CVE-2007-4303
Status: ModifiedMedium (6.2)—
Multiple race conditions in (1) certain rules and (2) argument copying during VM protection, in CerbNG for FreeBSD 4.8 allow local users to defeat system call interposition and possibly gain privileges or bypass auditing, as demonstrated by modifying command lines in log-exec.cb.
CVSS
- Version: 2.0
- Vector: AV:L/AC:H/Au:N/C:C/I:C/A:C
- Base score: 6.2
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.28%
- Percentile among all scored CVEs: 19
- Score date: 10/6/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- NVD-CWE-Other
References
Raw JSON (NVD)
Show
{
"id": "CVE-2007-4303",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.2,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:H/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "HIGH",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": true,
"exploitabilityScore": 1.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2007-08-13T21:17:00.000",
"references": [
{
"url": "http://secunia.com/advisories/26474",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/25259",
"source": "cve@mitre.org"
},
{
"url": "http://www.watson.org/~robert/2007woot/",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/26474",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/25259",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.watson.org/~robert/2007woot/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Multiple race conditions in (1) certain rules and (2) argument copying during VM protection, in CerbNG for FreeBSD 4.8 allow local users to defeat system call interposition and possibly gain privileges or bypass auditing, as demonstrated by modifying command lines in log-exec.cb."
},
{
"lang": "es",
"value": "Múltiples condiciones de carrera en (1) determinadas reglas y (2) copia de argumentos durante la protección de memoria virtual, en CerbNG para FreeBSD 4.8 permiten a usuarios locales vencer la interposición en llamadas del sistema y posiblemente obtener privilegios o evitar la monitorización, como se ha demostrado modificando líneas de comando en log-exec.cb."
}
],
"lastModified": "2026-06-16T22:43:46.450",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:freebsd:freebsd:4.8:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "441BE3A0-20F4-4972-B279-19B3DB5FA14D"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:cerb:cerbng:0.1:*:freebsd:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0181B778-3BF9-41A3-BAA0-1D0259E64AE8"
},
{
"criteria": "cpe:2.3:a:cerb:cerbng:0.2:*:freebsd:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F3C8CEE0-3973-4B6A-ABF1-630C56FB41E7"
},
{
"criteria": "cpe:2.3:a:cerb:cerbng:0.3:*:freebsd:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1D418808-847A-42D7-97B8-167790F869FD"
},
{
"criteria": "cpe:2.3:a:cerb:cerbng:0.4:*:freebsd:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "54FF562D-154E-4576-BB79-467D97CA842B"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "cve@mitre.org"
}