Vulnerabilities > Midnightbsd

DATE CVE VULNERABILITY TITLE RISK
2020-09-03 CVE-2020-24863 Out-of-bounds Write vulnerability in multiple products
A memory corruption vulnerability was found in the kernel function kern_getfsstat in MidnightBSD before 1.2.7 and 1.3 through 2020-08-19, and FreeBSD through 11.4, that allows an attacker to trigger an invalid free and crash the system via a crafted size value in conjunction with an invalid mode.
local
low complexity
midnightbsd freebsd CWE-787
4.9
2020-09-03 CVE-2020-24385 NULL Pointer Dereference vulnerability in multiple products
In MidnightBSD before 1.2.6 and 1.3 before August 2020, and FreeBSD before 7, a NULL pointer dereference was found in the Linux emulation layer that allows attackers to crash the running kernel.
local
low complexity
midnightbsd freebsd CWE-476
4.9
2009-08-11 CVE-2009-0687 Resource Management Errors vulnerability in multiple products
The pf_test_rule function in OpenBSD Packet Filter (PF), as used in OpenBSD 4.2 through 4.5, NetBSD 5.0 before RC3, MirOS 10 and earlier, and MidnightBSD 0.3-current allows remote attackers to cause a denial of service (panic) via crafted IP packets that trigger a NULL pointer dereference during translation, related to an IPv4 packet with an ICMPv6 payload.
network
low complexity
midnightbsd mirbsd netbsd openbsd CWE-399
7.8
2006-11-21 CVE-2006-6013 Local Integer Overflow vulnerability in Multiple BSD Vendor FireWire IOCTL
Integer signedness error in the fw_ioctl (FW_IOCTL) function in the FireWire (IEEE-1394) drivers (dev/firewire/fwdev.c) in various BSD kernels, including DragonFlyBSD, FreeBSD 5.5, MidnightBSD 0.1-CURRENT before 20061115, NetBSD-current before 20061116, NetBSD-4 before 20061203, and TrustedBSD, allows local users to read arbitrary memory contents via certain negative values of crom_buf->len in an FW_GCROM command.
2.1