Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Freebsd

34 known vulnerabilities

29
HIGH
5
MEDIUM

Top Products

freebsd 34
34 CVEs
7.8
CVE-2026-49416

The CONS_HISTORY ioctl handler did not adequately validate the requested history size. A large value caused an integer

7.8
CVE-2026-49414

The ELF image activator cleared per-process ASLR preference flags for setuid binaries after the code that computes the P

7.0
CVE-2026-49417

Second, the audio buffer backing a mapping could be freed when the device was closed even though the mapping remained va

7.1
CVE-2026-49413

The Linuxulator determined whether a binary was set-user-ID or set-group-ID by checking the P_SUGID process flag. Durin

7.8
CVE-2026-49412

The kernel handler for IPV6_MSFILTER dropped a serializing lock in order to copy the source-filter list from userspace,

6.5
CVE-2026-45259

sigqueue(2) was marked as permitted in capability mode with the introduction of Capsicum in 2011, but the implementation

7.8
CVE-2026-45258

dsp_mmap_single() validated the requested mapping by checking the sum of the user-supplied offset and length against the

7.8
CVE-2026-45257

The KTLS receive path decrypted each record in place, assuming that the mbufs holding received data were anonymous and s

5.5
CVE-2026-45256

When used to deliver a signal to a specific thread, thr_kill2(2) called p_cansignal() to determine whether the operation

7.5
CVE-2026-45255

When bsdinstall or bsdconfig are prompted to scan for nearby Wi-Fi networks, they build up a list of network names and u

6.5
CVE-2026-45254

In the case of the cap_net service, when a key present in the old limit was omitted from the new limit, the missing key

8.4
CVE-2026-45253

ptrace(PT_SC_REMOTE) failed to properly validate parameters for the syscall(2) and __syscall(2) meta-system calls. As a

5.5
CVE-2026-45252

When a fusefs file system implements extended attributes, the kernel may send a FUSE_LISTXATTR message to the userspace

7.8
CVE-2026-45251

A file descriptor can be closed while a thread is blocked in a poll(2) or select(2) call waiting for that descriptor. B

8.8
CVE-2026-39461

libcasper(3) communicates with helper processes via UNIX domain sockets, and uses the select(2) system call to wait for

7.8
CVE-2026-45250

The setcred(2) system call is only available to privileged users. However, before the privilege level of the caller is

8.1
CVE-2026-42512

As dhclient is building an environment to pass to dhclient-script, it may need to resize the array of string pointers.

7.8
CVE-2026-39457

When exchanging data over a socket, libnv uses select(2) to wait for data to arrive. However, it does not verify whethe

8.1
CVE-2026-35547

When processing the header of an incoming message, libnv failed to properly validate the message size. The lack of vali

7.5
CVE-2026-7164

Incorrect packet validation allowed unbounded recursion parsing SCTP chunk parameters. This can eventually result in a

7.8
CVE-2026-7270

An operator precedence bug in the kernel results in a scenario where a buffer overflow causes attacker-controlled data t

8.1
CVE-2026-42511

The BOOTP file field is written to the lease file without escaping embedded double-quotes, allowing injection of arbitra

6.2
CVE-2026-6386

In order to apply a particular protection key to an address range, the kernel must update the corresponding page table e

8.4
CVE-2026-5398

The implementation of TIOCNOTTY failed to clear a back-pointer from the structure representing the controlling terminal

7.5
CVE-2026-4748

A regression in the way hashes were calculated caused rules containing the address range syntax (x.x.x.x - y.y.y.y) that

8.8
CVE-2026-4747

Each RPCSEC_GSS data packet is validated by a routine which checks a signature in the packet. This routine copies a por

7.5
CVE-2026-4652

On a system exposing an NVMe/TCP target, a remote client can trigger a kernel panic by sending a CONNECT command for an

7.5
CVE-2026-4247

When a challenge ACK is to be sent tcp_respond() constructs and sends the challenge ACK and consumes the mbuf that is pa

7.5
CVE-2026-3038

The rtsock_msg_buffer() function serializes routing information into a buffer. As a part of this, it copies sockaddr st

7.5
CVE-2026-2261

Due to a programming error, blocklistd leaks a socket descriptor for each adverse event report it receives. Once a cert

7.5
CVE-2025-15576

If two sibling jails are restricted to separate filesystem trees, which is to say that neither of the two jail root dire

8.8
CVE-2025-15547

By default, jailed processes cannot mount filesystems, including nullfs(4). However, the allow.mount.nullfs option enab

7.5
CVE-2025-14769

In some cases, the `tcp-setmss` handler may free the packet data and throw an error without halting the rule processing

7.2
CVE-2025-14558

The rtsol(8) and rtsold(8) programs do not validate the domain search list options provided in router advertisement mess

Frequently Asked Questions

How many CVEs affect Freebsd?

Freebsd has 34 CVE records in our database, including 0 critical and 29 high severity vulnerabilities.

What are the most severe Freebsd vulnerabilities?

Freebsd has 0 critical severity (CVSS 9.0+) and 29 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.

How can I scan for Freebsd vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Freebsd products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Freebsd Vulnerabilities

CyberStrike scans your infrastructure for Freebsd vulnerabilities and provides real-time remediation guidance.

Get Started