Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2014-3880 | First vendor Publication | 2014-06-10 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:L/AC:L/Au:N/C:N/I:N/A:C) | |||
---|---|---|---|
Cvss Base Score | 4.9 | Attack Range | Local |
Cvss Impact Score | 6.9 | Attack Complexity | Low |
Cvss Expoit Score | 3.9 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
The (1) execve and (2) fexecve system calls in the FreeBSD kernel 8.4 before p11, 9.1 before p14, 9.2 before p7, and 10.0 before p4 destroys the virtual memory address space and mappings for a process before all threads have terminated, which allows local users to cause a denial of service (triple-fault and system reboot) via a crafted system call, which triggers an invalid page table pointer dereference. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3880 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-20 | Improper Input Validation |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:24634 | |||
Oval ID: | oval:org.mitre.oval:def:24634 | ||
Title: | DSA-2952-1 kfreebsd-9 - security update | ||
Description: | Several vulnerabilities have been discovered in the FreeBSD kernel that may lead to a denial of service or possibly disclosure of kernel memory. | ||
Family: | unix | Class: | patch |
Reference(s): | DSA-2952-1 CVE-2014-1453 CVE-2014-3000 CVE-2014-3880 | Version: | 3 |
Platform(s): | Debian GNU/kFreeBSD 7.0 | Product(s): | kfreebsd-9 |
Definition Synopsis: | |||
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Os | 4 |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2014-06-09 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-2952.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Source | Url |
---|
Alert History
Date | Informations |
---|---|
2024-11-28 12:41:10 |
|
2024-08-02 12:28:36 |
|
2024-08-02 01:08:35 |
|
2024-02-02 01:27:47 |
|
2024-02-01 12:08:15 |
|
2023-09-05 12:26:20 |
|
2023-09-05 01:08:09 |
|
2023-09-02 12:26:20 |
|
2023-09-02 01:08:16 |
|
2023-08-12 12:28:41 |
|
2023-08-12 01:07:46 |
|
2023-08-11 12:24:28 |
|
2023-08-11 01:07:58 |
|
2023-08-06 12:23:46 |
|
2023-08-06 01:07:44 |
|
2023-08-04 12:23:49 |
|
2023-08-04 01:07:49 |
|
2023-07-14 12:23:48 |
|
2023-07-14 01:07:47 |
|
2023-03-29 01:25:39 |
|
2023-03-28 12:08:08 |
|
2022-10-11 12:21:30 |
|
2022-10-11 01:07:56 |
|
2021-05-04 12:32:32 |
|
2021-04-22 01:39:39 |
|
2020-05-23 00:41:15 |
|
2019-03-19 12:06:26 |
|
2016-04-27 00:55:43 |
|
2014-06-21 09:26:20 |
|
2014-06-11 17:22:38 |
|
2014-06-10 21:24:49 |
|