|
241
|
-
7.2
|
HIGH
|
The _rtld function in the Run-Time Link-Editor (rtld) in libexec/rtld-elf/rtld.c in FreeBSD 7.1 and 8.0 does not clear the (1) LD_LIBMAP, (2) LD_LIBRARY_PATH, (3) LD_LIBMAP_DISABLE, (4) LD_DEBUG, and…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-4147
|
cpe:2.3:o:freebsd:freebsd:8.0:* cpe:2.3:o:freebsd:freebsd:7.1:*
|
|
|
|
|
2026-04-23 09:35
2009-12-3
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
242
|
-
7.2
|
HIGH
|
The _rtld function in the Run-Time Link-Editor (rtld) in libexec/rtld-elf/rtld.c in FreeBSD 7.1, 7.2, and 8.0 does not clear the LD_PRELOAD environment variable, which allows local users to gain priv…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-4146
|
cpe:2.3:o:freebsd:freebsd:8.0:* cpe:2.3:o:freebsd:freebsd:7.2:* cpe:2.3:o:freebsd:freebsd:7.1:*
|
|
|
|
|
2026-04-23 09:35
2009-12-3
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
243
|
-
6.9
|
MEDIUM
|
Race condition in the Pipe (IPC) close function in FreeBSD 6.3 and 6.4 allows local users to cause a denial of service (crash) or gain privileges via vectors related to kqueues, which triggers a use …
|
CWE-362
Race Condition
|
CVE-2009-3527
|
cpe:2.3:o:freebsd:freebsd:6.4:* cpe:2.3:o:freebsd:freebsd:6.3:*
|
|
|
|
|
2026-04-23 09:35
2009-10-7
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
244
|
-
4.7
|
MEDIUM
|
The IATA (ata) driver in FreeBSD 6.0 and 8.0, when read access to /dev is available, allows local users to cause a denial of service (kernel panic) via a certain IOCTL request with a large count, whi…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-2649
|
cpe:2.3:o:freebsd:freebsd:8.0:* cpe:2.3:o:freebsd:freebsd:6.0:*
|
|
|
|
|
2026-04-23 09:35
2009-07-31
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245
|
-
6.8
|
MEDIUM
|
Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the (2) gdtoa (aka new dtoa) implementation in gdtoa/misc.c in libc, as used in multiple operating systems and products in…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-0689
|
cpe:2.3:o:freebsd:freebsd:7.2:stable cpe:2.3:o:freebsd:freebsd:7.2:pre-release cpe:2.3:o:freebsd:freebsd:7.2:*
|
|
|
|
|
2026-04-23 09:35
2009-07-1
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246
|
-
3.6
|
LOW
|
FreeBSD 6.3, 6.4, 7.1, and 7.2 does not enforce permissions on the SIOCSIFINFO_IN6 IOCTL, which allows local users to modify or disable IPv6 network interfaces, as demonstrated by modifying the MTU.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-2208
|
cpe:2.3:o:freebsd:freebsd:7.2:stable cpe:2.3:o:freebsd:freebsd:7.2:pre-release cpe:2.3:o:freebsd:freebsd:7.2:*
|
|
|
|
|
2026-04-23 09:35
2009-06-25
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247
|
-
4.9
|
MEDIUM
|
Integer overflow in the pipe_build_write_buffer function (sys/kern/sys_pipe.c) in the direct write optimization feature in the pipe implementation in FreeBSD 7.1 through 7.2 and 6.3 through 6.4 allow…
|
CWE-189
Numeric Errors
|
CVE-2009-1935
|
cpe:2.3:o:freebsd:freebsd:7.2:pre-release cpe:2.3:o:freebsd:freebsd:7.2:* cpe:2.3:o:freebsd:freebsd:7.1:stable
|
|
|
|
|
2026-04-23 09:35
2009-06-19
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248
|
-
4.9
|
MEDIUM
|
The db interface in libc in FreeBSD 6.3, 6.4, 7.0, 7.1, and 7.2-PRERELEASE does not properly initialize memory for Berkeley DB 1.85 database structures, which allows local users to obtain sensitive i…
|
CWE-20
Improper Input Validation
|
CVE-2009-1436
|
cpe:2.3:o:freebsd:freebsd:7.2:pre-release cpe:2.3:o:freebsd:freebsd:7.1:release-p5 cpe:2.3:o:freebsd:freebsd:7.1:…
|
|
|
|
|
2026-04-23 09:35
2009-04-28
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249
|
-
7.2
|
HIGH
|
The ktimer feature (sys/kern/kern_time.c) in FreeBSD 7.0, 7.1, and 7.2 allows local users to overwrite arbitrary kernel memory via an out-of-bounds timer value.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2009-1041
|
cpe:2.3:o:freebsd:freebsd:7.2:* cpe:2.3:o:freebsd:freebsd:7.1:stable cpe:2.3:o:freebsd:freebsd:7.1:release-p2 …
|
|
|
|
|
2026-04-23 09:35
2009-03-26
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250
|
-
9.3
|
HIGH
|
sys_term.c in telnetd in FreeBSD 7.0-RELEASE and other 7.x versions deletes dangerous environment variables with a method that was valid only in older FreeBSD distributions, which might allow remote …
|
CWE-16 CWE-264
Configuration Permissions, Privileges, and Access Controls
|
CVE-2009-0641
|
cpe:2.3:o:freebsd:freebsd:7.1:rc1 cpe:2.3:o:freebsd:freebsd:7.1:* cpe:2.3:o:freebsd:freebsd:7.0_releng:* cpe:2…
|
|
|
|
|
2026-04-23 09:35
2009-02-20
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|