|
151
|
9.8
7.5
|
CRITICAL
Network
|
Buffer overflow in the decodearr function in ntpq in ntp 4.2.8p6 through 4.2.8p10 allows remote attackers to execute arbitrary code by leveraging an ntpq query and sending a response with a crafted a…
|
CWE-787
Out-of-bounds Write
|
CVE-2018-7183
|
cpe:2.3:o:freebsd:freebsd:11.1:* cpe:2.3:o:freebsd:freebsd:10.4:* cpe:2.3:o:freebsd:freebsd:10.3:*
|
|
|
|
|
2024-11-21 13:11
2018-03-9
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
152
|
6.5
4.0
|
MEDIUM
Network
|
The routed daemon in FreeBSD 9.3 before 9.3-RELEASE-p22, 10.2-RC2 before 10.2-RC2-p1, 10.2-RC1 before 10.2-RC1-p2, 10.2 before 10.2-BETA2-p3, and 10.1 before 10.1-RELEASE-p17 allows remote authentica…
|
CWE-20
Improper Input Validation
|
CVE-2015-5674
|
cpe:2.3:o:freebsd:freebsd:9.3:* cpe:2.3:o:freebsd:freebsd:10.2:* cpe:2.3:o:freebsd:freebsd:10.1:*
|
|
|
|
|
2024-11-21 11:33
2018-02-6
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
153
|
7.8
9.3
|
HIGH
Local
|
The do_ed_script function in pch.c in GNU patch through 2.7.6, and patch in FreeBSD 10.1 before 10.1-RELEASE-p17, 10.2 before 10.2-BETA2-p3, 10.2-RC1 before 10.2-RC1-p2, and 0.2-RC2 before 10.2-RC2-p…
|
CWE-200
Information Exposure
|
CVE-2015-1418
|
cpe:2.3:o:freebsd:freebsd:10.2:* cpe:2.3:o:freebsd:freebsd:10.1:*
|
|
|
|
|
2024-11-21 11:25
2018-02-6
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
154
|
7.8
9.3
|
HIGH
Local
|
Larry Wall's patch; patch in FreeBSD 10.2-RC1 before 10.2-RC1-p1, 10.2 before 10.2-BETA2-p2, and 10.1 before 10.1-RELEASE-p16; Bitrig; GNU patch before 2.2.5; and possibly other patch variants allow …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-1416
|
cpe:2.3:o:freebsd:freebsd:10.2:* cpe:2.3:o:freebsd:freebsd:10.1:* cpe:2.3:o:freebsd:freebsd:10.0:*
|
|
|
|
|
2024-11-21 11:25
2018-02-6
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
155
|
3.3
2.1
|
LOW
Local
|
In FreeBSD before 11.1-STABLE, 11.1-RELEASE-p4, 11.0-RELEASE-p15, 10.4-STABLE, 10.4-RELEASE-p3, and 10.3-RELEASE-p24, the kernel does not properly clear the memory of the kld_file_stat structure befo…
|
CWE-200
Information Exposure
|
CVE-2017-1088
|
cpe:2.3:o:freebsd:freebsd:-:*
|
|
|
|
|
2024-11-21 12:21
2017-11-17
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
156
|
7.8
4.6
|
HIGH
Local
|
In FreeBSD 10.x before 10.4-STABLE, 10.4-RELEASE-p3, and 10.3-RELEASE-p24 named paths are globally scoped, meaning a process located in one jail can read and modify the content of POSIX shared memory…
|
CWE-22
Path Traversal
|
CVE-2017-1087
|
cpe:2.3:o:freebsd:freebsd:-:*
|
|
|
|
|
2024-11-21 12:21
2017-11-17
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
157
|
3.3
2.1
|
LOW
Local
|
In FreeBSD before 11.1-STABLE, 11.1-RELEASE-p4, 11.0-RELEASE-p15, 10.4-STABLE, 10.4-RELEASE-p3, and 10.3-RELEASE-p24, not all information in the struct ptrace_lwpinfo is relevant for the state of any…
|
CWE-200
Information Exposure
|
CVE-2017-1086
|
cpe:2.3:o:freebsd:freebsd:-:*
|
|
|
|
|
2024-11-21 12:21
2017-11-17
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
158
|
5.3
2.9
|
MEDIUM
Adjacent
|
Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation of the Integrity Group Temporal Key (IGTK) when processing a Wireless Network Management (WNM) Sleep Mode Response fra…
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2017-13088
|
cpe:2.3:o:freebsd:freebsd:11:* cpe:2.3:o:freebsd:freebsd:11.1:* cpe:2.3:o:freebsd:freebsd:10:* cpe:2.3:o:freeb…
|
|
|
|
|
2024-11-21 12:10
2017-10-17
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
159
|
5.3
2.9
|
MEDIUM
Adjacent
|
Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation of the Group Temporal Key (GTK) when processing a Wireless Network Management (WNM) Sleep Mode Response frame, allowin…
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2017-13087
|
cpe:2.3:o:freebsd:freebsd:11:* cpe:2.3:o:freebsd:freebsd:11.1:* cpe:2.3:o:freebsd:freebsd:10:* cpe:2.3:o:freeb…
|
|
|
|
|
2024-11-21 12:10
2017-10-17
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
160
|
6.8
5.4
|
MEDIUM
Adjacent
|
Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Tunneled Direct-Link Setup (TDLS) Peer Key (TPK) during the TDLS handshake, allowing an attacker within radio range to replay, decry…
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2017-13086
|
cpe:2.3:o:freebsd:freebsd:11:* cpe:2.3:o:freebsd:freebsd:11.1:* cpe:2.3:o:freebsd:freebsd:10:* cpe:2.3:o:freeb…
|
|
|
|
|
2024-11-21 12:10
2017-10-17
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|