← Back

Freebsd

freebsd

Vendor: Freebsd • 535 CVEs

CVEs (535)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
7Canonical
DebianFreebsd+4 more
12Debian Linux
Enterprise Linux DesktopEnterprise Linux Server+9 more
May 13, 2026
Oct 17, 2017
N/A· v4
6.8 MEDIUM· v3
5.4 MEDIUM· v2
Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Pairwise Transient Key (PTK) Temporal Key (TK) during the four-way handshake, allowing an attacker within radio range to replay, decrypt, or spoof frames...Show more
Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Pairwise Transient Key (PTK) Temporal Key (TK) during the four-way handshake, allowing an attacker within radio range to replay, decrypt, or spoof frames.Show less
1Freebsd
1Freebsd
May 13, 2026
Oct 10, 2017
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
The sys_amd64 IRET Handler in the kernel in FreeBSD 9.3 and 10.1 allows local users to gain privileges or cause a denial of service (kernel panic).
1Freebsd
1Freebsd
May 13, 2026
Oct 5, 2017
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
In FreeBSD through 11.1, the smb_strdupin function in sys/netsmb/smb_subr.c has a race condition with a resultant out-of-bounds read, because it can cause t2p->t_name strings to lack a final '\0' character.
1Freebsd
1Freebsd
May 13, 2026
Jul 25, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The inet module in FreeBSD 10.2x before 10.2-PRERELEASE, 10.2-BETA2-p2, 10.2-RC1-p1, 10.1x before 10.1-RELEASE-p16, 9.x before 9.3-STABLE, 9.3-RELEASE-p21, and 8.x before 8.4-STABLE, 8.4-RELEASE-p35 on systems with VNET...Show more
The inet module in FreeBSD 10.2x before 10.2-PRERELEASE, 10.2-BETA2-p2, 10.2-RC1-p1, 10.1x before 10.1-RELEASE-p16, 9.x before 9.3-STABLE, 9.3-RELEASE-p21, and 8.x before 8.4-STABLE, 8.4-RELEASE-p35 on systems with VNET enabled and at least 16 VNET instances allows remote attackers to cause a denial of service (mbuf consumption) via multiple concurrent TCP connections.Show less
5Apple
DebianFreebsd+2 more
6Debian Linux
FreebsdHeimdal+3 more
May 13, 2026
Jul 13, 2017
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
Heimdal before 7.4 allows remote attackers to impersonate services with Orpheus' Lyre attacks because it obtains service-principal names in a way that violates the Kerberos 5 protocol specification. In _krb5_extract_tick...Show more
Heimdal before 7.4 allows remote attackers to impersonate services with Orpheus' Lyre attacks because it obtains service-principal names in a way that violates the Kerberos 5 protocol specification. In _krb5_extract_ticket() the KDC-REP service name must be obtained from the encrypted version stored in 'enc_part' instead of the unencrypted version stored in 'ticket'. Use of the unencrypted version provides an opportunity for successful server impersonation and other attacks. NOTE: this CVE is only for Heimdal and other products that embed Heimdal code; it does not apply to other instances in which this part of the Kerberos 5 protocol specification is violated.Show less
1Freebsd
1Freebsd
May 13, 2026
Feb 15, 2017
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Integer overflow in the bhyve hypervisor in FreeBSD 10.1, 10.2, 10.3, and 11.0 when configured with a large amount of guest memory, allows local users to gain privilege via a crafted device descriptor.
1Freebsd
1Freebsd
May 13, 2026
Feb 15, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The telnetd service in FreeBSD 9.3, 10.1, 10.2, 10.3, and 11.0 allows remote attackers to inject arguments to login and bypass authentication via vectors involving a "sequence of memory allocation failures."
1Freebsd
1Freebsd
May 13, 2026
Feb 15, 2017
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
The issetugid system call in the Linux compatibility layer in FreeBSD 9.3, 10.1, and 10.2 allows local users to gain privilege via unspecified vectors.
1Freebsd
1Freebsd
May 13, 2026
Feb 15, 2017
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
The kernel in FreeBSD 9.3, 10.1, and 10.2 allows local users to cause a denial of service (crash) or potentially gain privilege via a crafted Linux compatibility layer setgroups system call.
1Freebsd
1Freebsd
May 13, 2026
Feb 15, 2017
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
The Linux compatibility layer in the kernel in FreeBSD 9.3, 10.1, and 10.2 allows local users to read portions of kernel memory and potentially gain privilege via unspecified vectors, related to "handling of Linux futex...Show more
The Linux compatibility layer in the kernel in FreeBSD 9.3, 10.1, and 10.2 allows local users to read portions of kernel memory and potentially gain privilege via unspecified vectors, related to "handling of Linux futex robust lists."Show less
1Freebsd
1Freebsd
May 13, 2026
Feb 7, 2017
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
bsnmpd, as used in FreeBSD 9.3, 10.1, and 10.2, uses world-readable permissions on the snmpd.config file, which allows local users to obtain the secret key for USM authentication by reading the file.
7Debian
FreebsdNetapp+4 more
17Clustered Data Ontap
Communications User Data RepositoryData Ontap+14 more
May 13, 2026
Jan 30, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The MATCH_ASSOC function in NTP before version 4.2.8p9 and 4.3.x before 4.3.92 allows remote attackers to cause an out-of-bounds reference via an addpeer request with a large hmode value.
8Canonical
DebianFedoraproject+5 more
10Clustered Data Ontap
Debian LinuxFedora+7 more
May 13, 2026
Jan 30, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
ntpd in NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to cause a denial of service (NULL pointer dereference) via a ntpdc reslist command.
5Canonical
FreebsdNetapp+2 more
7Clustered Data Ontap
FreebsdNtp+4 more
May 13, 2026
Jan 30, 2017
N/A· v4
6.5 MEDIUM· v3
5.8 MEDIUM· v2
NTP before 4.2.8p6 and 4.3.x before 4.3.90, when configured in broadcast mode, allows man-in-the-middle attackers to conduct replay attacks by sniffing the network.
5Debian
FedoraprojectFreebsd+2 more
6Debian Linux
Enterprise LinuxFedora+3 more
May 6, 2026
Aug 7, 2016
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Integer overflow in the _gd2GetHeader function in gd_gd2.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8, allows remote attackers to cause a...Show more
Integer overflow in the _gd2GetHeader function in gd_gd2.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8, allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via crafted chunk dimensions in an image.Show less
1Freebsd
1Freebsd
May 6, 2026
May 25, 2016
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Integer signedness error in the sockargs function in sys/kern/uipc_syscalls.c in FreeBSD 10.1 before p34, 10.2 before p17, and 10.3 before p3 allows local users to cause a denial of service (memory overwrite and kernel p...Show more
Integer signedness error in the sockargs function in sys/kern/uipc_syscalls.c in FreeBSD 10.1 before p34, 10.2 before p17, and 10.3 before p3 allows local users to cause a denial of service (memory overwrite and kernel panic) or gain privileges via a negative buflen argument, which triggers a heap-based buffer overflow.Show less
1Freebsd
1Freebsd
May 6, 2026
May 25, 2016
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Integer signedness error in the genkbd_commonioctl function in sys/dev/kbd/kbd.c in FreeBSD 9.3 before p42, 10.1 before p34, 10.2 before p17, and 10.3 before p3 allows local users to obtain sensitive information from ker...Show more
Integer signedness error in the genkbd_commonioctl function in sys/dev/kbd/kbd.c in FreeBSD 9.3 before p42, 10.1 before p34, 10.2 before p17, and 10.3 before p3 allows local users to obtain sensitive information from kernel memory, cause a denial of service (memory overwrite and kernel crash), or gain privileges via a negative value in the flen structure member in the arg argument in a SETFKEY ioctl call, which triggers a "two way heap and stack overflow."Show less
1Freebsd
1Freebsd
May 6, 2026
Apr 12, 2016
N/A· v4
6.2 MEDIUM· v3
4.9 MEDIUM· v2
Integer signedness error in the amd64_set_ldt function in sys/amd64/amd64/sys_machdep.c in FreeBSD 9.3 before p39, 10.1 before p31, and 10.2 before p14 allows local users to cause a denial of service (kernel panic) via a...Show more
Integer signedness error in the amd64_set_ldt function in sys/amd64/amd64/sys_machdep.c in FreeBSD 9.3 before p39, 10.1 before p31, and 10.2 before p14 allows local users to cause a denial of service (kernel panic) via an i386_set_ldt system call, which triggers a heap-based buffer overflow.Show less
1Freebsd
1Freebsd
May 6, 2026
Jan 29, 2016
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
FreeBSD 9.3 before p33, 10.1 before p26, and 10.2 before p9 allow remote attackers to cause a denial of service (kernel crash) via vectors related to creating a TCP connection with the TCP_MD5SIG and TCP_NOOPT socket opt...Show more
FreeBSD 9.3 before p33, 10.1 before p26, and 10.2 before p9 allow remote attackers to cause a denial of service (kernel crash) via vectors related to creating a TCP connection with the TCP_MD5SIG and TCP_NOOPT socket options.Show less
1Freebsd
1Freebsd
May 6, 2026
Jan 29, 2016
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
The Stream Control Transmission Protocol (SCTP) module in FreeBSD 9.3 before p33, 10.1 before p26, and 10.2 before p9, when the kernel is configured for IPv6, allows remote attackers to cause a denial of service (asserti...Show more
The Stream Control Transmission Protocol (SCTP) module in FreeBSD 9.3 before p33, 10.1 before p26, and 10.2 before p9, when the kernel is configured for IPv6, allows remote attackers to cause a denial of service (assertion failure or NULL pointer dereference and kernel panic) via a crafted ICMPv6 packet.Show less