CVE-2015-1417

The inet module in FreeBSD 10.2x before 10.2-PRERELEASE, 10.2-BETA2-p2, 10.2-RC1-p1, 10.1x before 10.1-RELEASE-p16, 9.x before 9.3-STABLE, 9.3-RELEASE-p21, and 8.x before 8.4-STABLE, 8.4-RELEASE-p35 on systems with VNET enabled and at least 16 VNET instances allows remote attackers to cause a denial of service (mbuf consumption) via multiple concurrent TCP connections.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 87%
VendorProductVersion
freebsdfreebsd
8.4
freebsdfreebsd
8.4:beta1
freebsdfreebsd
8.4:p11
freebsdfreebsd
8.4:p12
freebsdfreebsd
8.4:p13
freebsdfreebsd
8.4:p14
freebsdfreebsd
8.4:p15
freebsdfreebsd
8.4:p16
freebsdfreebsd
8.4:p17
freebsdfreebsd
8.4:p19
freebsdfreebsd
8.4:p2
freebsdfreebsd
8.4:p20
freebsdfreebsd
8.4:p21
freebsdfreebsd
8.4:p22
freebsdfreebsd
8.4:p23
freebsdfreebsd
8.4:p24
freebsdfreebsd
8.4:p26
freebsdfreebsd
8.4:p27
freebsdfreebsd
8.4:p3
freebsdfreebsd
8.4:p30
freebsdfreebsd
8.4:p33
freebsdfreebsd
8.4:p34
freebsdfreebsd
8.4:p4
freebsdfreebsd
8.4:p7
freebsdfreebsd
8.4:p8
freebsdfreebsd
8.4:p9
freebsdfreebsd
9.3
freebsdfreebsd
9.3:p1
freebsdfreebsd
9.3:p10
freebsdfreebsd
9.3:p12
freebsdfreebsd
9.3:p13
freebsdfreebsd
9.3:p16
freebsdfreebsd
9.3:p19
freebsdfreebsd
9.3:p2
freebsdfreebsd
9.3:p20
freebsdfreebsd
9.3:p3
freebsdfreebsd
9.3:p5
freebsdfreebsd
9.3:p6
freebsdfreebsd
9.3:p7
freebsdfreebsd
9.3:p8
freebsdfreebsd
9.3:p9
freebsdfreebsd
10.1
freebsdfreebsd
10.1:p1
freebsdfreebsd
10.1:p10
freebsdfreebsd
10.1:p12
freebsdfreebsd
10.1:p15
freebsdfreebsd
10.1:p16
freebsdfreebsd
10.1:p2
freebsdfreebsd
10.1:p3
freebsdfreebsd
10.1:p4
freebsdfreebsd
10.1:p5
freebsdfreebsd
10.1:p6
freebsdfreebsd
10.1:p7
freebsdfreebsd
10.1:p8
freebsdfreebsd
10.1:p9
freebsdfreebsd
10.2
𝑥
= Vulnerable software versions