VYPR

Vendor CVEs

FreeBSD

All CVEs

619 total · sorted by risk
  • CVE-1999-0912Sep 22, 1999
    risk 0.03cvss —epss 0.01

    FreeBSD VFS cache (vfs_cache) allows local users to cause a denial of service by opening a large number of files.

  • CVE-1999-0704Sep 16, 1999
    risk 0.03cvss —epss 0.04

    Buffer overflow in Berkeley automounter daemon (amd) logging facility provided in the Linux am-utils package and others.

  • CVE-2000-0489Sep 5, 1999
    risk 0.03cvss —epss 0.01

    FreeBSD, NetBSD, and OpenBSD allow an attacker to cause a denial of service by creating a large number of socket pairs using the socketpair function, setting a large buffer size via setsockopt, then writing large buffers.

  • CVE-1999-1518Jul 15, 1999
    risk 0.03cvss —epss 0.03

    Operating systems with shared memory implementations based on BSD 4.4 code allow a user to conduct a denial of service and bypass memory limits (e.g., as specified with rlimits) using mmap or shmget to allocate memory and cause page faults.

  • CVE-2000-0412May 1, 1999
    risk 0.03cvss —epss 0.03

    The gnapster and knapster clients for Napster do not properly restrict access only to MP3 files, which allows remote attackers to read arbitrary files from the client by specifying the full pathname for the file.

  • CVE-1999-0405Feb 18, 1999
    risk 0.03cvss —epss 0.01

    A buffer overflow in lsof allows local users to obtain root privilege.

  • CVE-1999-1402May 17, 1997
    risk 0.03cvss —epss 0.01

    The access permissions for a UNIX domain socket are ignored in Solaris 2.x and SunOS 4.x, and other BSD-based operating systems before 4.4, which could allow local users to connect to the socket and possibly disrupt or control the operations of the program using that socket.

  • CVE-1999-0040May 1, 1997
    risk 0.03cvss —epss 0.01

    Buffer overflow in Xt library of X Windowing System allows local users to execute commands with root privileges.

  • CVE-1999-0130Nov 16, 1996
    risk 0.03cvss —epss 0.01

    Local users can start Sendmail in daemon mode and gain root privileges.

  • CVE-1999-0032Oct 25, 1996
    risk 0.03cvss —epss 0.01

    Buffer overflow in lpr, as used in BSD-based systems including Linux, allows local users to execute arbitrary code as root via a long -C (classification) command line option.

  • CVE-1999-0023Jul 24, 1996
    risk 0.03cvss —epss 0.01

    Local user gains root privileges via buffer overflow in rdist, via lookup() function.

  • CVE-2014-3000May 2, 2014
    risk 0.01cvss —epss 0.13

    The TCP reassembly function in the inet module in FreeBSD 8.3 before p16, 8.4 before p9, 9.1 before p12, 9.2 before p5, and 10.0 before p2 allows remote attackers to cause a denial of service (undefined memory access and system crash) or possibly read system memory via multiple…

  • CVE-2011-2895Aug 19, 2011
    risk 0.01cvss —epss 0.08

    The LZW decompressor in (1) the BufCompressedFill function in fontfile/decompress.c in X.Org libXfont before 1.4.4 and (2) compress/compress.c in 4.3BSD, as used in zopen.c in OpenBSD before 3.8, FreeBSD, NetBSD 4.0.x and 5.0.x before 5.0.3 and 5.1.x before 5.1.1, FreeType…

  • CVE-2010-4755Mar 2, 2011
    risk 0.01cvss —epss 0.08

    The (1) remote_glob function in sftp-glob.c and the (2) process_put function in sftp.c in OpenSSH 5.8 and earlier, as used in FreeBSD 7.3 and 8.1, NetBSD 5.0.2, OpenBSD 4.7, and other products, allow remote authenticated users to cause a denial of service (CPU and memory…

  • CVE-2008-2476Oct 3, 2008
    risk 0.01cvss —epss 0.07

    The IPv6 Neighbor Discovery Protocol (NDP) implementation in (1) FreeBSD 6.3 through 7.1, (2) OpenBSD 4.2 and 4.3, (3) NetBSD, (4) Force10 FTOS before E7.7.1.1, (5) Juniper JUNOS, and (6) Wind River VxWorks 5.x through 6.4 does not validate the origin of Neighbor Discovery…

  • CVE-2008-0122Jan 16, 2008
    risk 0.01cvss —epss 0.12

    Off-by-one error in the inet_network function in libbind in ISC BIND 9.4.2 and earlier, as used in libc in FreeBSD 6.2 through 7.0-PRERELEASE, allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted input that…

  • CVE-2007-3641Jul 14, 2007
    risk 0.01cvss —epss 0.07

    archive_read_support_format_tar.c in libarchive before 2.2.4 does not properly compute the length of a certain buffer when processing a malformed pax extension header, which allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary…

  • CVE-2006-0381Jan 25, 2006
    risk 0.01cvss —epss 0.07

    A logic error in the IP fragment cache functionality in pf in FreeBSD 5.3, 5.4, and 6.0, and OpenBSD, when a 'scrub fragment crop' or 'scrub fragment drop-ovl' rule is being used, allows remote attackers to cause a denial of service (crash) via crafted packets that cause a…

  • CVE-2005-0469May 2, 2005
    risk 0.01cvss —epss 0.09

    Buffer overflow in the slc_add_reply function in various BSD-based Telnet clients, when handling LINEMODE suboptions, allows remote attackers to execute arbitrary code via a reply with a large number of Set Local Character (SLC) commands.

  • CVE-2004-0081Nov 23, 2004
    risk 0.01cvss —epss 0.07

    OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test Tool.

  • CVE-2004-0112Nov 23, 2004
    risk 0.01cvss —epss 0.10

    The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake…

  • CVE-2003-0028Mar 25, 2003
    risk 0.01cvss —epss 0.15

    Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via certain integer values in…

  • CVE-2002-1219Nov 29, 2002
    risk 0.01cvss —epss 0.12

    Buffer overflow in named in BIND 4 versions 4.9.10 and earlier, and 8 versions 8.3.3 and earlier, allows remote attackers to execute arbitrary code via a certain DNS server response containing SIG resource records (RR).

  • CVE-2002-1221Nov 29, 2002
    risk 0.01cvss —epss 0.08

    BIND 8.x through 8.3.3 allows remote attackers to cause a denial of service (crash) via SIG RR elements with invalid expiry times, which are removed from the internal BIND database and later cause a null dereference.

  • CVE-2001-0670Oct 3, 2001
    risk 0.01cvss —epss 0.07

    Buffer overflow in BSD line printer daemon (in.lpd or lpd) in various BSD-based operating systems allows remote attackers to execute arbitrary code via an incomplete print job followed by a request to display the printer queue.

  • CVE-1999-0057Nov 16, 1998
    risk 0.01cvss —epss 0.08

    Vacation program allows command execution by remote users through a sendmail command.

  • CVE-1999-0074Jul 1, 1997
    risk 0.01cvss —epss 0.08

    Listening TCP ports are sequentially allocated, allowing spoofing attacks.

  • CVE-2026-49416HigJun 27, 2026
    risk 0.00cvss 7.8epss 0.00

    The CONS_HISTORY ioctl handler did not adequately validate the requested history size. A large value caused an integer overflow in the buffer size calculation, resulting in a heap allocation smaller than expected. Subsequent initialization of the buffer wrote beyond the end of…

  • CVE-2026-49414HigJun 27, 2026
    risk 0.00cvss 7.8epss 0.00

    The ELF image activator cleared per-process ASLR preference flags for setuid binaries after the code that computes the PIE base address, rather than before. As a result, a user-requested ASLR disable was still in effect at the point where the base address was chosen. An…

  • CVE-2026-49417HigJun 27, 2026
    risk 0.00cvss 7.0epss 0.00

    Second, the audio buffer backing a mapping could be freed when the device was closed even though the mapping remained valid. The freed memory could then be reused elsewhere while still accessible through the stale mapping. The /dev/dsp device nodes are world-accessible by…

  • CVE-2026-49413HigJun 27, 2026
    risk 0.00cvss 7.1epss 0.00

    The Linuxulator determined whether a binary was set-user-ID or set-group-ID by checking the P_SUGID process flag. During execve(2), this flag is not yet set at the point where the auxiliary vector is constructed, so AT_SECURE was incorrectly set to zero for set-user-ID and…

  • CVE-2026-49412HigJun 27, 2026
    risk 0.00cvss 7.8epss 0.00

    The kernel handler for IPV6_MSFILTER dropped a serializing lock in order to copy the source-filter list from userspace, then reacquired the lock. During this window another thread could free the multicast filter structure, leaving the handler with a stale pointer to freed…

  • CVE-2026-45259MedJun 27, 2026
    risk 0.00cvss 6.5epss 0.00

    sigqueue(2) was marked as permitted in capability mode with the introduction of Capsicum in 2011, but the implementation of kern_sigqueue did not include a capability mode check restricting signal delivery to the calling process's own PID. A process in capability mode can use…

  • CVE-2026-45258HigJun 27, 2026
    risk 0.00cvss 7.8epss 0.00

    dsp_mmap_single() validated the requested mapping by checking the sum of the user-supplied offset and length against the buffer size. This addition could overflow, so that a large offset and length wrapped around and passed the check. The offset was then narrowed from 64 to 32…

  • CVE-2026-45257HigJun 26, 2026
    risk 0.00cvss 7.8epss 0.00

    The KTLS receive path decrypted each record in place, assuming that the mbufs holding received data were anonymous and safe to modify. This assumption does not hold for data placed on a socket by sendfile(2), which can reference file-backed memory directly through non-anonymous…

  • CVE-2026-45256MedJun 26, 2026
    risk 0.00cvss 5.5epss 0.00

    When used to deliver a signal to a specific thread, thr_kill2(2) called p_cansignal() to determine whether the operation was permitted but did not check the result before delivering the signal. The signal was sent even when the permission check failed. The system call returned…

  • CVE-2023-51765MedDec 24, 2023
    risk 0.00cvss 5.3epss 0.01

    sendmail through 8.17.2 allows SMTP smuggling in certain configurations. Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF protection mechanism. This occurs because sendmail supports…

  • CVE-2022-32264HigSep 6, 2022
    risk 0.00cvss 7.5epss 0.01

    sys/netinet/tcp_timer.h in FreeBSD before 7.0 contains a denial-of-service (DoS) vulnerability due to improper handling of TSopt on TCP connections. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

  • CVE-2014-8611Sep 18, 2015
    risk 0.00cvss —epss 0.00

    The __sflush function in fflush.c in stdio in libc in FreeBSD 10.1 and the kernel in Apple iOS before 9 mishandles failures of the write system call, which allows context-dependent attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow) via…

  • CVE-2015-1415Apr 10, 2015
    risk 0.00cvss —epss 0.00

    The bsdinstall installer in FreeBSD 10.x before 10.1 p9, when configuring full disk encrypted ZFS, uses world-readable permissions for the GELI keyfile (/boot/encryption.key), which allows local users to obtain sensitive key information by reading the file.

  • CVE-2015-1414Feb 27, 2015
    risk 0.00cvss —epss 0.04

    Integer overflow in FreeBSD before 8.4 p24, 9.x before 9.3 p10. 10.0 before p18, and 10.1 before p6 allows remote attackers to cause a denial of service (crash) via a crafted IGMP packet, which triggers an incorrect size calculation and allocation of insufficient memory.

  • CVE-2014-8613Feb 2, 2015
    risk 0.00cvss —epss 0.03

    The sctp module in FreeBSD 10.1 before p5, 10.0 before p17, 9.3 before p9, and 8.4 before p23 allows remote attackers to cause a denial of service (NULL pointer dereference and kernel panic) via a crafted RE_CONFIG chunk.

  • CVE-2014-0998Feb 2, 2015
    risk 0.00cvss —epss 0.01

    Integer signedness error in the vt console driver (formerly Newcons) in FreeBSD 9.3 before p10 and 10.1 before p6 allows local users to cause a denial of service (crash) and possibly gain privileges via a negative value in a VT_WAITACTIVE ioctl call, which triggers an array…

  • CVE-2014-8117Dec 17, 2014
    risk 0.00cvss —epss 0.06

    softmagic.c in file before 5.21 does not properly limit recursion, which allows remote attackers to cause a denial of service (CPU consumption or crash) via unspecified vectors.

  • CVE-2014-8116Dec 17, 2014
    risk 0.00cvss —epss 0.04

    The ELF parser (readelf.c) in file before 5.21 allows remote attackers to cause a denial of service (CPU consumption or crash) via a large number of (1) program or (2) section headers or (3) invalid capabilities.

  • CVE-2014-7250Dec 12, 2014
    risk 0.00cvss —epss 0.05

    The TCP stack in 4.3BSD Net/2, as used in FreeBSD 5.4, NetBSD possibly 2.0, and OpenBSD possibly 3.6, does not properly implement the session timer, which allows remote attackers to cause a denial of service (resource consumption) via crafted packets.

  • CVE-2014-8475Nov 18, 2014
    risk 0.00cvss —epss 0.02

    FreeBSD 9.1, 9.2, and 10.0, when compiling OpenSSH with Kerberos support, uses incorrect library ordering when linking sshd, which causes symbols to be resolved incorrectly and allows remote attackers to cause a denial of service (sshd deadlock and prevention of new connections)…

  • CVE-2014-8476Nov 13, 2014
    risk 0.00cvss —epss 0.00

    The setlogin function in FreeBSD 8.4 through 10.1-RC4 does not initialize the buffer used to store the login name, which allows local users to obtain sensitive information from kernel memory via a call to getlogin, which returns the entire buffer.

  • CVE-2014-3955Oct 27, 2014
    risk 0.00cvss —epss 0.02

    routed in FreeBSD 8.4 through 10.1-RC2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via an RIP request from a source not on a directly connected network.

  • CVE-2014-3954Oct 27, 2014
    risk 0.00cvss —epss 0.04

    Stack-based buffer overflow in rtsold in FreeBSD 9.1 through 10.1-RC2 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via crafted DNS parameters in a router advertisement message.

Page 8 of 13