FreeBSD Local Security Checks Family for Nessus

IDNameSeverity
182077FreeBSD : xrdp -- Improper handling of session establishment errors allows bypassing OS-level session restrictions (c9ff1150-5d63-11ee-bbae-1c61b4739ac9)
medium
182076FreeBSD : xrdp -- unchecked access to font glyph info (af065e47-5d62-11ee-bbae-1c61b4739ac9)
medium
181924FreeBSD : routinator -- Possible path traversal when storing RRDP responses (ea9d1fd2-5d24-11ee-8507-b42e991fc52e)
medium
181837FreeBSD : jenkins -- multiple vulnerabilities (402fccd0-5b6d-11ee-9898-00e081b7aa2d)
high
181830FreeBSD : Mailpit affected by vulnerability in included go markdown module (732282a5-5a10-11ee-bca0-001999f8d30b)
high
181761FreeBSD : graphics/webp heap buffer overflow (4fd7a2fc-5860-11ee-a1b3-dca632daf43b)
high
181686FreeBSD : libwebp heap buffer overflow (58a738d4-57af-11ee-8c58-b42e991fc52e)
high
181611FreeBSD : Gitlab -- vulnerability (32a4896a-56da-11ee-9186-001b217b3468)
critical
181523FreeBSD : routinator -- multiple vulnerabilities (11982747-544c-11ee-ac3e-a04a5edf46d9)
medium
181522FreeBSD : Roundcube -- XSS vulnerability (b5508c08-547a-11ee-85eb-84a93843eb75)
high
181521FreeBSD : curl -- HTTP headers eat all memory (833b469b-5247-11ee-9667-080027f5fec9)
high
181369FreeBSD : electron22 -- multiple vulnerabilities (3693eca5-f0d3-453c-9558-2353150495bb)
high
181368FreeBSD : electron{24,25} -- multiple vulnerabilities (773ce35b-eabb-47e0-98ca-669b2b98107a)
high
181338FreeBSD : chromium -- multiple vulnerabilities (88754d55-521a-11ee-8290-a8a1599412c6)
high
181337FreeBSD : vscode -- VS Code Remote Code Execution Vulnerability (4bc66a81-89d2-4696-a04b-defd2eb77783)
high
181322FreeBSD : zeek -- potential DoS vulnerabilities (8eefa87f-31f1-496d-bf8e-2b465b6e4e8a)
high
181208FreeBSD : gitea -- block user account creation from blocked email domains (4061a4b2-4fb1-11ee-acc7-0151f07bc899)
high
180585FreeBSD : redis -- Possible bypassing ACL configuration (6c72b13f-4d1d-11ee-a7f1-080027f5fec9)
low
180584FreeBSD : Python -- multiple vulnerabilities (a57472ba-4d84-11ee-bf05-000c29de725b)
medium
180583FreeBSD : go -- multiple vulnerabilities (beb36f39-4d74-11ee-985e-bff341e78d94)
critical
180582FreeBSD : FreeBSD -- pf incorrectly handles multiple IPv6 fragment headers (d35373ae-4d34-11ee-8e38-002590c1f29c)
high
180581FreeBSD : FreeBSD -- Wi-Fi encryption bypass (924cb116-4d35-11ee-8e38-002590c1f29c)
high
180542FreeBSD : chromium -- multiple vulnerabilities (df0a2fd1-4c92-11ee-8290-a8a1599412c6)
high
180489FreeBSD : Django -- multiple vulnerabilities (8fd4f40a-4b7d-11ee-aa2a-080027de9982)
high
180454FreeBSD : Gitlab -- Vulnerabilities (aaea7b7c-4887-11ee-b164-001b217b3468)
high
180430FreeBSD : Borg (Backup) -- flaw in cryptographic authentication scheme in Borg allowed an attacker to fake archives and indirectly cause backup data loss. (b8a52e5a-483d-11ee-971d-3df00e0f9020)
medium
180383FreeBSD : py-pygments -- multiple DoS vulnerabilities (cdc685b5-1724-49a1-ad57-2eaab68e9cc0)
high
180382FreeBSD : py-markdown2 -- regular expression denial of service vulnerability (c9b3324f-8e03-4ae3-89ce-8098cdc5bfa9)
high
180381FreeBSD : py-httpie -- exposure of sensitive information vulnerabilities (1e37fa3e-5988-4991-808f-eae98047e2af)
medium
180380FreeBSD : py-Scrapy -- cookie injection vulnerability (a5403af6-225e-48ba-b233-bd95ad26434a)
high
180379FreeBSD : py-django-photologue -- XSS vulnerability (c2c89dea-2859-4231-8f3b-012be0d475ff)
medium
180378FreeBSD : py-flask-security -- user redirect to arbitrary URL vulnerability (06492bd5-085a-4cc0-9743-e30164bdcb1c)
medium
180377FreeBSD : py-Scrapy -- exposure of sensitive information vulnerability (67fe5e5b-549f-4a2a-9834-53f60eaa415e)
medium
180376FreeBSD : py-Flask-Cors -- directory traversal vulnerability (252f40cb-618c-47f4-a2cf-1abf30cffbbe)
high
180375FreeBSD : py-flask-caching -- remote code execution or local privilege escalation vulnerabilities (692a5fd5-bb25-4df4-8a0e-eb91581f2531)
critical
180374FreeBSD : py-dparse -- REDoS vulnerability (83b29e3f-886f-439f-b9a8-72e014479ff9)
high
180373FreeBSD : py-wagtail -- DoS vulnerability (2def7c4b-736f-4754-9f03-236fcb586d91)
medium
180372FreeBSD : py-Scrapy -- DoS vulnerability (4eb5dccb-923c-4f18-9cd4-b53f9e28d4d7)
high
180371FreeBSD : py-markdown2 -- XSS vulnerability (cf6f3465-e996-4672-9458-ce803f29fdb7)
medium
180370FreeBSD : py-WsgiDAV -- XSS vulnerability (1a15b928-5011-4953-8133-d49e24902fe1)
medium
180369FreeBSD : py-httpx -- input validation vulnerability (e831dd5a-7d8e-4818-aa1f-17dd495584ec)
critical
180368FreeBSD : py-Scrapy -- credentials leak vulnerability (2ad25820-c71a-4e6c-bb99-770c66fe496d)
high
180367FreeBSD : electron25 -- multiple vulnerabilities (970dcbe0-a947-41a4-abe9-7aaba87f41fe)
high
180366FreeBSD : py-wagtail -- stored XSS vulnerability (17efbe19-4e72-426a-8016-2b4e001c1378)
medium
180365FreeBSD : electron22 -- multiple vulnerabilities (579c7489-c23d-454a-b0fc-ed9d80ea46e0)
high
180364FreeBSD : py-treq -- sensitive information leak vulnerability (181f5e49-b71d-4527-9464-d4624d69acc3)
medium
180363FreeBSD : electron24 -- multiple vulnerabilities (29f050e9-3ef4-4c5f-8204-503b41caf181)
high
180348FreeBSD : FreeBSD -- Network authentication attack via pam_krb5 (9b0d9832-47c1-11ee-8e38-002590c1f29c)
critical
180347FreeBSD : FreeBSD -- OpenSSH pre-authentication double free (09b7cd39-47bd-11ee-8e38-002590c1f29c)
medium
180346FreeBSD : FreeBSD -- bhyve privileged guest escape via fwctl (ab437561-47c0-11ee-8e38-002590c1f29c)
high