VYPR

Vendor CVEs

FreeBSD

All CVEs

619 total · sorted by risk
  • CVE-2018-17159HigDec 4, 2018
    risk 0.49cvss 7.5epss 0.04

    In FreeBSD before 11.2-STABLE(r340854) and 11.2-RELEASE-p5, the NFS server lacks a bounds check in the READDIRPLUS NFS request. Unprivileged remote users with access to the NFS server can cause a resource exhaustion by forcing the server to allocate an arbitrarily large memory…

  • CVE-2018-17158HigDec 4, 2018
    risk 0.49cvss 7.5epss 0.04

    In FreeBSD before 11.2-STABLE(r340854) and 11.2-RELEASE-p5, an integer overflow error can occur when handling the client address length field in an NFSv4 request. Unprivileged remote users with access to the NFS server can crash the system by sending a specially crafted NFSv4…

  • CVE-2017-1083HigSep 12, 2018
    risk 0.49cvss 7.5epss 0.01

    In FreeBSD before 11.2-RELEASE, a stack guard-page is available but is disabled by default. This results in the possibility a poorly written process could be cause a stack overflow.

  • CVE-2017-1082HigSep 12, 2018
    risk 0.49cvss 7.5epss 0.01

    In FreeBSD 11.x before 11.1-RELEASE and 10.x before 10.4-RELEASE, the qsort algorithm has a deterministic recursion pattern. Feeding a pathological input to the algorithm can lead to excessive stack usage and potential overflow. Applications that use qsort to handle large data…

  • CVE-2018-6923HigSep 4, 2018
    risk 0.49cvss 7.5epss 0.04

    In FreeBSD before 11.1-STABLE, 11.2-RELEASE-p2, 11.1-RELEASE-p13, ip fragment reassembly code is vulnerable to a denial of service due to excessive system resource consumption. This issue can allow a remote attacker who is able to send an arbitrary ip fragments to cause the…

  • CVE-2017-1081HigApr 10, 2018
    risk 0.49cvss 7.5epss 0.02

    In FreeBSD before 11.0-STABLE, 11.0-RELEASE-p10, 10.3-STABLE, and 10.3-RELEASE-p19, ipfilter using "keep state" or "keep frags" options can cause a kernel panic when fed specially crafted packet fragments due to incorrect memory handling.

  • CVE-2018-6919HigApr 4, 2018
    risk 0.49cvss 7.5epss 0.01

    In FreeBSD before 11.1-STABLE, 11.1-RELEASE-p9, 10.4-STABLE, 10.4-RELEASE-p8 and 10.3-RELEASE-p28, due to insufficient initialization of memory copied to userland, small amounts of kernel memory may be disclosed to userland processes. Unprivileged users may be able to access…

  • CVE-2018-6918HigApr 4, 2018
    risk 0.49cvss 7.5epss 0.04

    In FreeBSD before 11.1-STABLE, 11.1-RELEASE-p9, 10.4-STABLE, 10.4-RELEASE-p8 and 10.3-RELEASE-p28, the length field of the ipsec option header does not count the size of the option header itself, causing an infinite loop when the length is zero. This issue can allow a remote…

  • CVE-2018-6917HigApr 4, 2018
    risk 0.49cvss 7.5epss 0.02

    In FreeBSD before 11.1-STABLE, 11.1-RELEASE-p9, 10.4-STABLE, 10.4-RELEASE-p8 and 10.3-RELEASE-p28, insufficient validation of user-provided font parameters can result in an integer overflow, leading to the use of arbitrary kernel memory as glyph data. Unprivileged users may be…

  • CVE-2015-1417HigJul 25, 2017
    risk 0.49cvss 7.5epss 0.03

    The inet module in FreeBSD 10.2x before 10.2-PRERELEASE, 10.2-BETA2-p2, 10.2-RC1-p1, 10.1x before 10.1-RELEASE-p16, 9.x before 9.3-STABLE, 9.3-RELEASE-p21, and 8.x before 8.4-STABLE, 8.4-RELEASE-p35 on systems with VNET enabled and at least 16 VNET instances allows remote…

  • CVE-2016-1888HigFeb 15, 2017
    risk 0.49cvss 7.5epss 0.02

    The telnetd service in FreeBSD 9.3, 10.1, 10.2, 10.3, and 11.0 allows remote attackers to inject arguments to login and bypass authentication via vectors involving a "sequence of memory allocation failures."

  • CVE-2016-1882HigJan 29, 2016
    risk 0.49cvss 7.5epss 0.02

    FreeBSD 9.3 before p33, 10.1 before p26, and 10.2 before p9 allow remote attackers to cause a denial of service (kernel crash) via vectors related to creating a TCP connection with the TCP_MD5SIG and TCP_NOOPT socket options.

  • CVE-1999-0052HigNov 4, 1998
    risk 0.49cvss 7.5epss 0.02

    IP fragmentation denial of service in FreeBSD allows a remote attacker to cause a crash.

  • CVE-2026-58088HigAug 19, 2026
    risk 0.48cvss 7.4epss 0.00

    The ELF core dump code counted the number of dumpable VM map entries, allocated a buffer for the corresponding program headers, then iterated over the map a second time to populate them. A process sharing the address space via rfork(2) can mutate the map between the two passes,…

  • CVE-2026-49428HigAug 19, 2026
    risk 0.48cvss 8.4epss 0.00

    Certain system calls, such open(2) with the O_TRUNC flag set, and fspacectl(2), could incorrectly free memory in largepage objects. These operations are not permitted on largepage objects, but the implementation did not verify this. An unprivileged local user can abuse the bug…

  • CVE-2026-49422HigAug 19, 2026
    risk 0.48cvss 8.4epss 0.00

    The RACK setsockopt(2) handler drops the connection lock in order to copy option data from userspace, then reacquires the lock. After reacquiring, it verifies that the TCP stack had not been switched away, but did not reload its pointer to the stack's per-connection control…

  • CVE-2026-45253HigMay 21, 2026
    risk 0.48cvss 8.4epss 0.00

    ptrace(PT_SC_REMOTE) failed to properly validate parameters for the syscall(2) and __syscall(2) meta-system calls. As a result, a user with the ability to debug a process may trigger arbitrary code execution in the kernel, even if the target process has no special privileges. …

  • CVE-2026-5398HigApr 22, 2026
    risk 0.48cvss 8.4epss 0.00

    The implementation of TIOCNOTTY failed to clear a back-pointer from the structure representing the controlling terminal to the calling process' session. If the invoking process then exits, the terminal structure may end up containing a pointer to freed memory. A malicious…

  • CVE-2020-7461HigMar 26, 2021
    risk 0.48cvss 7.3epss 0.04

    In FreeBSD 12.1-STABLE before r365010, 11.4-STABLE before r365011, 12.1-RELEASE before p9, 11.4-RELEASE before p3, and 11.3-RELEASE before p13, dhclient(8) fails to handle certain malformed input related to handling of DHCP option 119 resulting a heap overflow. The heap overflow…

  • CVE-2019-15879HigMay 13, 2020
    risk 0.48cvss 7.4epss 0.01

    In FreeBSD 12.1-STABLE before r356908, 12.1-RELEASE before p5, 11.3-STABLE before r356908, and 11.3-RELEASE before p9, a race condition in the cryptodev module permitted a data structure in the kernel to be used after it was freed, allowing an unprivileged process can overwrite…

  • CVE-2019-14899HigDec 11, 2019
    risk 0.48cvss 7.4epss 0.01

    A vulnerability was discovered in Linux, FreeBSD, OpenBSD, MacOS, iOS, and Android that allows a malicious access point, or an adjacent user, to determine if a connected user is using a VPN, make positive inferences about the websites they are visiting, and determine the correct…

  • CVE-2026-58092HigAug 26, 2026
    risk 0.46cvss 8.1epss 0.00

    In FreeBSD 15.0, the kernel structure used to represent user credentials changed: previously the primary group ID was stored in the first element of the array containing the list of supplementary group IDs, whereas now the primary group ID is stored in a dedicated field. This…

  • CVE-2026-58086HigAug 19, 2026
    risk 0.46cvss 8.1epss 0.00

    As an inadvertent side effect of an unrelated code change, PRIV_KTRACE was always denied to a jailed root user. Tracing configured by a jailed root user was therefore not flagged as privileged. An unprivileged user in a jail that has permission to debug the target process can…

  • CVE-2026-49421HigAug 19, 2026
    risk 0.46cvss 7.1epss 0.00

    The kernel function that implements unlinkat(2) and funlinkat(2) validated the AT_RESOLVE_BENEATH flag but failed to pass it through to the underlying path lookup. The flag was silently dropped, so path resolution was not actually restricted. A process that uses…

  • CVE-2026-42511HigApr 30, 2026
    risk 0.46cvss 8.1epss 0.00

    The BOOTP file field is written to the lease file without escaping embedded double-quotes, allowing injection of arbitrary dhclient.conf directives. When the lease file is subsequently re-parsed by dhclient, e.g., after a system restart, an attacker-controlled field from the…

  • CVE-2023-5369HigOct 4, 2023
    risk 0.46cvss 7.1epss 0.00

    Before correction, the copy_file_range system call checked only for the CAP_READ and CAP_WRITE capabilities on the input and output file descriptors, respectively. Using an offset is logically equivalent to seeking, and the system call must additionally require the CAP_SEEK…

  • CVE-2020-7460HigAug 6, 2020
    risk 0.46cvss 7.0epss 0.01

    In FreeBSD 12.1-STABLE before r363918, 12.1-RELEASE before p8, 11.4-STABLE before r363919, 11.4-RELEASE before p2, and 11.3-RELEASE before p12, the sendmsg system call in the compat32 subsystem on 64-bit platforms has a time-of-check to time-of-use vulnerability allowing a…

  • CVE-2020-1967HigApr 21, 2020
    risk 0.46cvss 7.5epss 0.53

    Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the "signature_algorithms_cert" TLS extension. The crash occurs if an invalid or…

  • CVE-2018-6924HigSep 12, 2018
    risk 0.46cvss 7.1epss 0.00

    In FreeBSD before 11.1-STABLE, 11.2-RELEASE-p3, 11.1-RELEASE-p14, 10.4-STABLE, and 10.4-RELEASE-p12, insufficient validation in the ELF header parser could allow a malicious ELF binary to cause a kernel crash or disclose kernel memory.

  • CVE-2008-5162HigNov 26, 2008
    risk 0.46cvss 7.0epss 0.00

    The arc4random function in the kernel in FreeBSD 6.3 through 7.1 does not have a proper entropy source for a short time period immediately after boot, which makes it easier for attackers to predict the function's return values and conduct certain attacks against the GEOM…

  • CVE-2026-58094HigAug 26, 2026
    risk 0.44cvss 7.8epss 0.00

    The FIOSSHMLPGCNF ioctl(2) operation configures the page size for a largepage shared memory object. This is intended to be used immediately after creating the object, before any memory is allocated for the object. The handler checked whether a page size had already been…

  • CVE-2020-7459MedAug 6, 2020
    risk 0.44cvss 6.8epss 0.00

    In FreeBSD 12.1-STABLE before r362166, 12.1-RELEASE before p8, 11.4-STABLE before r362167, 11.4-RELEASE before p2, and 11.3-RELEASE before p12, missing length validation code common to mulitple USB network drivers allows a malicious USB device to write beyond the end of an…

  • CVE-2020-7456MedJun 9, 2020
    risk 0.44cvss 6.8epss 0.01

    In FreeBSD 12.1-STABLE before r361918, 12.1-RELEASE before p6, 11.4-STABLE before r361919, 11.3-RELEASE before p10, and 11.4-RC2 before p1, an invalid memory location may be used for HID items if the push/pop level is not restored within the processing of that HID item allowing…

  • CVE-2012-4576HigDec 2, 2019
    risk 0.44cvss 7.8epss 0.00

    FreeBSD: Input Validation Flaw allows local users to gain elevated privileges

  • CVE-2015-1418HigFeb 5, 2018
    risk 0.44cvss 7.8epss 0.06

    The do_ed_script function in pch.c in GNU patch through 2.7.6, and patch in FreeBSD 10.1 before 10.1-RELEASE-p17, 10.2 before 10.2-BETA2-p3, 10.2-RC1 before 10.2-RC1-p2, and 0.2-RC2 before 10.2-RC2-p1, allows remote attackers to execute arbitrary commands via a crafted patch…

  • CVE-2015-1416HigFeb 5, 2018
    risk 0.44cvss 7.8epss 0.05

    Larry Wall's patch; patch in FreeBSD 10.2-RC1 before 10.2-RC1-p1, 10.2 before 10.2-BETA2-p2, and 10.1 before 10.1-RELEASE-p16; Bitrig; GNU patch before 2.2.5; and possibly other patch variants allow remote attackers to execute arbitrary shell commands via a crafted patch file.

  • CVE-2017-13086MedOct 17, 2017
    risk 0.44cvss 6.8epss 0.02

    Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Tunneled Direct-Link Setup (TDLS) Peer Key (TPK) during the TDLS handshake, allowing an attacker within radio range to replay, decrypt, or spoof frames.

  • CVE-2017-13084MedOct 17, 2017
    risk 0.44cvss 6.8epss 0.02

    Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Station-To-Station-Link (STSL) Transient Key (STK) during the PeerKey handshake, allowing an attacker within radio range to replay, decrypt, or spoof frames.

  • CVE-2017-13077MedOct 17, 2017
    risk 0.44cvss 6.8epss 0.02

    Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Pairwise Transient Key (PTK) Temporal Key (TK) during the four-way handshake, allowing an attacker within radio range to replay, decrypt, or spoof frames.

  • CVE-2021-3449MedMar 25, 2021
    risk 0.43cvss 5.9epss 0.64

    An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a…

  • CVE-2016-1885MedApr 12, 2016
    risk 0.43cvss 6.2epss 0.01

    Integer signedness error in the amd64_set_ldt function in sys/amd64/amd64/sys_machdep.c in FreeBSD 9.3 before p39, 10.1 before p31, and 10.2 before p14 allows local users to cause a denial of service (kernel panic) via an i386_set_ldt system call, which triggers a heap-based…

  • CVE-2026-45255HigMay 21, 2026
    risk 0.42cvss 7.5epss 0.00

    When bsdinstall or bsdconfig are prompted to scan for nearby Wi-Fi networks, they build up a list of network names and use bsddialog(1) to prompt the user to select a network. This is implemented using a shell script, and the code which handled network names was not careful to…

  • CVE-2026-45254MedMay 21, 2026
    risk 0.42cvss 6.5epss 0.00

    In the case of the cap_net service, when a key present in the old limit was omitted from the new limit, the missing key was treated as "allow any" instead of being rejected. In certain scenarios, an application that had previously restricted a subset of network operations could…

  • CVE-2026-4247HigMar 26, 2026
    risk 0.42cvss 7.5epss 0.01

    When a challenge ACK is to be sent tcp_respond() constructs and sends the challenge ACK and consumes the mbuf that is passed in. When no challenge ACK should be sent the function returns and leaks the mbuf. If an attacker is either on path with an established TCP connection,…

  • CVE-2025-0374MedJan 30, 2025
    risk 0.42cvss 6.5epss 0.00

    When etcupdate encounters conflicts while merging files, it saves a version containing conflict markers in /var/db/etcupdate/conflicts. This version does not preserve the mode of the input file, and is world-readable. This applies to files that would normally have restricted…

  • CVE-2024-51566MedNov 12, 2024
    risk 0.42cvss 6.5epss 0.00

    The NVMe driver queue processing is vulernable to guest-induced infinite loops.

  • CVE-2024-51565MedNov 12, 2024
    risk 0.42cvss 6.5epss 0.00

    The hda driver is vulnerable to a buffer over-read from a guest-controlled value.

  • CVE-2024-51563MedNov 12, 2024
    risk 0.42cvss 6.5epss 0.00

    The virtio_vq_recordon function is subject to a time-of-check to time-of-use (TOCTOU) race condition.

  • CVE-2024-51562MedNov 12, 2024
    risk 0.42cvss 6.5epss 0.00

    The NVMe driver function nvme_opc_get_log_page is vulnerable to a buffer over-read from a guest-controlled value.

  • CVE-2022-23093MedFeb 15, 2024
    risk 0.42cvss 6.5epss 0.02

    ping reads raw IP packets from the network to process responses in the pr_pack() function. As part of processing a response ping has to reconstruct the IP header, the ICMP header and if present a "quoted packet," which represents the packet that generated an ICMP error. …

Page 4 of 13