← Back

Freebsd

freebsd

552 CVEs • 13 products

Products (13)

Click to collapse
Toggle

CVEs (552)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
4Freebsd
MicrosoftOpenbsd+1 more
7Freebsd
OpenbsdSolaris+4 more
Apr 16, 2026
Aug 12, 2002
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, allows remote attackers to execute arbitrary code by passing a large num...Show more
Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, allows remote attackers to execute arbitrary code by passing a large number of arguments to xdr_array through RPC services such as rpc.cmsd and dmispd.Show less
2Freebsd
Openbsd
2Freebsd
Openbsd
Apr 16, 2026
Jul 23, 2002
N/A· v4
N/A· v3
2.1 LOW· v2
ktrace in BSD-based operating systems allows the owner of a process with special privileges to trace the process after its privileges have been lowered, which may allow the owner to obtain sensitive information that the...Show more
ktrace in BSD-based operating systems allows the owner of a process with special privileges to trace the process after its privileges have been lowered, which may allow the owner to obtain sensitive information that the process obtained while it was running with the extra privileges.Show less
1Freebsd
1Freebsd
Apr 16, 2026
Jul 3, 2002
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Memory leak in FreeBSD 4.5 and earlier allows remote attackers to cause a denial of service (memory exhaustion) via ICMP echo packets that trigger a bug in ip_output() in which the reference count for a routing table ent...Show more
Memory leak in FreeBSD 4.5 and earlier allows remote attackers to cause a denial of service (memory exhaustion) via ICMP echo packets that trigger a bug in ip_output() in which the reference count for a routing table entry is not decremented, which prevents the entry from being removed.Show less
3Freebsd
OpenbsdSun
4Freebsd
OpenbsdSolaris+1 more
Apr 16, 2026
Jul 3, 2002
N/A· v4
N/A· v3
7.2 HIGH· v2
FreeBSD 4.5 and earlier, and possibly other BSD-based operating systems, allows local users to write to or read from restricted files by closing the file descriptors 0 (standard input), 1 (standard output), or 2 (standar...Show more
FreeBSD 4.5 and earlier, and possibly other BSD-based operating systems, allows local users to write to or read from restricted files by closing the file descriptors 0 (standard input), 1 (standard output), or 2 (standard error), which may then be reused by a called setuid process that intended to perform I/O on normal files.Show less
3Freebsd
NetbsdOpenbsd
3Freebsd
NetbsdOpenbsd
Apr 16, 2026
Jun 25, 2002
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The TCP implementation in various BSD operating systems (tcp_input.c) does not properly block connections to broadcast addresses, which could allow remote attackers to bypass intended filters via packets with a unicast l...Show more
The TCP implementation in various BSD operating systems (tcp_input.c) does not properly block connections to broadcast addresses, which could allow remote attackers to bypass intended filters via packets with a unicast link layer address and an IP broadcast address.Show less
6Debian
FreebsdGnu+3 more
6Debian Linux
FreebsdLinux+3 more
Jul 23, 2026
Mar 8, 2002
N/A· v4
N/A· v3
7.2 HIGH· v2
Buffer overflow in ncurses 5.0, and the ncurses4 compatibility package as used in Red Hat Linux, allows local users to gain privileges, related to "routines for moving the physical cursor and scrolling."
8Caldera
DebianFreebsd+5 more
9Debian Linux
FreebsdLinux+6 more
Apr 16, 2026
Feb 27, 2002
N/A· v4
N/A· v3
7.2 HIGH· v2
Heap corruption vulnerability in the "at" program allows local users to execute arbitrary code via a malformed execution time, which causes at to free the same memory twice.
1Freebsd
1Freebsd
Apr 16, 2026
Dec 10, 2001
N/A· v4
N/A· v3
6.2 MEDIUM· v2
Some AIO operations in FreeBSD 4.4 may be delayed until after a call to execve, which could allow a local user to overwrite memory of the new process and gain privileges.
2Freebsd
Sgi
2Freebsd
Irix
Apr 16, 2026
Dec 6, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
SGI IRIX 6.5 through 6.5.12f and possibly earlier versions, and FreeBSD 3.0, allows remote attackers to cause a denial of service via a malformed IGMP multicast packet with a small response delay.
4Bsd
FreebsdNetbsd+1 more
4Bsd
FreebsdNetbsd+1 more
Apr 16, 2026
Oct 3, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in BSD line printer daemon (in.lpd or lpd) in various BSD-based operating systems allows remote attackers to execute arbitrary code via an incomplete print job followed by a request to display the printer...Show more
Buffer overflow in BSD line printer daemon (in.lpd or lpd) in various BSD-based operating systems allows remote attackers to execute arbitrary code via an incomplete print job followed by a request to display the printer queue.Show less
1Freebsd
1Freebsd
Apr 16, 2026
Sep 23, 2001
N/A· v4
N/A· v3
7.2 HIGH· v2
Format string vulnerability in Hylafax on FreeBSD allows local users to execute arbitrary code via format specifiers in the -h hostname argument for (1) faxrm or (2) faxalter.
2Freebsd
Openbsd
2Freebsd
Openssh
Apr 16, 2026
Sep 20, 2001
N/A· v4
N/A· v3
2.1 LOW· v2
libutil in OpenSSH on FreeBSD 4.4 and earlier does not drop privileges before verifying the capabilities for reading the copyright and welcome files, which allows local users to bypass the capabilities checks and read ar...Show more
libutil in OpenSSH on FreeBSD 4.4 and earlier does not drop privileges before verifying the capabilities for reading the copyright and welcome files, which allows local users to bypass the capabilities checks and read arbitrary files by specifying alternate copyright or welcome files.Show less
2Freebsd
Netbsd
2Freebsd
Netbsd
Apr 16, 2026
Sep 20, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
NetBSD 1.5 and earlier and FreeBSD 4.3 and earlier allows a remote attacker to cause a denial of service by sending a large number of IP fragments to the machine, exhausting the mbuf pool.
1Freebsd
1Freebsd
Apr 16, 2026
Sep 4, 2001
N/A· v4
N/A· v3
7.2 HIGH· v2
rmuser utility in FreeBSD 4.2 and 4.3 creates a copy of the master.passwd file with world-readable permissions while updating the original file, which could allow local users to gain privileges by reading the copied file...Show more
rmuser utility in FreeBSD 4.2 and 4.3 creates a copy of the master.passwd file with world-readable permissions while updating the original file, which could allow local users to gain privileges by reading the copied file while rmuser is running, obtain the password hashes, and crack the passwords.Show less
1Freebsd
1Freebsd
Apr 16, 2026
Aug 31, 2001
N/A· v4
N/A· v3
10.0 HIGH· v2
ipfw in FreeBSD does not properly handle the use of "me" in its rules when point to point interfaces are used, which causes ipfw to allow connections from arbitrary remote hosts.
1Freebsd
1Freebsd
Apr 16, 2026
Aug 23, 2001
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
TCP Wrappers (tcp_wrappers) in FreeBSD 4.1.1 through 4.3 with the PARANOID ACL option enabled does not properly check the result of a reverse DNS lookup, which could allow remote attackers to bypass intended access restr...Show more
TCP Wrappers (tcp_wrappers) in FreeBSD 4.1.1 through 4.3 with the PARANOID ACL option enabled does not properly check the result of a reverse DNS lookup, which could allow remote attackers to bypass intended access restrictions via DNS spoofing.Show less
1Freebsd
1Freebsd
Apr 16, 2026
Aug 21, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
linprocfs on FreeBSD 4.3 and earlier does not properly restrict access to kernel memory, which allows one process with debugging rights on a privileged process to read restricted memory from that process.
3Freebsd
NetbsdOpenbsd
3Freebsd
NetbsdOpenbsd
Apr 16, 2026
Aug 17, 2001
N/A· v4
N/A· v3
6.2 MEDIUM· v2
fts routines in FreeBSD 4.3 and earlier, NetBSD before 1.5.2, and OpenBSD 2.9 and earlier can be forced to change (chdir) into a different directory than intended when the directory above the current directory is moved,...Show more
fts routines in FreeBSD 4.3 and earlier, NetBSD before 1.5.2, and OpenBSD 2.9 and earlier can be forced to change (chdir) into a different directory than intended when the directory above the current directory is moved, which could cause scripts to perform dangerous actions on the wrong directories.Show less
9Debian
FreebsdIbm+6 more
11Aix
Debian LinuxFreebsd+8 more
Apr 16, 2026
Aug 14, 2001
N/A· v4
N/A· v3
10.0 HIGH· v2
Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a set of options including AYT (Are You There), which is not properly handled by t...Show more
Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a set of options including AYT (Are You There), which is not properly handled by the telrcv function.Show less
1Freebsd
1Freebsd
Apr 16, 2026
Jul 10, 2001
N/A· v4
N/A· v3
7.2 HIGH· v2
FreeBSD 4.3 does not properly clear shared signal handlers when executing a process, which allows local users to gain privileges by calling rfork with a shared signal handler, having the child process execute a setuid pr...Show more
FreeBSD 4.3 does not properly clear shared signal handlers when executing a process, which allows local users to gain privileges by calling rfork with a shared signal handler, having the child process execute a setuid program, and sending a signal to the child.Show less