|
301
|
-
4.6
|
MEDIUM
|
FreeBSD 4.6 to 4.11 and 5.x to 5.4 uses insecure default permissions for the /dev/iir device, which allows local users to execute restricted ioctl calls to read or modify data on hardware that is con…
|
NVD-CWE-Other
|
CVE-2005-1399
|
cpe:2.3:o:freebsd:freebsd:5.4:* cpe:2.3:o:freebsd:freebsd:5.3:* cpe:2.3:o:freebsd:freebsd:5.2:* cpe:2.3:o:free…
|
|
|
|
|
2008-09-6 05:49
2005-05-6
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
302
|
-
4.6
|
MEDIUM
|
The i386_get_ldt system call in FreeBSD 4.7 to 4.11 and 5.x to 5.4 allows local users to access sensitive kernel memory via arguments with negative or very large values.
|
NVD-CWE-Other
|
CVE-2005-1400
|
cpe:2.3:o:freebsd:freebsd:5.4:* cpe:2.3:o:freebsd:freebsd:5.3:* cpe:2.3:o:freebsd:freebsd:5.2:* cpe:2.3:o:free…
|
|
|
|
|
2008-09-6 05:49
2005-05-6
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303
|
-
4.6
|
MEDIUM
|
The kernel in FreeBSD 4.x to 4.11 and 5.x to 5.4 does not properly clear certain fixed-length buffers when copying variable-length data for use by applications, which could allow those applications t…
|
NVD-CWE-Other
|
CVE-2005-1406
|
cpe:2.3:o:freebsd:freebsd:5.4:* cpe:2.3:o:freebsd:freebsd:5.3:* cpe:2.3:o:freebsd:freebsd:5.2:* cpe:2.3:o:free…
|
|
|
|
|
2011-03-8 11:21
2005-05-6
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304
|
-
10.0
|
HIGH
|
The sendfile system call in FreeBSD 4.8 through 4.11 and 5 through 5.4 can transfer portions of kernel memory if a file is truncated while it is being sent, which could allow remote attackers to obta…
|
NVD-CWE-Other
|
CVE-2005-0708
|
cpe:2.3:o:freebsd:freebsd:5.4:pre-release cpe:2.3:o:freebsd:freebsd:5.3:stable cpe:2.3:o:freebsd:freebsd:5.3:rele…
|
|
|
|
|
2017-10-12 10:29
2005-05-2
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305
|
-
3.7
|
LOW
|
Race condition in gzip 1.2.4, 1.3.3, and earlier, when decompressing a gzipped file, allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being dec…
|
NVD-CWE-Other
|
CVE-2005-0988
|
cpe:2.3:o:freebsd:freebsd:5.4:releng cpe:2.3:o:freebsd:freebsd:5.4:release cpe:2.3:o:freebsd:freebsd:5.4:pre-rele…
|
|
|
|
|
2017-10-11 10:30
2005-05-2
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306
|
7.8
7.2
|
HIGH
Local
|
FreeBSD 5.x to 5.4 on AMD64 does not properly initialize the IO permission bitmap used to allow user access to certain hardware, which allows local users to bypass intended access restrictions to cau…
|
CWE-909
Missing Initialization of Resource
|
CVE-2005-1036
|
cpe:2.3:o:freebsd:freebsd:*:*
|
5.0
|
5.4
|
|
|
2024-02-9 08:47
2005-05-2
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307
|
-
2.1
|
LOW
|
The SIOCGIFCONF ioctl (ifconf function) in FreeBSD 4.x through 4.11 and 5.x through 5.4 does not properly clear a buffer before using it, which allows local users to obtain portions of sensitive kern…
|
CWE-399
Resource Management Errors
|
CVE-2005-1126
|
cpe:2.3:o:freebsd:freebsd:5.3:stable cpe:2.3:o:freebsd:freebsd:5.3:releng cpe:2.3:o:freebsd:freebsd:5.3:release
|
|
|
|
|
2017-07-11 10:32
2005-04-15
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308
|
-
7.2
|
HIGH
|
Multiple symlink vulnerabilities in portupgrade before 20041226_2 in FreeBSD allow local users to (1) overwrite arbitrary files and possibly replace packages to execute arbitrary code via pkg_fetch, …
|
NVD-CWE-Other
|
CVE-2005-0610
|
cpe:2.3:o:freebsd:freebsd:5.4:release cpe:2.3:o:freebsd:freebsd:5.4:pre-release cpe:2.3:o:freebsd:freebsd:5.3:sta…
|
|
|
|
|
2008-09-6 05:46
2005-04-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309
|
5.6
4.7
|
MEDIUM
Local
|
Hyper-Threading technology, as used in FreeBSD and other operating systems that are run on Intel Pentium and other processors, allows local users to use a malicious thread to create covert channels, …
|
NVD-CWE-Other
|
CVE-2005-0109
|
cpe:2.3:o:freebsd:freebsd:5.4:pre-release cpe:2.3:o:freebsd:freebsd:5.3:stable cpe:2.3:o:freebsd:freebsd:5.3:rele…
|
|
|
|
|
2018-10-16 21:06
2005-03-5
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310
|
-
3.6
|
LOW
|
The cmdline pseudofiles in (1) procfs on FreeBSD 4.8 through 5.3, and (2) linprocfs on FreeBSD 5.x through 5.3, do not properly validate a process argument vector, which allows local users to cause a…
|
NVD-CWE-Other
|
CVE-2004-1066
|
cpe:2.3:o:freebsd:freebsd:5.3:stable cpe:2.3:o:freebsd:freebsd:5.3:release cpe:2.3:o:freebsd:freebsd:5.3:* cpe…
|
|
|
|
|
2017-07-11 10:30
2005-01-10
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|