Vulnerabilities > Freebsd > Medium

DATE CVE VULNERABILITY TITLE RISK
2014-12-17 CVE-2014-8116 Resource Management Errors vulnerability in multiple products
The ELF parser (readelf.c) in file before 5.21 allows remote attackers to cause a denial of service (CPU consumption or crash) via a large number of (1) program or (2) section headers or (3) invalid capabilities.
network
low complexity
file-project freebsd mageia canonical CWE-399
5.0
2014-12-12 CVE-2014-7250 Resource Management Errors vulnerability in multiple products
The TCP stack in 4.3BSD Net/2, as used in FreeBSD 5.4, NetBSD possibly 2.0, and OpenBSD possibly 3.6, does not properly implement the session timer, which allows remote attackers to cause a denial of service (resource consumption) via crafted packets.
network
low complexity
bsd freebsd netbsd openbsd CWE-399
5.0
2014-11-18 CVE-2014-8475 Code vulnerability in Freebsd 10.0/9.1/9.2
FreeBSD 9.1, 9.2, and 10.0, when compiling OpenSSH with Kerberos support, uses incorrect library ordering when linking sshd, which causes symbols to be resolved incorrectly and allows remote attackers to cause a denial of service (sshd deadlock and prevention of new connections) by ending multiple connections before authentication is completed.
network
freebsd CWE-17
4.3
2014-10-27 CVE-2014-3955 Improper Input Validation vulnerability in Freebsd
routed in FreeBSD 8.4 through 10.1-RC2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via an RIP request from a source not on a directly connected network.
network
low complexity
freebsd CWE-20
5.0
2014-10-27 CVE-2014-3711 Resource Management Errors vulnerability in Freebsd
namei in FreeBSD 9.1 through 10.1-RC2 allows remote attackers to cause a denial of service (memory exhaustion) via vectors that trigger a sandboxed process to look up a large number of nonexistent path names.
network
low complexity
freebsd CWE-399
5.0
2014-08-21 CVE-2014-5384 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products
The VIQR module in the iconv implementation in FreeBSD 10.0 before p6 and NetBSD allows context-dependent attackers to cause a denial of service (out-of-bounds array access) via a crafted argument to the iconv_open function.
network
low complexity
freebsd netbsd CWE-119
5.0
2014-08-21 CVE-2014-3951 The HZ module in the iconv implementation in FreeBSD 10.0 before p6 and NetBSD allows context-dependent attackers to cause a denial of service (NULL pointer dereference) via a crafted argument to the iconv_open function.
network
low complexity
freebsd netbsd
5.0
2014-07-15 CVE-2014-3953 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Freebsd
FreeBSD 8.4 before p14, 9.1 before p17, 9.2 before p10, and 10.0 before p7 does not properly initialize certain data structures, which allows local users to obtain sensitive information from kernel memory via a (1) SCTP_SNDRCV, (2) SCTP_EXTRCV, or (3) SCTP_RCVINFO SCTP cmsg or a (4) SCTP_PEER_ADDR_CHANGE, (5) SCTP_REMOTE_ERROR, or (6) SCTP_AUTHENTICATION_EVENT notification.
local
low complexity
freebsd CWE-119
4.9
2014-07-15 CVE-2014-3952 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Freebsd
FreeBSD 8.4 before p14, 9.1 before p17, 9.2 before p10, and 10.0 before p7 does not properly initialize the buffer between the header and data of a control message, which allows local users to obtain sensitive information from kernel memory via unspecified vectors.
local
low complexity
freebsd CWE-119
4.9
2014-06-10 CVE-2014-3880 Improper Input Validation vulnerability in Freebsd
The (1) execve and (2) fexecve system calls in the FreeBSD kernel 8.4 before p11, 9.1 before p14, 9.2 before p7, and 10.0 before p4 destroys the virtual memory address space and mappings for a process before all threads have terminated, which allows local users to cause a denial of service (triple-fault and system reboot) via a crafted system call, which triggers an invalid page table pointer dereference.
local
low complexity
freebsd CWE-20
4.9