FreeBSD Local Security Checks Family for Nessus

IDNameSeverity
133436FreeBSD : MariaDB -- Vulnerability in C API (cb0183bb-45f6-11ea-a1c7-b499baebfeaf)
medium
133435FreeBSD : spamassassin -- Nefarious rule configuration files can run system commands (c86bfee3-4441-11ea-8be3-54e1ad3d6335)
high
133434FreeBSD : Gitlab -- Multiple Vulnerabilities (c5bd9068-440f-11ea-9cdb-001b217b3468)
critical
133433FreeBSD : sudo -- Potential bypass of Runas user restrictions (b4e5f782-442d-11ea-9ba9-206a8a720317)
high
133432FreeBSD : libssh -- Unsanitized location in scp could lead to unwanted command execution (1e7fa41b-f6ca-4fe8-bd46-0e176b42b14f)
high
133380FreeBSD : spamassassin -- Apache SpamAssassin Nefarious rule configuration (.cf) files can be configured to run system commands with warnings (e3404a6e-4364-11ea-b643-206a8a720317)
high
133329FreeBSD : jenkins -- multiple vulnerabilities (a250539d-d1d4-4591-afd3-c8bdfac335d8)
high
133328FreeBSD : pkg -- vulnerability in libfetch (2af10639-4299-11ea-aab1-98fa9bfec35a)
critical
133327FreeBSD : OpenSMTPd -- critical LPE / RCE vulnerability (08f5c27d-4326-11ea-af8b-00155d0a0200)
critical
133245FreeBSD : webkit-gtk3 -- Multiple vulnerabilities (dc8cff4c-4063-11ea-8a94-3497f6939fdd)
high
133244FreeBSD : samba -- multiple vulnerabilities (5f0dd349-40a2-11ea-8d8c-005056a311d1)
medium
133243FreeBSD : Pillow -- Multiple vulnerabilities (0700e76c-3eb0-11ea-8478-3085a9a95629)
critical
133121FreeBSD : gitea -- multiple vulnerabilities (a512a412-3a33-11ea-af63-0800274e5f20)
high
132943FreeBSD : drm graphics drivers -- potential information disclusure via local access (d2c2c815-3793-11ea-8be3-54e1ad3d6335)
medium
132942FreeBSD : MySQL -- Multiple vulerabilities (a6cf65ad-37d2-11ea-a1c7-b499baebfeaf)
critical
132880FreeBSD : Gitlab -- Private objects exposed through project import (f929b172-369e-11ea-9cdb-001b217b3468)
medium
132879FreeBSD : Template::Toolkit -- Directory traversal on write (2bab995f-36d4-11ea-9dad-002590acae31)
critical
132793FreeBSD : e2fsprogs -- rehash.c/pass 3a mutate_name() code execution vulnerability (8b61308b-322a-11ea-b34b-1de6fb24355d)
medium
132792FreeBSD : phpMyAdmin -- SQL injection (16aed7b7-344a-11ea-9cdb-001b217b3468)
high
132683FreeBSD : cacti -- multiple vulnerabilities (86224a04-26de-11ea-97f2-001a8c5c04b6)
high
132665FreeBSD : Gitlab -- Multiple Vulnerabilities (01bde18a-2e09-11ea-a935-001b217b3468)
medium
132429FreeBSD : OpenEXR -- heap buffer overflow, and out-of-memory bugs (e4d9dffb-2a32-11ea-9693-e1b3f6feec79)
high
132428FreeBSD : rack -- information leak / session hijack vulnerability (66e4dc99-28b3-11ea-8dde-08002728f74c)
medium
132411FreeBSD : wordpress -- multiple issues (7b97b32e-27c4-11ea-9673-4c72b94353b5)
high
132410FreeBSD : typo3 -- multiple vulnerabilities (1c9178aa-2709-11ea-9673-4c72b94353b5)
high
132352FreeBSD : py-matrix-synapse -- multiple vulnerabilities (ed8cbad5-21a8-11ea-9b6d-901b0e934d69)
high
132351FreeBSD : OpenSSL -- Overflow vulnerability (d778ddb0-2338-11ea-a1c7-b499baebfeaf)
medium
132350FreeBSD : e2fsprogs -- maliciously corrupted file systems can trigger buffer overruns in the quota code used by e2fsck (ad3451b9-23e0-11ea-8b36-f1925a339a82)
medium
132349FreeBSD : drupal -- Drupal Core - Multiple Vulnerabilities (3da0352f-2397-11ea-966e-000ffec0b3e1)
high
132066FreeBSD : dovecot -- NULL pointer deref in notify with empty headers (b7dc4dde-2e48-43f9-967a-c68461537cf2)
medium
132065FreeBSD : spamassassin -- multiple vulnerabilities (70111759-1dae-11ea-966a-206a8a720317)
medium
132064FreeBSD : samba -- multiple vulnerabilities (1edae47e-1cdd-11ea-8c2a-08002743b791)
medium
131970FreeBSD : Gitlab -- Multiple Vulnerabilities (21944144-1b90-11ea-a2d4-001b217b3468)
critical
131844FreeBSD : Ghostscript -- Security bypass vulnerabilities (22ae307a-1ac4-11ea-b267-001cc0382b2f)
critical
131795FreeBSD : phpmyadmin -- multiple vulnerabilities (ca3fe5b3-185e-11ea-9673-4c72b94353b5)
high
131471FreeBSD : py-matrix-synapse -- incomplete cleanup of 3rd-party-IDs on user deactivation (9c36d41c-11df-11ea-9b6d-901b0e934d69)
high
131470FreeBSD : Django -- multiple vulnerabilities (4e3fa78b-1577-11ea-b66e-080027bdabe8)
medium
131469FreeBSD : Gitlab -- Multiple Vulnerabilities (4ce7c28a-11ac-11ea-b537-001b217b3468)
medium
131468FreeBSD : py-matrix-synapse -- missing signature checks on some federation APIs (42675046-fa70-11e9-ba4e-901b0e934d69)
high
131467FreeBSD : webkit2-gtk3 -- Multiple vulnerabilities (3e748551-c732-45f6-bd88-928da16f23a8)
high
131466FreeBSD : Gitlab -- Multiple Vulnerabilities (1aa7a094-1147-11ea-b537-001b217b3468)
critical
131340FreeBSD : urllib3 -- multiple vulnerabilities (87270ba5-03d3-11ea-b81f-3085a9a95629)
critical
131297FreeBSD : FreeBSD -- Intel CPU Microcode Update (fbe10a8a-05a1-11ea-9dfa-f8b156ac3ff9) (MFBDS/RIDL/ZombieLoad) (MLPDS/RIDL) (MSBDS/Fallout) (Spectre)
critical
131296FreeBSD : FreeBSD -- Machine Check Exception on Page Size Change (edc0bf7e-05a1-11ea-9dfa-f8b156ac3ff9)
medium
131295FreeBSD : clamav -- Denial-of-Service (DoS) vulnerability (6ade62d9-0f62-11ea-9673-4c72b94353b5)
medium
131264FreeBSD : unbound -- parsing vulnerability (ffc80e58-0dcb-11ea-9673-4c72b94353b5)
high
131263FreeBSD : gitea -- multiple vulnerabilities (b12a341a-0932-11ea-bf09-080027e0baa0)
high
131262FreeBSD : asterisk -- SIP request can change address of a SIP peer (a8d94711-0d03-11ea-87ca-001999f8d30b)
medium
131261FreeBSD : asterisk -- Re-invite with T.38 and malformed SDP causes crash (94c6951a-0d04-11ea-87ca-001999f8d30b)
high
131260FreeBSD : asterisk -- AMI user could execute system commands (49b61ab6-0d04-11ea-87ca-001999f8d30b)
high