FreeBSD kayıtları
freebsd üreticisine ait 630 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 12 · %1,9
- Pre-auth RCE
- 54
- Düzeltme kaydı olan
- %35,9
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-20 Improper Input Validation34
- CWE-264 Permissions, Privileges, and Access Controls31
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer26
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor22
- CWE-416 Use After Free20
- CWE-787 Out-of-bounds Write18
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
630 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
68Bu hafta | CVE-2011-4862Silahlaştırılmış | Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and mit · krb5-appl · CWE-120 | Kritik10,0 | — | %95,0 | 24 Ara 2011 |
63Bu hafta | CVE-2020-13160Silahlaştırılmış | AnyDesk before 5.5.3 on Linux and FreeBSD has a format string vulnerability that can be exploited for remote code execution.anydesk · anydesk · CWE-134 | Kritik9,8 | — | %80,6 | 9 Haz 2020 |
62Bu hafta | CVE-2024-6387Kavram kanıtı | Openssh: regresshion - race condition in ssh allows rce/dossonicwall · sma 6200 firmware · CWE-364 | Yüksek8,1 | — | %99,5 | 1 Tem 2024 |
62Bu hafta | CVE-2003-0466Kavram kanıtı | Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code,redhat · wu ftpd · CWE-193 | Kritik9,8 | — | %78,1 | 27 Ağu 2003 |
60Bu hafta | CVE-2007-3798Kavram kanıtı | Integer overflow in print-bgp.c in the BGP dissector in tcpdump 3.9.6 and earlier allows remote attackers to execute arbitrary code via craftcpdump · tcpdump · CWE-252 | Kritik9,8 | — | %70,4 | 16 Tem 2007 |
60Bu hafta | CVE-2003-0694Silahlaştırılmış | The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated usingsendmail · advanced message server | Kritik10,0 | — | %66,2 | 6 Eki 2003 |
56Planlayın | CVE-2002-0391İstismar yok | Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including disun · solaris · CWE-190 | Kritik9,8 | — | %58,1 | 12 Ağu 2002 |
56Planlayın | CVE-1999-0046Kavram kanıtı | Buffer overflow of rlogin program using TERM environmental variable.bsdi · bsd os · CWE-120 | Kritik10,0 | — | %51,9 | 6 Şub 1997 |
52Planlayın | CVE-2001-0554Kavram kanıtı | Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a mit · kerberos · CWE-120 | Kritik10,0 | — | %38,7 | 14 Ağu 2001 |
51Planlayın | CVE-2023-48795Kavram kanıtı | The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypasssh · ssh · CWE-354 | Orta5,9 | — | %93,5 | 18 Ara 2023 |
51Planlayın | CVE-2006-0900Silahlaştırılmış | nfsd in FreeBSD 6.0 kernel allows remote attackers to cause a denial of service via a crafted NFS mount request, as demonstrated by the Protfreebsd · freebsd | Yüksek7,8 | — | %65,1 | 27 Şub 2006 |
46Planlayın | CVE-2020-1967Kavram kanıtı | Segmentation fault in SSL_check_chainopenssl · openssl · CWE-476 | Yüksek7,5 | — | %53,3 | 21 Nis 2020 |
46Planlayın | CVE-2018-17157İstismar yok | In FreeBSD before 11.2-STABLE(r340854) and 11.2-RELEASE-p5, an integer overflow error when handling opcodes can cause memory corruption by sfreebsd · freebsd · CWE-190 | Kritik9,8 | — | %24,2 | 4 Ara 2018 |
46Planlayın | CVE-2001-0247Kavram kanıtı | Buffer overflows in BSD-based FTP servers allows remote attackers to execute arbitrary commands via a long pattern string containing a {} semit · kerberos 5 | Kritik10,0 | — | %19,3 | 18 Haz 2001 |
45Planlayın | CVE-2005-0356Kavram kanıtı | Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackecisco · agent desktop | Orta5,0 | — | %82,8 | 31 May 2005 |
44Planlayın | CVE-2010-1938Kavram kanıtı | Off-by-one error in the __opiereadrec function in readrec.c in libopie in OPIE 2.4.1-test1 and earlier, as used on FreeBSD 6.4 through 8.1-Pfreebsd · freebsd · CWE-189 | Kritik9,3 | — | %21,9 | 28 May 2010 |
44Planlayın | CVE-2008-0122İstismar yok | Off-by-one error in the inet_network function in libbind in ISC BIND 9.4.2 and earlier, as used in libc in FreeBSD 6.2 through 7.0-PRERELEASisc · bind · CWE-189 | Kritik10,0 | — | %12,4 | 15 Oca 2008 |
44Planlayın | CVE-2006-4304İstismar yok | Buffer overflow in the sppp driver in FreeBSD 4.11 through 6.1, NetBSD 2.0 through 4.0 beta before 20060823, and OpenBSD 3.8 and 3.9 before freebsd · freebsd | Kritik10,0 | — | %11,9 | 23 Ağu 2006 |
43Planlayın | CVE-2009-4502Silahlaştırılmış | The NET_TCP_LISTEN function in net.c in Zabbix Agent before 1.6.7, when running on FreeBSD or Solaris, allows remote attackers to bypass thezabbix · zabbix · CWE-264 | Kritik9,3 | — | %21,6 | 31 Ara 2009 |
42Planlayın | CVE-2021-3449Kavram kanıtı | NULL pointer deref in signature_algorithms processingopenssl · openssl · CWE-476 | Orta5,9 | — | %63,5 | 25 Mar 2021 |
42Planlayın | CVE-2020-7457Silahlaştırılmış | In FreeBSD 12.1-STABLE before r359565, 12.1-RELEASE before p7, 11.4-STABLE before r362975, 11.4-RELEASE before p1, and 11.3-RELEASE before pfreebsd · freebsd · CWE-362 | Yüksek8,1 | — | %33,1 | 9 Tem 2020 |
42Planlayın | CVE-2008-2427Kavram kanıtı | Stack-based buffer overflow in NConvert 4.92, GFL SDK 2.82, and XnView 1.93.6 on Windows and 1.70 on Linux and FreeBSD allows user-assisted freebsd · freebsd · CWE-119 | Kritik9,3 | — | %16,1 | 24 Haz 2008 |
42Planlayın | CVE-2018-7183İstismar yok | Buffer overflow in the decodearr function in ntpq in ntp 4.2.8p6 through 4.2.8p10 allows remote attackers to execute arbitrary code by leverntp · ntp · CWE-787 | Kritik9,8 | — | %10,2 | 8 Mar 2018 |
42Planlayın | CVE-2000-0584Kavram kanıtı | Buffer overflow in Canna input system allows remote attackers to execute arbitrary commands via an SR_INIT command with a long user name or debian · debian linux | Kritik10,0 | — | %5,9 | 2 Tem 2000 |
42Planlayın | CVE-2006-0226İstismar yok | Integer overflow in IEEE 802.11 network subsystem (ieee80211_ioctl.c) in FreeBSD before 6.0-STABLE, while scanning for wireless networks, alfreebsd · freebsd | Kritik10,0 | — | %5,8 | 18 Oca 2006 |
- CVE-2011-486268Bu hafta
Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and
KritikCVSS 10,0SilahlaştırılmışEPSS %95mit · krb5-appl24 Ara 2011
- CVE-2020-1316063Bu hafta
AnyDesk before 5.5.3 on Linux and FreeBSD has a format string vulnerability that can be exploited for remote code execution.
KritikCVSS 9,8SilahlaştırılmışEPSS %81anydesk · anydesk9 Haz 2020
- CVE-2024-638762Bu hafta
Openssh: regresshion - race condition in ssh allows rce/dos
YüksekCVSS 8,1Kavram kanıtıEPSS %100sonicwall · sma 6200 firmware1 Tem 2024
- CVE-2003-046662Bu hafta
Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code,
KritikCVSS 9,8Kavram kanıtıEPSS %78redhat · wu ftpd27 Ağu 2003
- CVE-2007-379860Bu hafta
Integer overflow in print-bgp.c in the BGP dissector in tcpdump 3.9.6 and earlier allows remote attackers to execute arbitrary code via craf
KritikCVSS 9,8Kavram kanıtıEPSS %70tcpdump · tcpdump16 Tem 2007
- CVE-2003-069460Bu hafta
The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using
KritikCVSS 10,0SilahlaştırılmışEPSS %66sendmail · advanced message server6 Eki 2003
- CVE-2002-039156Planlayın
Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including di
KritikCVSS 9,8İstismar yokEPSS %58sun · solaris12 Ağu 2002
- CVE-1999-004656Planlayın
Buffer overflow of rlogin program using TERM environmental variable.
KritikCVSS 10,0Kavram kanıtıEPSS %52bsdi · bsd os6 Şub 1997
- CVE-2001-055452Planlayın
Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a
KritikCVSS 10,0Kavram kanıtıEPSS %39mit · kerberos14 Ağu 2001
- CVE-2023-4879551Planlayın
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypas
OrtaCVSS 5,9Kavram kanıtıEPSS %94ssh · ssh18 Ara 2023
- CVE-2006-090051Planlayın
nfsd in FreeBSD 6.0 kernel allows remote attackers to cause a denial of service via a crafted NFS mount request, as demonstrated by the Prot
YüksekCVSS 7,8SilahlaştırılmışEPSS %65freebsd · freebsd27 Şub 2006
- CVE-2020-196746Planlayın
Segmentation fault in SSL_check_chain
YüksekCVSS 7,5Kavram kanıtıEPSS %53openssl · openssl21 Nis 2020
- CVE-2018-1715746Planlayın
In FreeBSD before 11.2-STABLE(r340854) and 11.2-RELEASE-p5, an integer overflow error when handling opcodes can cause memory corruption by s
KritikCVSS 9,8İstismar yokEPSS %24freebsd · freebsd4 Ara 2018
- CVE-2001-024746Planlayın
Buffer overflows in BSD-based FTP servers allows remote attackers to execute arbitrary commands via a long pattern string containing a {} se
KritikCVSS 10,0Kavram kanıtıEPSS %19mit · kerberos 518 Haz 2001
- CVE-2005-035645Planlayın
Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attacke
OrtaCVSS 5,0Kavram kanıtıEPSS %83cisco · agent desktop31 May 2005
- CVE-2010-193844Planlayın
Off-by-one error in the __opiereadrec function in readrec.c in libopie in OPIE 2.4.1-test1 and earlier, as used on FreeBSD 6.4 through 8.1-P
KritikCVSS 9,3Kavram kanıtıEPSS %22freebsd · freebsd28 May 2010
- CVE-2008-012244Planlayın
Off-by-one error in the inet_network function in libbind in ISC BIND 9.4.2 and earlier, as used in libc in FreeBSD 6.2 through 7.0-PRERELEAS
KritikCVSS 10,0İstismar yokEPSS %12isc · bind15 Oca 2008
- CVE-2006-430444Planlayın
Buffer overflow in the sppp driver in FreeBSD 4.11 through 6.1, NetBSD 2.0 through 4.0 beta before 20060823, and OpenBSD 3.8 and 3.9 before
KritikCVSS 10,0İstismar yokEPSS %12freebsd · freebsd23 Ağu 2006
- CVE-2009-450243Planlayın
The NET_TCP_LISTEN function in net.c in Zabbix Agent before 1.6.7, when running on FreeBSD or Solaris, allows remote attackers to bypass the
KritikCVSS 9,3SilahlaştırılmışEPSS %22zabbix · zabbix31 Ara 2009
- CVE-2021-344942Planlayın
NULL pointer deref in signature_algorithms processing
OrtaCVSS 5,9Kavram kanıtıEPSS %64openssl · openssl25 Mar 2021
- CVE-2020-745742Planlayın
In FreeBSD 12.1-STABLE before r359565, 12.1-RELEASE before p7, 11.4-STABLE before r362975, 11.4-RELEASE before p1, and 11.3-RELEASE before p
YüksekCVSS 8,1SilahlaştırılmışEPSS %33freebsd · freebsd9 Tem 2020
- CVE-2008-242742Planlayın
Stack-based buffer overflow in NConvert 4.92, GFL SDK 2.82, and XnView 1.93.6 on Windows and 1.70 on Linux and FreeBSD allows user-assisted
KritikCVSS 9,3Kavram kanıtıEPSS %16freebsd · freebsd24 Haz 2008
- CVE-2018-718342Planlayın
Buffer overflow in the decodearr function in ntpq in ntp 4.2.8p6 through 4.2.8p10 allows remote attackers to execute arbitrary code by lever
KritikCVSS 9,8İstismar yokEPSS %10ntp · ntp8 Mar 2018
- CVE-2000-058442Planlayın
Buffer overflow in Canna input system allows remote attackers to execute arbitrary commands via an SR_INIT command with a long user name or
KritikCVSS 10,0Kavram kanıtıEPSS %6debian · debian linux2 Tem 2000
- CVE-2006-022642Planlayın
Integer overflow in IEEE 802.11 network subsystem (ieee80211_ioctl.c) in FreeBSD before 6.0-STABLE, while scanning for wireless networks, al
KritikCVSS 10,0İstismar yokEPSS %6freebsd · freebsd18 Oca 2006