VYPR

Vendor CVEs

FreeBSD

All CVEs

619 total · sorted by risk
  • CVE-2024-42416HigSep 5, 2024
    risk 0.57cvss 8.8epss 0.00

    The ctl_report_supported_opcodes function did not sufficiently validate a field provided by userspace, allowing an arbitrary write to a limited amount of kernel help memory. Malicious software running in a guest VM that exposes virtio_scsi can exploit the vulnerabilities to…

  • CVE-2022-23092HigFeb 15, 2024
    risk 0.57cvss 8.8epss 0.01

    The implementation of lib9p's handling of RWALK messages was missing a bounds check needed when unpacking the message contents. The missing check means that the receipt of a specially crafted message will cause lib9p to overwrite unrelated memory. The bug can be triggered by a…

  • CVE-2022-23087HigFeb 15, 2024
    risk 0.57cvss 8.8epss 0.00

    The e1000 network adapters permit a variety of modifications to an Ethernet packet when it is being transmitted. These include the insertion of IP and TCP checksums, insertion of an Ethernet VLAN header, and TCP segmentation offload ("TSO"). The e1000 device model uses an…

  • CVE-2023-3494HigAug 1, 2023
    risk 0.57cvss 8.8epss 0.00

    The fwctl driver implements a state machine which is executed when a bhyve guest accesses certain x86 I/O ports. The interface lets the guest copy a string into a buffer resident in the bhyve process' memory. A bug in the state machine implementation can result in a buffer…

  • CVE-2020-7468HigMar 26, 2021
    risk 0.57cvss 8.8epss 0.01

    In FreeBSD 12.2-STABLE before r365772, 11.4-STABLE before r365773, 12.1-RELEASE before p10, 11.4-RELEASE before p4 and 11.3-RELEASE before p14 a ftpd(8) bug in the implementation of the file system sandbox, combined with capabilities available to an authenticated FTP user, can…

  • CVE-2020-25582HigMar 26, 2021
    risk 0.57cvss 8.7epss 0.01

    In FreeBSD 12.2-STABLE before r369334, 11.4-STABLE before r369335, 12.2-RELEASE before p4 and 11.4-RELEASE before p8 when a process, such as jexec(8) or killall(1), calls jail_attach(2) to enter a jail, the jailed root can attach to it using ptrace(2) before the current working…

  • CVE-2026-58083HigAug 19, 2026
    risk 0.55cvss 8.4epss 0.00

    While the kernel was copying knotes during fork, a knote with a timer-based filter could fire and be enqueued on the kqueue's active list before the copy was complete. The copy routine did not account for this and could enqueue the new knote a second time, corrupting the active…

  • CVE-2024-45288HigSep 5, 2024
    risk 0.55cvss 8.4epss 0.00

    A missing null-termination character in the last element of an nvlist array string can lead to writing outside the allocated buffer.

  • CVE-2024-41928HigSep 5, 2024
    risk 0.55cvss 8.4epss 0.00

    Malicious software running in a guest VM can exploit the buffer overflow to achieve code execution on the host in the bhyve userspace process, which typically runs as root. Note that bhyve runs in a Capsicum sandbox, so malicious code is constrained by the capabilities available…

  • CVE-2017-1085HigSep 12, 2018
    risk 0.54cvss 7.8epss 0.02

    In FreeBSD before 11.2-RELEASE, an application which calls setrlimit() to increase RLIMIT_STACK may turn a read-only memory region below the stack into a read-write region. A specially crafted executable could be exploited to execute arbitrary code in the user context.

  • CVE-2016-1887HigMay 25, 2016
    risk 0.54cvss 7.8epss 0.01

    Integer signedness error in the sockargs function in sys/kern/uipc_syscalls.c in FreeBSD 10.1 before p34, 10.2 before p17, and 10.3 before p3 allows local users to cause a denial of service (memory overwrite and kernel panic) or gain privileges via a negative buflen argument,…

  • CVE-2016-1886HigMay 25, 2016
    risk 0.54cvss 7.8epss 0.01

    Integer signedness error in the genkbd_commonioctl function in sys/dev/kbd/kbd.c in FreeBSD 9.3 before p42, 10.1 before p34, 10.2 before p17, and 10.3 before p3 allows local users to obtain sensitive information from kernel memory, cause a denial of service (memory overwrite and…

  • CVE-2010-4210HigNov 22, 2010
    risk 0.54cvss 7.8epss 0.01

    The pfs_getextattr function in FreeBSD 7.x before 7.3-RELEASE and 8.x before 8.0-RC1 unlocks a mutex that was not previously locked, which allows local users to cause a denial of service (kernel panic), overwrite arbitrary memory locations, and possibly execute arbitrary code…

  • CVE-2026-42512HigApr 30, 2026
    risk 0.53cvss 8.1epss 0.01

    As dhclient is building an environment to pass to dhclient-script, it may need to resize the array of string pointers. The code which expands the array incorrectly calculates its new size when requesting memory, resulting in a heap buffer overrun. A specially crafted packet…

  • CVE-2026-35547HigApr 30, 2026
    risk 0.53cvss 8.1epss 0.00

    When processing the header of an incoming message, libnv failed to properly validate the message size. The lack of validation allows a malicious program to write outside the bounds of a heap allocation. This can trigger a crash or system panic, and it may be possible for an…

  • CVE-2024-41721HigSep 20, 2024
    risk 0.53cvss 8.1epss 0.01

    An insufficient boundary validation in the USB code could lead to an out-of-bounds read on the heap, which could potentially lead to an arbitrary write and remote code execution.

  • CVE-2024-32668HigSep 5, 2024
    risk 0.53cvss 8.2epss 0.00

    An insufficient boundary validation in the USB code could lead to an out-of-bounds write on the heap, with data controlled by the caller. A malicious, privileged software running in a guest VM can exploit the vulnerability to achieve code execution on the host in the bhyve…

  • CVE-2024-7589HigAug 12, 2024
    risk 0.53cvss 8.1epss 0.02

    A signal handler in sshd(8) may call a logging function that is not async-signal-safe. The signal handler is invoked when a client does not authenticate within the LoginGraceTime seconds (120 by default). This signal handler executes in the context of the sshd(8)'s privileged…

  • CVE-2022-23085HigFeb 15, 2024
    risk 0.53cvss 8.2epss 0.00

    A user-provided integer option was passed to nmreq_copyin() without checking if it would overflow. This insufficient bounds checking could lead to kernel memory corruption. On systems configured to include netmap in their devfs_ruleset, a privileged process running in a jail…

  • CVE-2021-29630HigAug 30, 2021
    risk 0.53cvss 8.1epss 0.02

    In FreeBSD 13.0-STABLE before n246938-0729ba2f49c9, 12.2-STABLE before r370383, 11.4-STABLE before r370381, 13.0-RELEASE before p4, 12.2-RELEASE before p10, and 11.4-RELEASE before p13, the ggatec daemon does not validate the size of a response before writing it to a fixed-sized…

  • CVE-2020-24718HigSep 25, 2020
    risk 0.53cvss 8.2epss 0.01

    bhyve, as used in FreeBSD through 12.1 and illumos (e.g., OmniOS CE through r151034 and OpenIndiana through Hipster 2020.04), does not properly restrict VMCS and VMCB read/write operations, as demonstrated by a root user in a container on an Intel system, who can gain privileges…

  • CVE-2019-9499HigApr 17, 2019
    risk 0.53cvss 8.1epss 0.02

    The implementations of EAP-PWD in wpa_supplicant EAP Peer, when built against a crypto library missing explicit validation on imported elements, do not validate the scalar and element values in EAP-pwd-Commit. An attacker may complete authentication, session key and control of…

  • CVE-2019-9498HigApr 17, 2019
    risk 0.53cvss 8.1epss 0.02

    The implementations of EAP-PWD in hostapd EAP Server, when built against a crypto library missing explicit validation on imported elements, do not validate the scalar and element values in EAP-pwd-Commit. An attacker may be able to use invalid scalar/element values to complete…

  • CVE-2017-1084HigSep 12, 2018
    risk 0.53cvss 7.5epss 0.12

    In FreeBSD before 11.2-RELEASE, multiple issues with the implementation of the stack guard-page reduce the protections afforded by the guard-page. This results in the possibility a poorly written process could be cause a stack overflow.

  • CVE-2017-13082HigOct 17, 2017
    risk 0.53cvss 8.1epss 0.04

    Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11r allows reinstallation of the Pairwise Transient Key (PTK) Temporal Key (TK) during the fast BSS transmission (FT) handshake, allowing an attacker within radio range to replay, decrypt, or spoof frames.

  • CVE-2017-15037HigOct 5, 2017
    risk 0.53cvss 8.1epss 0.01

    In FreeBSD through 11.1, the smb_strdupin function in sys/netsmb/smb_subr.c has a race condition with a resultant out-of-bounds read, because it can cause t2p->t_name strings to lack a final '\0' character.

  • CVE-2017-11103HigJul 13, 2017
    risk 0.53cvss 8.1epss 0.05

    Heimdal before 7.4 allows remote attackers to impersonate services with Orpheus' Lyre attacks because it obtains service-principal names in a way that violates the Kerberos 5 protocol specification. In _krb5_extract_ticket() the KDC-REP service name must be obtained from the…

  • CVE-2016-1879HigJan 29, 2016
    risk 0.53cvss 7.5epss 0.11

    The Stream Control Transmission Protocol (SCTP) module in FreeBSD 9.3 before p33, 10.1 before p26, and 10.2 before p9, when the kernel is configured for IPv6, allows remote attackers to cause a denial of service (assertion failure or NULL pointer dereference and kernel panic)…

  • CVE-2011-3336HigFeb 12, 2020
    risk 0.52cvss 7.5epss 0.06

    regcomp in the BSD implementation of libc is vulnerable to denial of service due to stack exhaustion.

  • CVE-2026-58097HigAug 26, 2026
    risk 0.51cvss 7.8epss 0.00

    mp_SetEnddisc() copied a user-supplied PSN endpoint value without length validation, allowing a buffer overflow via the ppp(8) command interface. A local user with access to the ppp(8) command interface can crash ppp(8) or potentially execute arbitrary code as root.

  • CVE-2026-58091HigAug 26, 2026
    risk 0.51cvss 7.8epss 0.00

    The implementation of this ioctl attempts to acquire locks on all channels in a sync group. If locking a channel would block, it releases the sync group list lock and sleeps. Upon reawakening, it is possible that the sync group structure is freed, but the implementation did…

  • CVE-2026-58090HigAug 26, 2026
    risk 0.51cvss 7.8epss 0.00

    The SOCK_STREAM receive path in the unix socket implementation failed to fully detach control messages from the socket buffer before processing them. Some error paths would free those messages, leaving freed data mbufs in the receive socket buffer. An unprivileged local user…

  • CVE-2026-58089HigAug 26, 2026
    risk 0.51cvss 7.8epss 0.00

    When a process calls execve(2) to execute a setuid or setgid image, hwpmc(4) is supposed to detach PMCs owned by unprivileged processes. An inverted check meant that this scenario was not handled properly. An unprivileged local user who has attached PMCs to a process can…

  • CVE-2026-58087HigAug 19, 2026
    risk 0.51cvss 7.8epss 0.00

    The GETALL and SETALL commands in semctl(2) recorded the number of semaphores in the target set, dropped the lock protecting the set, allocated a buffer sized for that count, and reacquired the lock. A sequence-number check was used to verify that the set had not been replaced…

  • CVE-2026-49430HigAug 19, 2026
    risk 0.51cvss 7.8epss 0.00

    The ZFS_IOC_RECV_NEW ioctl, in the heal receive path, similarly truncated a 64-bit payload size to a 32-bit integer for allocation, then used the original 64-bit size as the length for a byteswap operation. A local user with the "receive" delegated ZFS permission can trigger…

  • CVE-2026-49429HigAug 19, 2026
    risk 0.51cvss 7.8epss 0.00

    The ZFS_IOC_USERSPACE_MANY ioctl, used by zfs-userspace(8), truncated a 64-bit output buffer size to a 32-bit integer for the kernel allocation, but used the original 64-bit size as the buffer limit when writing records. A local user with the "userused" delegated ZFS permission…

  • CVE-2026-45251HigMay 21, 2026
    risk 0.51cvss 7.8epss 0.00

    A file descriptor can be closed while a thread is blocked in a poll(2) or select(2) call waiting for that descriptor. Because the blocked thread does not hold a reference to the underlying object, this closure may result in the object being freed while the thread remains…

  • CVE-2026-45250HigMay 21, 2026
    risk 0.51cvss 7.8epss 0.00

    The setcred(2) system call is only available to privileged users. However, before the privilege level of the caller is checked, the user-supplied list of supplementary groups is copied into a fixed-size kernel stack buffer without first validating its length. If the supplied…

  • CVE-2026-39457HigApr 30, 2026
    risk 0.51cvss 7.8epss 0.00

    When exchanging data over a socket, libnv uses select(2) to wait for data to arrive. However, it does not verify whether the provided socket descriptor fits in select(2)'s file descriptor set size limit of FD_SETSIZE (1024). An attacker who is able to force a libnv application…

  • CVE-2026-7270HigApr 30, 2026
    risk 0.51cvss 7.8epss 0.00

    An operator precedence bug in the kernel results in a scenario where a buffer overflow causes attacker-controlled data to overwrite adjacent execve(2) argument buffers. The bug may be exploitable by an unprivileged user to obtain superuser privileges.

  • CVE-2022-23086HigFeb 15, 2024
    risk 0.51cvss 7.8epss 0.00

    Handlers for *_CFG_PAGE read / write ioctls in the mpr, mps, and mpt drivers allocated a buffer of a caller-specified size, but copied to it a fixed size header. Other heap content would be overwritten if the specified size was too small. Users with access to the mpr, mps or…

  • CVE-2021-29631HigAug 30, 2021
    risk 0.51cvss 7.8epss 0.00

    In FreeBSD 13.0-STABLE before n246941-20f96f215562, 12.2-STABLE before r370400, 11.4-STABLE before r370399, 13.0-RELEASE before p4, 12.2-RELEASE before p10, and 11.4-RELEASE before p13, certain VirtIO-based device models in bhyve failed to handle errors when fetching I/O…

  • CVE-2021-29627HigApr 7, 2021
    risk 0.51cvss 7.8epss 0.01

    In FreeBSD 13.0-STABLE before n245050, 12.2-STABLE before r369525, 13.0-RC4 before p0, and 12.2-RELEASE before p6, listening socket accept filters implementing the accf_create callback incorrectly freed a process supplied argument string. Additional operations on the socket can…

  • CVE-2019-15878HigMay 13, 2020
    risk 0.51cvss 7.8epss 0.00

    In FreeBSD 12.1-STABLE before r352509, 11.3-STABLE before r352509, and 11.3-RELEASE before p9, an unprivileged local user can trigger a use-after-free situation due to improper checking in SCTP when an application tries to update an SCTP-AUTH shared key.

  • CVE-2020-10566HigMar 14, 2020
    risk 0.51cvss 7.8epss 0.00

    grub2-bhyve, as used in FreeBSD bhyve before revision 525916 2020-02-12, mishandles font loading by a guest through a grub2.cfg file, leading to a buffer overflow.

  • CVE-2020-10565HigMar 14, 2020
    risk 0.51cvss 7.8epss 0.00

    grub2-bhyve, as used in FreeBSD bhyve before revision 525916 2020-02-12, does not validate the address provided as part of a memrw command (read_* or write_*) by a guest through a grub2.cfg file. This allows an untrusted guest to perform arbitrary read or write operations in the…

  • CVE-2019-5607HigJul 26, 2019
    risk 0.51cvss 7.8epss 0.01

    In FreeBSD 12.0-STABLE before r350222, 12.0-RELEASE before 12.0-RELEASE-p8, 11.3-STABLE before r350223, 11.3-RELEASE before 11.3-RELEASE-p1, and 11.2-RELEASE before 11.2-RELEASE-p12, rights transmitted over a domain socket did not properly release a reference on transmission…

  • CVE-2019-5606HigJul 26, 2019
    risk 0.51cvss 7.8epss 0.01

    In FreeBSD 12.0-STABLE before r349805, 12.0-RELEASE before 12.0-RELEASE-p8, 11.3-STABLE before r349806, 11.3-RELEASE before 11.3-RELEASE-p1, and 11.2-RELEASE before 11.2-RELEASE-p12, code which handles close of a descriptor created by posix_openpt fails to undo a signal…

  • CVE-2019-5603HigJul 26, 2019
    risk 0.51cvss 7.8epss 0.01

    In FreeBSD 12.0-STABLE before r350261, 12.0-RELEASE before 12.0-RELEASE-p8, 11.3-STABLE before r350263, 11.3-RELEASE before 11.3-RELEASE-p1, and 11.2-RELEASE before 11.2-RELEASE-p12, system calls operating on file descriptors as part of mqueuefs did not properly release the…

  • CVE-2017-1087HigNov 16, 2017
    risk 0.51cvss 7.8epss 0.00

    In FreeBSD 10.x before 10.4-STABLE, 10.4-RELEASE-p3, and 10.3-RELEASE-p24 named paths are globally scoped, meaning a process located in one jail can read and modify the content of POSIX shared memory objects created by a process in another jail or the host system. As a result, a…

Page 2 of 13