VYPR

Vendor CVEs

FreeBSD

All CVEs

619 total · sorted by risk
  • CVE-2015-5675HigOct 10, 2017
    risk 0.51cvss 7.8epss 0.01

    The sys_amd64 IRET Handler in the kernel in FreeBSD 9.3 and 10.1 allows local users to gain privileges or cause a denial of service (kernel panic).

  • CVE-2016-1889HigFeb 15, 2017
    risk 0.51cvss 7.8epss 0.00

    Integer overflow in the bhyve hypervisor in FreeBSD 10.1, 10.2, 10.3, and 11.0 when configured with a large amount of guest memory, allows local users to gain privilege via a crafted device descriptor.

  • CVE-2016-1883HigFeb 15, 2017
    risk 0.51cvss 7.8epss 0.00

    The issetugid system call in the Linux compatibility layer in FreeBSD 9.3, 10.1, and 10.2 allows local users to gain privilege via unspecified vectors.

  • CVE-2016-1881HigFeb 15, 2017
    risk 0.51cvss 7.8epss 0.00

    The kernel in FreeBSD 9.3, 10.1, and 10.2 allows local users to cause a denial of service (crash) or potentially gain privilege via a crafted Linux compatibility layer setgroups system call.

  • CVE-2016-1880HigFeb 15, 2017
    risk 0.51cvss 7.8epss 0.00

    The Linux compatibility layer in the kernel in FreeBSD 9.3, 10.1, and 10.2 allows local users to read portions of kernel memory and potentially gain privilege via unspecified vectors, related to "handling of Linux futex robust lists."

  • CVE-2006-6165HigNov 29, 2006
    risk 0.51cvss 7.8epss 0.00

    ld.so in FreeBSD, NetBSD, and possibly other BSD distributions does not remove certain harmful environment variables, which allows local users to gain privileges by passing certain environment variables to loading processes. NOTE: this issue has been disputed by a third party,…

  • CVE-2005-1036HigMay 2, 2005
    risk 0.51cvss 7.8epss 0.00

    FreeBSD 5.x to 5.4 on AMD64 does not properly initialize the IO permission bitmap used to allow user access to certain hardware, which allows local users to bypass intended access restrictions to cause a denial of service, obtain sensitive information, and possibly gain…

  • CVE-1999-0022HigJul 3, 1996
    risk 0.51cvss 7.8epss 0.00

    Local user gains root privileges via buffer overflow in rdist, via expstr() function.

  • CVE-2026-49427HigAug 19, 2026
    risk 0.50cvss 8.8epss 0.00

    Pages belonging to largepage shared memory objects were not explicitly wired. When sendfile(2) transmitted such an object with the SF_NOCACHE flag, it freed the underlying pages after transmission even though existing mappings still referred to them. An unprivileged local user…

  • CVE-2026-4747HigMar 26, 2026
    risk 0.50cvss 8.8epss 0.02

    Each RPCSEC_GSS data packet is validated by a routine which checks a signature in the packet. This routine copies a portion of the packet into a stack buffer, but fails to ensure that the buffer is sufficiently large, and a malicious client can trigger a stack overflow. …

  • CVE-2025-14558HigMar 9, 2026
    risk 0.50cvss 7.2epss 0.06

    The rtsol(8) and rtsold(8) programs do not validate the domain search list options provided in router advertisement messages; the option body is passed to resolvconf(8) unmodified. resolvconf(8) is a shell script which does not validate its input. A lack of quoting meant that…

  • CVE-2022-23090HigFeb 15, 2024
    risk 0.50cvss 7.7epss 0.00

    The aio_aqueue function, used by the lio_listio system call, fails to release a reference to a credential in an error case. An attacker may cause the reference count to overflow, leading to a use after free (UAF).

  • CVE-2021-3450HigMar 25, 2021
    risk 0.50cvss 7.4epss 0.18

    The X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present in a certificate chain. It is not set by default. Starting from OpenSSL version 1.1.1h a check to disallow certificates in the chain that have explicitly encoded elliptic curve…

  • CVE-2004-0079HigNov 23, 2004
    risk 0.50cvss 7.5epss 0.10

    The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.

  • CVE-2026-58085HigAug 19, 2026
    risk 0.49cvss 7.5epss 0.00

    After dispatching a decrypt operation to OCF and receiving the result, the wg(4) driver failed to check whether the MAC verification step succeeded. The driver thus silently accepted packets with an invalid Poly1305 authentication tag. A remote attacker who can send UDP…

  • CVE-2026-7164HigApr 30, 2026
    risk 0.49cvss 7.5epss 0.00

    Incorrect packet validation allowed unbounded recursion parsing SCTP chunk parameters. This can eventually result in a stack overflow and panic. Remote attackers can craft packets which cause affected systems to panic. This affects any system where pf is configured to process…

  • CVE-2026-4748HigApr 1, 2026
    risk 0.49cvss 7.5epss 0.00

    A regression in the way hashes were calculated caused rules containing the address range syntax (x.x.x.x - y.y.y.y) that only differ in the address range(s) involved to be silently dropped as duplicates. Only the first of such rules is actually loaded into pf. Ranges expressed…

  • CVE-2026-4652HigMar 26, 2026
    risk 0.49cvss 7.5epss 0.00

    On a system exposing an NVMe/TCP target, a remote client can trigger a kernel panic by sending a CONNECT command for an I/O queue with a bogus or stale CNTLID. An attacker with network access to the NVMe/TCP target can trigger an unauthenticated Denial of Service condition on…

  • CVE-2026-3038HigMar 9, 2026
    risk 0.49cvss 7.5epss 0.01

    The rtsock_msg_buffer() function serializes routing information into a buffer. As a part of this, it copies sockaddr structures into a sockaddr_storage structure on the stack. It assumes that the source sockaddr length field had already been validated, but this is not…

  • CVE-2026-2261HigMar 9, 2026
    risk 0.49cvss 7.5epss 0.00

    Due to a programming error, blocklistd leaks a socket descriptor for each adverse event report it receives. Once a certain number of leaked sockets is reached, blocklistd becomes unable to run the helper script: a child process is forked, but this child dereferences a null…

  • CVE-2025-15576HigMar 9, 2026
    risk 0.49cvss 7.5epss 0.00

    If two sibling jails are restricted to separate filesystem trees, which is to say that neither of the two jail root directories is an ancestor of the other, jailed processes may nonetheless be able to access a shared directory via a nullfs mount, if the administrator has…

  • CVE-2025-14769HigMar 9, 2026
    risk 0.49cvss 7.5epss 0.01

    In some cases, the `tcp-setmss` handler may free the packet data and throw an error without halting the rule processing engine. A subsequent rule can then allow the traffic after the packet data is gone, resulting in a NULL pointer dereference. Maliciously crafted packets sent…

  • CVE-2024-51564HigNov 12, 2024
    risk 0.49cvss 7.5epss 0.00

    A guest can trigger an infinite loop in the hda audio driver.

  • CVE-2024-45289HigNov 12, 2024
    risk 0.49cvss 7.5epss 0.00

    The fetch(3) library uses environment variables for passing certain information, including the revocation file pathname. The environment variable name used by fetch(1) to pass the filename to the library was incorrect, in effect ignoring the option. Fetch would still connect…

  • CVE-2024-45287HigSep 5, 2024
    risk 0.49cvss 7.5epss 0.01

    A malicious value of size in a structure of packed libnv can cause an integer overflow, leading to the allocation of a smaller buffer than required for the parsed data.

  • CVE-2024-6760HigAug 12, 2024
    risk 0.49cvss 7.5epss 0.01

    A logic bug in the code which disables kernel tracing for setuid programs meant that tracing was not disabled when it should have, allowing unprivileged users to trace and inspect the behavior of setuid programs. The bug may be used by an unprivileged user to read the contents…

  • CVE-2022-23084HigFeb 15, 2024
    risk 0.49cvss 7.5epss 0.00

    The total size of the user-provided nmreq to nmreq_copyin() was first computed and then trusted during the copyin. This time-of-check to time-of-use bug could lead to kernel memory corruption. On systems configured to include netmap in their devfs_ruleset, a privileged process…

  • CVE-2023-6534HigDec 13, 2023
    risk 0.49cvss 7.5epss 0.01

    In versions of FreeBSD 14.0-RELEASE before 14-RELEASE-p2, FreeBSD 13.2-RELEASE before 13.2-RELEASE-p7 and FreeBSD 12.4-RELEASE before 12.4-RELEASE-p9, the pf(4) packet filter incorrectly validates TCP sequence numbers.  This could allow a malicious actor to execute a…

  • CVE-2023-5978HigNov 8, 2023
    risk 0.49cvss 7.5epss 0.01

    In versions of FreeBSD 13-RELEASE before 13-RELEASE-p5, under certain circumstances the cap_net libcasper(3) service incorrectly validates that updated constraints are strictly subsets of the active constraints.  When only a list of resolvable domain names was specified…

  • CVE-2023-4809HigSep 6, 2023
    risk 0.49cvss 7.5epss 0.01

    In pf packet processing with a 'scrub fragment reassemble' rule, a packet containing multiple IPv6 fragment headers would be reassembled, and then immediately processed. That is, a packet with multiple fragment extension headers would not be recognized as the correct ultimate…

  • CVE-2023-3107HigAug 1, 2023
    risk 0.49cvss 7.5epss 0.01

    A set of carefully crafted ipv6 packets can trigger an integer overflow in the calculation of a fragment reassembled packet's payload length field. This allows an attacker to trigger a kernel panic, resulting in a denial of service.

  • CVE-2022-47522HigApr 15, 2023
    risk 0.49cvss 7.5epss 0.01

    The IEEE 802.11 specifications through 802.11ax allow physically proximate attackers to intercept (possibly cleartext) target-destined frames by spoofing a target's MAC address, sending Power Save frames to the access point, and then sending other frames to the access point…

  • CVE-2021-29632HigJan 18, 2022
    risk 0.49cvss 7.5epss 0.01

    In FreeBSD 13.0-STABLE before n247428-9352de39c3dc, 12.2-STABLE before r370674, 13.0-RELEASE before p6, and 12.2-RELEASE before p12, certain conditions involving use of the highlight buffer while text is scrolling on the console, console data may overwrite data structures…

  • CVE-2010-4816HigJun 22, 2021
    risk 0.49cvss 7.5epss 0.02

    It was found in FreeBSD 8.0, 6.3 and 4.9, and OpenBSD 4.6 that a null pointer dereference in ftpd/popen.c may lead to remote denial of service of the ftpd service.

  • CVE-2020-7469HigJun 4, 2021
    risk 0.49cvss 7.5epss 0.01

    In FreeBSD 12.2-STABLE before r367402, 11.4-STABLE before r368202, 12.2-RELEASE before p1, 12.1-RELEASE before p11 and 11.4-RELEASE before p5 the handler for a routing option caches a pointer into the packet buffer holding the ICMPv6 message. However, when processing subsequent…

  • CVE-2021-29629HigMay 28, 2021
    risk 0.49cvss 7.5epss 0.01

    In FreeBSD 13.0-STABLE before n245765-bec0d2c9c841, 12.2-STABLE before r369859, 11.4-STABLE before r369866, 13.0-RELEASE before p1, 12.2-RELEASE before p7, and 11.4-RELEASE before p10, missing message validation in libradius(3) could allow malicious clients or servers to trigger…

  • CVE-2021-29628HigMay 28, 2021
    risk 0.49cvss 7.5epss 0.01

    In FreeBSD 13.0-STABLE before n245764-876ffe28796c, 12.2-STABLE before r369857, 13.0-RELEASE before p1, and 12.2-RELEASE before p7, a system call triggering a fault could cause SMAP protections to be disabled for the duration of the system call. This weakness could be combined…

  • CVE-2020-25584HigApr 7, 2021
    risk 0.49cvss 7.5epss 0.00

    In FreeBSD 13.0-STABLE before n245118, 12.2-STABLE before r369552, 11.4-STABLE before r369560, 13.0-RC5 before p1, 12.2-RELEASE before p6, and 11.4-RELEASE before p9, a superuser inside a FreeBSD jail configured with the non-default allow.mount permission could cause a race…

  • CVE-2020-7467HigMar 26, 2021
    risk 0.49cvss 7.6epss 0.00

    In FreeBSD 12.2-STABLE before r365767, 11.4-STABLE before r365769, 12.1-RELEASE before p10, 11.4-RELEASE before p4 and 11.3-RELEASE before p14 a number of AMD virtualization instructions operate on host physical addresses, are not subject to nested page table translation, and…

  • CVE-2020-25581HigMar 26, 2021
    risk 0.49cvss 7.5epss 0.01

    In FreeBSD 12.2-STABLE before r369312, 11.4-STABLE before r369313, 12.2-RELEASE before p4 and 11.4-RELEASE before p8 due to a race condition in the jail_remove(2) implementation, it may fail to kill some of the processes.

  • CVE-2012-5365HigFeb 20, 2020
    risk 0.49cvss 7.5epss 0.03

    The IPv6 implementation in FreeBSD and NetBSD (unknown versions, year 2012 and earlier) allows remote attackers to cause a denial of service via a flood of ICMPv6 Router Advertisement packets containing multiple Routing entries.

  • CVE-2012-5363HigFeb 20, 2020
    risk 0.49cvss 7.5epss 0.03

    The IPv6 implementation in FreeBSD and NetBSD (unknown versions, year 2012 and earlier) allows remote attackers to cause a denial of service via a flood of ICMPv6 Neighbor Solicitation messages, a different vulnerability than CVE-2011-2393.

  • CVE-2011-2480HigNov 27, 2019
    risk 0.49cvss 7.5epss 0.02

    Information Disclosure vulnerability in the 802.11 stack, as used in FreeBSD before 8.2 and NetBSD when using certain non-x86 architectures. A signedness error in the IEEE80211_IOC_CHANINFO ioctl allows a local unprivileged user to cause the kernel to copy large amounts of…

  • CVE-2012-2979HigNov 1, 2019
    risk 0.49cvss 7.5epss 0.02

    FreeBSD NSD before 3.2.13 allows remote attackers to crash a NSD child server process (SIGSEGV) and cause a denial of service in the NSD server.

  • CVE-2019-5612HigAug 30, 2019
    risk 0.49cvss 7.5epss 0.01

    In FreeBSD 12.0-STABLE before r351264, 12.0-RELEASE before 12.0-RELEASE-p10, 11.3-STABLE before r351265, 11.3-RELEASE before 11.3-RELEASE-p3, and 11.2-RELEASE before 11.2-RELEASE-p14, the kernel driver for /dev/midistat implements a read handler that is not thread-safe. A…

  • CVE-2019-5611HigAug 30, 2019
    risk 0.49cvss 7.5epss 0.04

    In FreeBSD 12.0-STABLE before r350828, 12.0-RELEASE before 12.0-RELEASE-p10, 11.3-STABLE before r350829, 11.3-RELEASE before 11.3-RELEASE-p3, and 11.2-RELEASE before 11.2-RELEASE-p14, a missing check in the function to arrange data in a chain of mbufs could cause data returned…

  • CVE-2019-5610HigAug 30, 2019
    risk 0.49cvss 7.5epss 0.04

    In FreeBSD 12.0-STABLE before r350637, 12.0-RELEASE before 12.0-RELEASE-p9, 11.3-STABLE before r350638, 11.3-RELEASE before 11.3-RELEASE-p2, and 11.2-RELEASE before 11.2-RELEASE-p13, the bsnmp library is not properly validating the submitted length from a type-length-value…

  • CVE-2019-5609HigAug 30, 2019
    risk 0.49cvss 7.5epss 0.01

    In FreeBSD 12.0-STABLE before r350619, 12.0-RELEASE before 12.0-RELEASE-p9, 11.3-STABLE before r350619, 11.3-RELEASE before 11.3-RELEASE-p2, and 11.2-RELEASE before 11.2-RELEASE-p13, the bhyve e1000 device emulation used a guest-provided value to determine the size of the…

  • CVE-2019-5599HigJul 2, 2019
    risk 0.49cvss 7.5epss 0.05

    In FreeBSD 12.0-STABLE before r349197 and 12.0-RELEASE before 12.0-RELEASE-p6, a bug in the non-default RACK TCP stack can allow an attacker to cause several linked lists to grow unbounded and cause an expensive list traversal on every packet being processed, leading to resource…

  • CVE-2019-5598HigMay 15, 2019
    risk 0.49cvss 7.5epss 0.03

    In FreeBSD 11.3-PRERELEASE before r345378, 12.0-STABLE before r345377, 11.2-RELEASE before 11.2-RELEASE-p10, and 12.0-RELEASE before 12.0-RELEASE-p4, a bug in pf does not check if the outer ICMP or ICMP6 packet has the same destination IP as the source IP of the inner protocol…

Page 3 of 13