FreeBSD Local Security Checks Family for Nessus

IDNameSeverity
140312FreeBSD : Mbed TLS -- Local side channel attack on classical CBC decryption in (D)TLS (4c69240f-f02c-11ea-838a-0011d823eebd)
medium
140311FreeBSD : GnuTLS -- NULL pointer dereference (2272e6f1-f029-11ea-838a-0011d823eebd)
high
140310FreeBSD : Django -- multiple vulnerabilities (002432c8-ef6a-11ea-ba8f-08002728f74c)
high
140238FreeBSD : gnupg -- AEAD key import overflow (f9fa7adc-ee51-11ea-a240-002590acae31)
high
140237FreeBSD : FreeBSD -- SCTP socket use-after-free bug (77b877aa-ec18-11ea-88f8-901b0ef719ab)
medium
140236FreeBSD : FreeBSD -- dhclient heap overflow (762b7d4a-ec19-11ea-88f8-901b0ef719ab)
high
140235FreeBSD : FreeBSD -- IPv6 Hop-by-Hop options use-after-free bug (74bbde13-ec17-11ea-88f8-901b0ef719ab)
medium
140234FreeBSD : Gitlab -- multiple vulnerabilities (1fb13175-ed52-11ea-8b93-001b217b3468)
critical
140135FreeBSD : go -- net/http/cgi, net/http/fcgi: XSS (XSS) when Content-Type is not specified (67b050ae-ec82-11ea-9071-10c37b4ac2ea)
medium
139935FreeBSD : php72 -- use of freed hash key (ee261034-b95e-4479-b947-08b0877e029f)
low
139934FreeBSD : ark -- extraction outside of extraction directory (38fdf07b-e8ec-11ea-8bbe-e0d55e2a8bf9)
low
139886FreeBSD : chromium -- multiple vulnerabilities (d73bc4e6-e7c4-11ea-a878-e09467587c17)
high
139832FreeBSD : xorg-server -- Multiple input validation failures in X server extensions (ffa15b3b-e6f6-11ea-8cbf-54e1ad3d6335)
high
139831FreeBSD : libX11 -- Doublefree in locale handlng code (8da79498-e6f6-11ea-8cbf-54e1ad3d6335)
high
139830FreeBSD : jasper -- multiple vulnerabilities (6842ac7e-d250-11ea-b9b7-08002728f74c)
high
139763FreeBSD : chrony <= 3.5.1 data corruption through symlink vulnerability writing the pidfile (719f06af-e45e-11ea-95a1-c3b8167b8026)
medium
139740FreeBSD : textproc/elasticsearch6 -- field disclosure flaw (fbca6863-e2ad-11ea-9d39-00a09858faf5)
medium
139739FreeBSD : sysutils/openzfs-kmod -- critical permissions issues (2ed7e8db-e234-11ea-9392-002590bc43be)
high
139738FreeBSD : adns -- multiple vulnerabilities (08de38d2-e2d0-11ea-9538-0c9d925bbbc0)
critical
139717FreeBSD : Icinga Web 2 -- directory traversal vulnerability (f60561e7-e23e-11ea-be64-507b9d01076a)
high
139716FreeBSD : security/trousers -- several vulnerabilities (e37a0a7b-e1a7-11ea-9538-0c9d925bbbc0)
high
139715FreeBSD : curl -- expired pointer dereference vulnerability (b905dff4-e227-11ea-b0ea-08002728f74c)
high
139714FreeBSD : Python -- multiple vulnerabilities (3fcb70a4-e22d-11ea-98b2-080027846a02)
high
139683FreeBSD : chromium -- heap buffer overflow (64575bb6-e188-11ea-beed-e09467587c17)
high
139643FreeBSD : ceph14 -- HTTP header injection via CORS ExposeHeader tag (f20eb9a4-dfea-11ea-a9b8-9c5c8e84d621)
medium
139642FreeBSD : snmptt -- malicious shell code (b8ea5b66-deff-11ea-adef-641c67a117d8)
high
139641FreeBSD : security/py-ecdsa -- multiple issues (a23ebf36-e8b6-4665-b0f3-4c977f9a145c)
critical
139640FreeBSD : jenkins -- Buffer corruption in bundled Jetty (09ea1b08-1d3e-4bf2-91a1-d6573f4da3d8)
critical
139639FreeBSD : net/rsync -- multiple zlib issues (085399ab-dfd7-11ea-96e4-80ee73bc7b66)
critical
139590FreeBSD : ilmbase, openexr -- v2.5.3 is a patch release with various bug/security fixes (b1d6b383-dd51-11ea-a688-7b12871ef3ad)
high
139589FreeBSD : mail/dovecot -- multiple vulnerabilities (87a07de1-e55e-4d51-bb64-8d117829a26a)
high
139557FreeBSD : jenkins -- multiple vulnerabilities (eef0d2d9-78c0-441e-8b03-454c5baebe20)
medium
139529FreeBSD : chromium -- multiple vulnerabilities (1110e286-dc08-11ea-beed-e09467587c17)
high
139472FreeBSD : bftpd -- Multiple vulnerabilities (6b6de127-db0b-11ea-ba1e-1c39475b9f84)
high
139471FreeBSD : puppetdb -- Multiple vulnerabilities (10e3ed8a-db7f-11ea-8bdf-643150d3111d)
critical
139436FreeBSD : Apache httpd -- Multiple vulnerabilities (76700d2f-d959-11ea-b53c-d4c9ef517024)
critical
139435FreeBSD : trafficserver -- resource consumption (6fd773d3-bc5a-11ea-b38d-f0def1d0c3ea)
high
139395FreeBSD : go -- encoding/binary: ReadUvarint and ReadVarint can read an unlimited number of bytes from invalid inputs (bc7aff8c-d806-11ea-a5aa-0800272260e5)
high
139394FreeBSD : Gitlab -- Multiple Vulnerabilities (a003b74f-d7b3-11ea-9df1-001b217b3468)
critical
139349FreeBSD : typo3 -- multiple vulnerabilities (eab964f8-d632-11ea-9172-4c72b94353b5)
high
139348FreeBSD : FreeBSD -- Potential memory corruption in USB network device drivers (9eb01384-d793-11ea-88f8-901b0ef719ab)
medium
139347FreeBSD : FreeBSD -- sendmsg(2) privilege escalation (8db74c04-d794-11ea-88f8-901b0ef719ab)
high
139268FreeBSD : Python -- multiple vulnerabilities (7d7221ee-d334-11ea-bc50-080027846a02)
critical
139267FreeBSD : libX11 -- Heap corruption in the X input method client in libX11 (6faa7feb-d3fa-11ea-9aba-0c9d925bbbc0)
medium
139266FreeBSD : xorg-server -- Pixel Data Uninitialized Memory Information Disclosure (3c7ba82a-d3fb-11ea-9aba-0c9d925bbbc0)
medium
139218FreeBSD : ark -- directory traversal (d1ef1138-d273-11ea-a757-e0d55e2a8bf9)
low
139114FreeBSD : zeek -- Various vulnerabilities (e333084c-9588-4eee-8bdc-323e02cb4fe0)
high
139113FreeBSD : Wagtail -- XSS vulnerability (e1d3a580-cd8b-11ea-bad0-08002728f74c)
medium
139112FreeBSD : Cacti -- multiple vulnerabilities (cd2dc126-cfe4-11ea-9172-4c72b94353b5)
high
139111FreeBSD : FreeRDP -- Integer overflow in RDPEGFX channel (a955cdb7-d089-11ea-8c6f-080027eedc6a)
low