CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
Sendmail decode alias can be used to overwrite sensitive files. |
Sendmail allows local users to write to a file and gain group permissions via a .forward or :include: file. |
Local users can start Sendmail in daemon mode and gain root privileges. |
Multiple TCP implementations could allow remote attackers to cause a denial of service (bandwidth and CPU exhaustion) by setting the maximum segment size (MSS) to a very small number and requesting large amounts of data, which generates more packets with less TCP-level data that amplify network traffic and consume more server CPU to process. |
Buffer overflow and denial of service in Sendmail 8.7.5 and earlier through GECOS field gives root access to local users. |
The suidperl and sperl program do not give up root privileges when changing UIDs back to the original users, allowing root access. |
Buffer overflow in FreeBSD lpd through long DNS hostnames. |
The system configuration control (sysctl) facility in BSD based operating systems OpenBSD 2.2 and earlier, and FreeBSD 2.2.5 and earlier, does not properly restrict source routed packets even when the (1) dosourceroute or (2) forwarding variables are set, which allows remote attackers to spoof TCP connections. |
The open() function in FreeBSD allows local attackers to write to arbitrary files. |
Jolt ICMP attack causes a denial of service in Windows 95 and Windows NT systems. |
A buffer overflow in lsof allows local users to obtain root privilege. |
IPSEC implementations including (1) FreeS/WAN and (2) KAME do not properly calculate the length of authentication data, which allows remote attackers to cause a denial of service (kernel panic) via spoofed, short Encapsulating Security Payload (ESP) packets, which result in integer signedness errors. |
The SYN cache (syncache) and SYN cookie (syncookie) mechanism in FreeBSD 4.5 and earlier allows remote attackers to cause a denial of service (crash) (1) via a SYN packet that is accepted using syncookies that causes a null pointer to be referenced for the socket's TCP options, or (2) by killing and restarting a process that listens on the same socket, which does not properly clear the old inpcb pointer on restart. |
The rwho/rwhod service is running, which exposes machine status and user information. |
KDE klock allows local users to kill arbitrary processes by specifying an arbitrary PID in the .kss.pid file. |
KDE kppp allows local users to create a directory in an arbitrary location via the HOME environmental variable. |
FreeBSD allows local users to conduct a denial of service by creating a hard link from a device special file to a file on an NFS file system. |
Buffer overflow in FreeBSD xmindpath allows local users to gain privileges via -f argument. |
Buffer overflow in FreeBSD gdc program. |
FreeBSD gdc program allows local users to modify files via a symlink attack. |