Freebsd
34 known vulnerabilities
Top Products
The CONS_HISTORY ioctl handler did not adequately validate the requested history size. A large value caused an integer
The ELF image activator cleared per-process ASLR preference flags for setuid binaries after the code that computes the P
Second, the audio buffer backing a mapping could be freed when the device was closed even though the mapping remained va
The Linuxulator determined whether a binary was set-user-ID or set-group-ID by checking the P_SUGID process flag. Durin
The kernel handler for IPV6_MSFILTER dropped a serializing lock in order to copy the source-filter list from userspace,
sigqueue(2) was marked as permitted in capability mode with the introduction of Capsicum in 2011, but the implementation
dsp_mmap_single() validated the requested mapping by checking the sum of the user-supplied offset and length against the
The KTLS receive path decrypted each record in place, assuming that the mbufs holding received data were anonymous and s
When used to deliver a signal to a specific thread, thr_kill2(2) called p_cansignal() to determine whether the operation
When bsdinstall or bsdconfig are prompted to scan for nearby Wi-Fi networks, they build up a list of network names and u
In the case of the cap_net service, when a key present in the old limit was omitted from the new limit, the missing key
ptrace(PT_SC_REMOTE) failed to properly validate parameters for the syscall(2) and __syscall(2) meta-system calls. As a
When a fusefs file system implements extended attributes, the kernel may send a FUSE_LISTXATTR message to the userspace
A file descriptor can be closed while a thread is blocked in a poll(2) or select(2) call waiting for that descriptor. B
libcasper(3) communicates with helper processes via UNIX domain sockets, and uses the select(2) system call to wait for
The setcred(2) system call is only available to privileged users. However, before the privilege level of the caller is
As dhclient is building an environment to pass to dhclient-script, it may need to resize the array of string pointers.
When exchanging data over a socket, libnv uses select(2) to wait for data to arrive. However, it does not verify whethe
When processing the header of an incoming message, libnv failed to properly validate the message size. The lack of vali
Incorrect packet validation allowed unbounded recursion parsing SCTP chunk parameters. This can eventually result in a
An operator precedence bug in the kernel results in a scenario where a buffer overflow causes attacker-controlled data t
The BOOTP file field is written to the lease file without escaping embedded double-quotes, allowing injection of arbitra
In order to apply a particular protection key to an address range, the kernel must update the corresponding page table e
The implementation of TIOCNOTTY failed to clear a back-pointer from the structure representing the controlling terminal
A regression in the way hashes were calculated caused rules containing the address range syntax (x.x.x.x - y.y.y.y) that
Each RPCSEC_GSS data packet is validated by a routine which checks a signature in the packet. This routine copies a por
On a system exposing an NVMe/TCP target, a remote client can trigger a kernel panic by sending a CONNECT command for an
When a challenge ACK is to be sent tcp_respond() constructs and sends the challenge ACK and consumes the mbuf that is pa
The rtsock_msg_buffer() function serializes routing information into a buffer. As a part of this, it copies sockaddr st
Due to a programming error, blocklistd leaks a socket descriptor for each adverse event report it receives. Once a cert
If two sibling jails are restricted to separate filesystem trees, which is to say that neither of the two jail root dire
By default, jailed processes cannot mount filesystems, including nullfs(4). However, the allow.mount.nullfs option enab
In some cases, the `tcp-setmss` handler may free the packet data and throw an error without halting the rule processing
The rtsol(8) and rtsold(8) programs do not validate the domain search list options provided in router advertisement mess
Frequently Asked Questions
How many CVEs affect Freebsd?
Freebsd has 34 CVE records in our database, including 0 critical and 29 high severity vulnerabilities.
What are the most severe Freebsd vulnerabilities?
Freebsd has 0 critical severity (CVSS 9.0+) and 29 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Freebsd vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Freebsd products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Freebsd Vulnerabilities
CyberStrike scans your infrastructure for Freebsd vulnerabilities and provides real-time remediation guidance.
Get Started