Vulnerabilities > Omniosce > High

DATE CVE VULNERABILITY TITLE RISK
2020-09-25 CVE-2020-24718 Missing Authorization vulnerability in multiple products
bhyve, as used in FreeBSD through 12.1 and illumos (e.g., OmniOS CE through r151034 and OpenIndiana through Hipster 2020.04), does not properly restrict VMCS and VMCB read/write operations, as demonstrated by a root user in a container on an Intel system, who can gain privileges by modifying VMCS_HOST_RIP.
local
low complexity
freebsd omniosce openindiana netapp CWE-862
8.2
2019-11-29 CVE-2019-19396 Improper Input Validation vulnerability in Omniosce Omnios
illumos, as used in OmniOS Community Edition before r151030y, allows a kernel crash via an application with multiple threads calling sendmsg concurrently over a single socket, because uts/common/inet/ip/ip_attr.c mishandles conn_ixa dereferences.
network
low complexity
omniosce CWE-20
7.5