FreeBSD Local Security Checks Family for Nessus

IDNameSeverity
136726FreeBSD : Rails -- multiple vulnerabilities (85fca718-99f6-11ea-bf1d-08002728f74c)
critical
136706FreeBSD : Dovecot -- Multiple vulnerabilities (37d106a8-15a4-483e-8247-fcb68b16eaf8)
high
136689FreeBSD : Rails -- remote code execution vulnerability (ce6db19b-976e-11ea-93c4-08002728f74c)
high
136688FreeBSD : clamav -- multiple vulnerabilities (91ce95d5-cd15-4105-b942-af5ccc7144c1)
high
136687FreeBSD : salt -- multiple vulnerabilities in salt-master process (6bf55af9-973b-11ea-9f2c-38d547003487)
critical
136635FreeBSD : json-c -- integer overflow and out-of-bounds write via a large JSON file (abc3ef37-95d4-11ea-9004-25fadb81abf4)
high
136596FreeBSD : typo3 -- multiple vulnerabilities (59fabdf2-9549-11ea-9448-08002728f74c)
critical
136537FreeBSD : FreeBSD -- Use after free in cryptodev module (9f15c2da-947e-11ea-92ab-00163e433440)
high
136536FreeBSD : FreeBSD -- Memory disclosure vulnerability in libalias (78992249-947c-11ea-92ab-00163e433440)
medium
136535FreeBSD : FreeBSD -- Insufficient packet length validation in libalias (30ce591c-947b-11ea-92ab-00163e433440)
critical
136534FreeBSD : FreeBSD -- Improper checking in SCTP-AUTH shared key update (253486f5-947d-11ea-92ab-00163e433440)
high
136533FreeBSD : FreeBSD -- Insufficient cryptodev MAC key length check (0bfcae0b-947f-11ea-92ab-00163e433440)
high
136444FreeBSD : glpi -- stored XSS (d222241d-91cc-11ea-82b8-4c72b94353b5)
medium
136443FreeBSD : Python -- CRLF injection via the host part of the url passed to urlopen() (ca595a25-91d8-11ea-b470-080027846a02)
medium
136442FreeBSD : qutebrowser -- Reloading page with certificate errors shows a green URL (452d16bb-920d-11ea-9d20-18a6f7016652)
low
136387FreeBSD : Wagtail -- potential timing attack vulnerability (d5fead4f-8efa-11ea-a5c8-08002728f74c)
medium
136386FreeBSD : cacti -- XSS exposure (cd864f1a-8e5a-11ea-b5b4-641c67a117d8)
medium
136385FreeBSD : mailman -- arbitrary content injection vulnerability via options or private archive login pages (88760f4d-8ef7-11ea-a66d-4b2ef158be83)
medium
136384FreeBSD : zeek -- Various vulnerabilities (1a6b7641-aed2-4ba1-96f4-c282d5b09c37)
high
136304FreeBSD : Gitlab -- Multiple Vulnerabilities (e8483115-8b8e-11ea-bdcf-001b217b3468)
high
136303FreeBSD : taglib -- heap-based buffer over-read via a crafted audio file (d3f3e818-8d10-11ea-8668-e0d55e2a8bf9)
medium
136302FreeBSD : Squid -- multiple vulnerabilities (57c1c2ee-7914-11ea-90bf-0800276545c1)
high
136160FreeBSD : ceph14 -- multiple security issues (5b6bc863-89dc-11ea-af8b-00155d0a0200)
medium
136159FreeBSD : vlc -- Multiple vulnerabilities fixed in VLC media player (4a10902f-8a48-11ea-8668-e0d55e2a8bf9)
high
136158FreeBSD : samba -- multiple vulnerabilities (3c7911c9-8a29-11ea-8d8c-005056a311d1)
high
136070FreeBSD : nested filters leads to stack overflow (c7617931-8985-11ea-93ef-b42e99a1b9c3)
high
136021FreeBSD : py-yaml -- FullLoader (still) exploitable for arbitrary command execution (aae8fecf-888e-11ea-9714-08002718de91)
critical
136003FreeBSD : py-bleach -- regular expression denial-of-service (4c52ec3c-86f3-11ea-b5b4-641c67a117d8)
high
135945FreeBSD : Nextcloud -- multiple vulnerabilities (afa018d9-8557-11ea-a5e2-d4c9ef517024)
high
135944FreeBSD : Python -- Regular Expression DoS attack against client (a27b0bb6-84fc-11ea-b5b4-641c67a117d8)
medium
135943FreeBSD : Wagtail -- XSS vulnerability (8d85d600-84a9-11ea-97b9-08002728f74c)
medium
135942FreeBSD : MySQL Client -- Multiple vulerabilities (622b5c47-855b-11ea-a5e2-d4c9ef517024)
medium
135941FreeBSD : MySQL Server -- Multiple vulerabilities (21d59ea3-8559-11ea-a5e2-d4c9ef517024)
critical
135883FreeBSD : py-twisted -- multiple vulnerabilities (9fbaefb3-837e-11ea-b5b4-641c67a117d8) (Ping Flood) (Reset Flood) (Settings Flood)
critical
135882FreeBSD : FreeBSD -- ipfw invalid mbuf handling (33edcc56-83f2-11ea-92ab-00163e433440)
critical
135881FreeBSD : libntlm -- buffer overflow vulnerability (0f798bd6-8325-11ea-9a78-08002728f74c)
critical
135880FreeBSD : OpenSSL remote denial of service vulnerability (012809ce-83f3-11ea-92ab-00163e433440)
high
135795FreeBSD : Client/server denial of service when handling AES-CTR ciphers (3d7dfd63-823b-11ea-b3a8-240a644dd835)
medium
135733FreeBSD : webkit2-gtk3 -- Denial of service (e418b8f0-9abb-420b-a7f1-1d8231b352e2)
high
135732FreeBSD : drupal -- Drupal Core - Moderately critical - Third-party library (e24fd421-8128-11ea-aa57-000ffec73f06)
high
135731FreeBSD : ansible - Vault password leak from temporary file (ae2e7871-80f6-11ea-bafd-815569f3852d)
medium
135730FreeBSD : ansible - subversion password leak from PID (67dbeeb6-80f4-11ea-bafd-815569f3852d)
low
135729FreeBSD : ansible - win_unzip path normalization (0899c0d3-80f2-11ea-bafd-815569f3852d)
high
135714FreeBSD : openvpn -- illegal client float can break VPN session for other users (8604121c-7fc2-11ea-bcac-7781e90b0c8f)
low
135713FreeBSD : chromium -- use after free (25efe05c-7ffc-11ea-b594-3065ec8fd3ec)
critical
135604FreeBSD : Mbed TLS -- Side channel attack on ECDSA (bf1f47c4-7f1b-11ea-bf94-001cc0382b2f)
medium
135603FreeBSD : Gitlab -- Multiple Vulnerabilities (570706ff-7ee0-11ea-bd0b-001b217b3468)
high
135500FreeBSD : zeek -- Remote crash vulnerability (f59c4c53-c55f-43fe-9920-82b9d1ea9c3d)
high
135425FreeBSD : chromium -- multiple vulnerabilities (6e3b700a-7ca3-11ea-b594-3065ec8fd3ec)
high
135194FreeBSD : Apache -- Multiple vulnerabilities (b360b120-74b1-11ea-a84a-4c72b94353b5)
medium