VYPR

FreeBSD

by FreeBSD

Source repositories

CVEs (556)

  • CVE-2026-4652HigMar 26, 2026
    risk 0.49cvss 7.5epss 0.00

    On a system exposing an NVMe/TCP target, a remote client can trigger a kernel panic by sending a CONNECT command for an I/O queue with a bogus or stale CNTLID. An attacker with network access to the NVMe/TCP target can trigger an unauthenticated Denial of Service condition on…

  • CVE-2026-3038HigMar 9, 2026
    risk 0.49cvss 7.5epss 0.00

    The rtsock_msg_buffer() function serializes routing information into a buffer. As a part of this, it copies sockaddr structures into a sockaddr_storage structure on the stack. It assumes that the source sockaddr length field had already been validated, but this is not…

  • CVE-2026-2261HigMar 9, 2026
    risk 0.49cvss 7.5epss 0.00

    Due to a programming error, blocklistd leaks a socket descriptor for each adverse event report it receives. Once a certain number of leaked sockets is reached, blocklistd becomes unable to run the helper script: a child process is forked, but this child dereferences a null…

  • CVE-2025-15576HigMar 9, 2026
    risk 0.49cvss 7.5epss 0.00

    If two sibling jails are restricted to separate filesystem trees, which is to say that neither of the two jail root directories is an ancestor of the other, jailed processes may nonetheless be able to access a shared directory via a nullfs mount, if the administrator has…

  • CVE-2025-14769HigMar 9, 2026
    risk 0.49cvss 7.5epss 0.01

    In some cases, the `tcp-setmss` handler may free the packet data and throw an error without halting the rule processing engine. A subsequent rule can then allow the traffic after the packet data is gone, resulting in a NULL pointer dereference. Maliciously crafted packets sent…

  • CVE-2024-45289HigNov 12, 2024
    risk 0.49cvss 7.5epss 0.00

    The fetch(3) library uses environment variables for passing certain information, including the revocation file pathname. The environment variable name used by fetch(1) to pass the filename to the library was incorrect, in effect ignoring the option. Fetch would still connect…

  • CVE-2024-45287HigSep 5, 2024
    risk 0.49cvss 7.5epss 0.01

    A malicious value of size in a structure of packed libnv can cause an integer overflow, leading to the allocation of a smaller buffer than required for the parsed data.

  • CVE-2024-6760HigAug 12, 2024
    risk 0.49cvss 7.5epss 0.01

    A logic bug in the code which disables kernel tracing for setuid programs meant that tracing was not disabled when it should have, allowing unprivileged users to trace and inspect the behavior of setuid programs. The bug may be used by an unprivileged user to read the contents…

  • CVE-2022-23084HigFeb 15, 2024
    risk 0.49cvss 7.5epss 0.00

    The total size of the user-provided nmreq to nmreq_copyin() was first computed and then trusted during the copyin. This time-of-check to time-of-use bug could lead to kernel memory corruption. On systems configured to include netmap in their devfs_ruleset, a privileged process…

  • CVE-2023-6534HigDec 13, 2023
    risk 0.49cvss 7.5epss 0.01

    In versions of FreeBSD 14.0-RELEASE before 14-RELEASE-p2, FreeBSD 13.2-RELEASE before 13.2-RELEASE-p7 and FreeBSD 12.4-RELEASE before 12.4-RELEASE-p9, the pf(4) packet filter incorrectly validates TCP sequence numbers.  This could allow a malicious actor to execute a…

  • CVE-2023-5978HigNov 8, 2023
    risk 0.49cvss 7.5epss 0.01

    In versions of FreeBSD 13-RELEASE before 13-RELEASE-p5, under certain circumstances the cap_net libcasper(3) service incorrectly validates that updated constraints are strictly subsets of the active constraints.  When only a list of resolvable domain names was specified…

  • CVE-2023-4809HigSep 6, 2023
    risk 0.49cvss 7.5epss 0.01

    In pf packet processing with a 'scrub fragment reassemble' rule, a packet containing multiple IPv6 fragment headers would be reassembled, and then immediately processed. That is, a packet with multiple fragment extension headers would not be recognized as the correct ultimate…

  • CVE-2023-3107HigAug 1, 2023
    risk 0.49cvss 7.5epss 0.01

    A set of carefully crafted ipv6 packets can trigger an integer overflow in the calculation of a fragment reassembled packet's payload length field. This allows an attacker to trigger a kernel panic, resulting in a denial of service.

  • CVE-2022-47522HigApr 15, 2023
    risk 0.49cvss 7.5epss 0.01

    The IEEE 802.11 specifications through 802.11ax allow physically proximate attackers to intercept (possibly cleartext) target-destined frames by spoofing a target's MAC address, sending Power Save frames to the access point, and then sending other frames to the access point…

  • CVE-2021-29632HigJan 18, 2022
    risk 0.49cvss 7.5epss 0.01

    In FreeBSD 13.0-STABLE before n247428-9352de39c3dc, 12.2-STABLE before r370674, 13.0-RELEASE before p6, and 12.2-RELEASE before p12, certain conditions involving use of the highlight buffer while text is scrolling on the console, console data may overwrite data structures…

  • CVE-2010-4816HigJun 22, 2021
    risk 0.49cvss 7.5epss 0.02

    It was found in FreeBSD 8.0, 6.3 and 4.9, and OpenBSD 4.6 that a null pointer dereference in ftpd/popen.c may lead to remote denial of service of the ftpd service.

  • CVE-2020-7469HigJun 4, 2021
    risk 0.49cvss 7.5epss 0.01

    In FreeBSD 12.2-STABLE before r367402, 11.4-STABLE before r368202, 12.2-RELEASE before p1, 12.1-RELEASE before p11 and 11.4-RELEASE before p5 the handler for a routing option caches a pointer into the packet buffer holding the ICMPv6 message. However, when processing subsequent…

  • CVE-2021-29629HigMay 28, 2021
    risk 0.49cvss 7.5epss 0.01

    In FreeBSD 13.0-STABLE before n245765-bec0d2c9c841, 12.2-STABLE before r369859, 11.4-STABLE before r369866, 13.0-RELEASE before p1, 12.2-RELEASE before p7, and 11.4-RELEASE before p10, missing message validation in libradius(3) could allow malicious clients or servers to trigger…

  • CVE-2021-29628HigMay 28, 2021
    risk 0.49cvss 7.5epss 0.01

    In FreeBSD 13.0-STABLE before n245764-876ffe28796c, 12.2-STABLE before r369857, 13.0-RELEASE before p1, and 12.2-RELEASE before p7, a system call triggering a fault could cause SMAP protections to be disabled for the duration of the system call. This weakness could be combined…

  • CVE-2020-25584HigApr 7, 2021
    risk 0.49cvss 7.5epss 0.00

    In FreeBSD 13.0-STABLE before n245118, 12.2-STABLE before r369552, 11.4-STABLE before r369560, 13.0-RC5 before p1, 12.2-RELEASE before p6, and 11.4-RELEASE before p9, a superuser inside a FreeBSD jail configured with the non-default allow.mount permission could cause a race…

Page 6 of 28