Page 10 of 103 results (0.007 seconds)

CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 0

02 Aug 2002 — FreeBSD kernel 4.6 and earlier closes the file descriptors 0, 1, and 2 after they have already been assigned to /dev/null when the descriptors reference procfs or linprocfs, which could allow local users to reuse the file descriptors in a setuid or setgid program to modify critical data and gain privileges. • ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-02:23.stdio.asc •

CVSS: 7.8EPSS: 0%CPEs: 28EXPL: 0

08 Mar 2002 — Buffer overflow in ncurses 5.0, and the ncurses4 compatibility package as used in Red Hat Linux, allows local users to gain privileges, related to "routines for moving the physical cursor and scrolling." El desbordamiento del búfer en ncurses 5.0, y el paquete de compatibilidad ncurses4 basado en él, permite a usuarios locales la obtención de privilegios. • http://www.debian.org/security/2002/dsa-113 • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •

CVSS: 7.8EPSS: 0%CPEs: 12EXPL: 0

11 Dec 2000 — Buffer overflow in catopen() function in FreeBSD 5.0 and earlier, and possibly other OSes, allows local users to gain root privileges via a long environmental variable. • ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:53.catopen.asc •

CVSS: 7.2EPSS: 0%CPEs: 12EXPL: 0

29 Nov 2000 — The catopen function in FreeBSD 5.0 and earlier, and possibly other OSes, allows local users to read arbitrary files via the LANG environmental variable. • ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:53.catopen.asc •

CVSS: 7.2EPSS: 0%CPEs: 12EXPL: 0

29 Nov 2000 — The setlocale function in FreeBSD 5.0 and earlier, and possibly other OSes, allows local users to read arbitrary files via the LANG environmental variable. • ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:53.catopen.asc •

CVSS: 7.8EPSS: 0%CPEs: 4EXPL: 0

14 Nov 2000 — Multiple buffer overflows in eject on FreeBSD and possibly other OSes allows local users to gain root privileges. • http://archives.neohapsis.com/archives/freebsd/2000-09/0110.html •

CVSS: 7.8EPSS: 0%CPEs: 9EXPL: 0

20 Oct 2000 — Buffer overflow in the Linux binary compatibility module in FreeBSD 3.x through 5.x allows local users to gain root privileges via long filenames in the linux shadow file system. • http://archives.neohapsis.com/archives/freebsd/2000-08/0338.html •

CVSS: 5.5EPSS: 0%CPEs: 11EXPL: 0

20 Oct 2000 — FreeBSD 5.x, 4.x, and 3.x allows local users to cause a denial of service by executing a program with a malformed ELF image header. • http://archives.neohapsis.com/archives/freebsd/2000-08/0337.html •

CVSS: 7.8EPSS: 0%CPEs: 6EXPL: 0

21 Sep 2000 — Buffer overflows in brouted in FreeBSD and possibly other OSes allows local users to gain root privileges via long command line arguments. • http://archives.neohapsis.com/archives/freebsd/2000-08/0339.html •

CVSS: 7.5EPSS: 0%CPEs: 3EXPL: 0

12 Jun 2000 — OpenSSL 0.9.4 and OpenSSH for FreeBSD do not properly check for the existence of the /dev/random or /dev/urandom devices, which are absent on FreeBSD Alpha systems, which causes them to produce weak keys which may be more easily broken. • http://archives.neohapsis.com/archives/freebsd/2000-06/0083.html •