE-119
6.8
2020-05-24 CVE-2020-13434 Integer Overflow or Wraparound vulnerability in multiple products
SQLite through 3.32.0 has an integer overflow in sqlite3_str_vappendf in printf.c.
5.5