FreeBSD

15 May

CVE-2012-2612

The DiagTraceHex function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatch ...

CVE-2012-2611

The DiagTraceR3Info function in the Dialog processor in disp+work.exe 7010.29.15.58313 and 7200. ...

CVE-2012-2514

The DiagiEventSource function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Disp ...

CVE-2012-2513

The Diaginput function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher ...

CVE-2012-2512

The DiagTraceStreamI function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Disp ...

CVE-2012-2511

The DiagTraceAtoms function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispat ...

14 May

CVE-2012-2333

Integer underflow in OpenSSL before 0.9.8x, 1.0.0 before 1.0.0j, and 1.0.1 before 1.0.1c, when TLS 1 ...

CVE-2012-2277

The IRM Server in EMC Documentum Information Rights Management 4.x before 4.7.0100 and 5.x before 5. ...

CVE-2012-2276

The IRM Server in EMC Documentum Information Rights Management 4.x before 4.7.0100 and 5.x before 5. ...

CVE-2012-1804

Progea Movicon before 11.3 allows remote attackers to cause a denial of service (out-of-bounds r ...

Óâåäîìëåíèÿ 22 - 36 of 426
First | Prev. | 1 2 3 4 5 6 7 8 9 10 11 | Next | Last 

FreeBSD-SA-09:13.pipe: kqueue pipe race conditions

A race condition exists in the pipe close() code relating to kqueues, causing use-after-free for kernel memory, which may lead to an exploitable NULL pointer vulnerability in the kernel, kernel memory corruption, and other unpredictable results.

03 october, 2009

FreeBSD-SA-09:14.devfs: Devfs / VFS NULL pointer race condition

Due to the interaction between devfs and VFS, a race condition exists where the kernel might dereference a NULL pointer.

03 october, 2009

FreeBSD-SA-09:12.bind: BIND named(8) dynamic update message remote DoS

When named(8) receives a specially crafted dynamic update message an internal assertion check is triggered which causes named(8) to exit.

29 july, 2009

FreeBSD-EN-09:02.bce: bce(4) does not work with lagg(4) LACP mode

The bce(4) driver used an incorrect total packet length calculation.

24 june, 2009

FreeBSD-EN-09:04.fork: Deadlock in a multi-threaded program during fork(2)

A lock order reversal has been found in the interaction between the malloc(3) implementation and threading library.

24 june, 2009

FreeBSD-EN-09:03.fxp: Poor TCP performance of fxp(4)

When a TSO option is enabled, fxp(4) always sets the length of outgoing IP packets as the interface MTU (Maximum Transmission Unit).

24 june, 2009

FreeBSD-SA-09:09.pipe: Local information disclosure via direct pipe writes

An integer overflow in computing the set of pages containing data to be copied can result in virtual-to-physical address lookups not being performed.

10 june, 2009

FreeBSD-SA-09:11.ntpd: ntpd stack-based buffer-overflow vulnerability

The ntpd(8) daemon is prone to a stack-based buffer-overflow when it is configured to use the 'autokey' security model.

10 june, 2009

FreeBSD-SA-09:10.ipv6: Missing permission check on SIOCSIFINFO_IN6 ioctl

The SIOCSIFINFO_IN6 ioctl is missing a necessary permissions check.

10 june, 2009

FreeBSD-SA-09:07.libc: Information leak in db(3)

Some data structures used by the database interface code are not properly initialized when allocated.

22 april, 2009

FreeBSD-SA-09:08.openssl: Remotely exploitable crash in OpenSSL

The function ASN1_STRING_print_ex does not properly validate the lengths of BMPString or UniversalString objects before attempting to print them.

22 april, 2009

FreeBSD-EN-09:01.kenv: Kernel panic when dumping environment

When dumping all of the entries in the kernel environment, the kernel does not adequately bounds-check the size of the buffer into which the environment should be written.

23 march, 2009

FreeBSD-SA-09:06.ktimer: Local privilege escalation

An integer which specifies which timer a process wishes to operate upon is not properly bounds-checked.

23 march, 2009

FreeBSD-SA-09:05.telnetd: telnetd code execution vulnerability

In order to prevent environment variable based attacks, telnetd(8) "scrubs" its environment; however, recent changes in FreeBSD's environment-handling code rendered telnetd's scrubbing inoperative, thereby allowing potentially harmful environment variables to be set.

17 february, 2009

FreeBSD-SA-09:03.ntpd: ntpd cryptographic signature bypass

The EVP_VerifyFinal() function from OpenSSL is used to determine if a digital signature is valid.

14 january, 2009

Óâåäîìëåíèÿ 22 - 36 of 426
First | Prev. | 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 | Next | Last

CVE-2012-2612

The DiagTraceHex function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.

15 may, 2012

CVE-2012-2611

The DiagTraceR3Info function in the Dialog processor in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2, when a certain Developer Trace configuration is enabled, allows remote attackers to execu ...

15 may, 2012

CVE-2012-2514

The DiagiEventSource function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.

15 may, 2012

CVE-2012-2513

The Diaginput function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.

15 may, 2012

CVE-2012-2512

The DiagTraceStreamI function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.

15 may, 2012

CVE-2012-2511

The DiagTraceAtoms function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote attackers to cause a denial of service (daemon crash) via a crafted SAP Diag packet.

15 may, 2012

CVE-2012-2333

Integer underflow in OpenSSL before 0.9.8x, 1.0.0 before 1.0.0j, and 1.0.1 before 1.0.1c, when TLS 1.1, TLS 1.2, or DTLS is used with CBC encryption, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecif ...

14 may, 2012

CVE-2012-2277

The IRM Server in EMC Documentum Information Rights Management 4.x before 4.7.0100 and 5.x before 5.0.1030 allows remote attackers to cause a denial of service (pvcontrol.exe process hang) via \n (line feed) characters in the Id fields of ...

14 may, 2012

CVE-2012-2276

The IRM Server in EMC Documentum Information Rights Management 4.x before 4.7.0100 and 5.x before 5.0.1030 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via input data that (1) lacks FIPS ...

14 may, 2012

CVE-2012-1804

Progea Movicon before 11.3 allows remote attackers to cause a denial of service (out-of-bounds read and memory corruption) via a crafted HTTP request.

14 may, 2012

Firefox 8/9 AttributeChildRemoved() Use-After-Free Exploit

Target: Mozilla Firefox 8.x, 9.x
Impact: Code execution

MS12-027 MSCOMCTL ActiveX Buffer Overflow Exploit (meta)

Target: MSCOMCTL ActiveX
Impact: Code execution

Microsoft Windows RDP PoC (CVE-2012-0002)

Target: Microsoft Windows XP, 2003, Vista, 7, 2008
Impact: Code execution