Vulnerability index

Browse CVEs

387 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

FreeBSD HIGH 8.8
CVE-2025-15547

By default, jailed processes cannot mount filesystems, including nullfs(4). However, the allow.mount.nullfs option enables mounting nullfs filesyste…

Mitigation only
Fix from $1,950 2026-03-09
FreeBSD HIGH 7.5
CVE-2025-14769

In some cases, the `tcp-setmss` handler may free the packet data and throw an error without halting the rule processing engine. A subsequent rule ca…

Mitigation only
Fix from $1,950 2026-03-09
FreeBSD HIGH 7.5
CVE-2025-15576

If two sibling jails are restricted to separate filesystem trees, which is to say that neither of the two jail root directories is an ancestor of the…

Mitigation only
Fix from $1,950 2026-03-09
FreeBSD HIGH 7.2
CVE-2025-14558EPSS 6%

The rtsol(8) and rtsold(8) programs do not validate the domain search list options provided in router advertisement messages; the option body is pass…

No fix yet
Fix from $1,950 2026-03-09
FreeBSD CRITICAL 10.0
CVE-2024-43102

Concurrent removals of certain anonymous shared memory mappings by using the UMTX_SHM_DESTROY sub-request of UMTX_OP_SHM can lead to decreasing the r…

Fix: 13.3+
Fix from $2,300 2024-09-05
FreeBSD HIGH 8.8
CVE-2024-42416

The ctl_report_supported_opcodes function did not sufficiently validate a field provided by userspace, allowing an arbitrary write to a limited amoun…

Fix: 13.3+
Fix from $1,950 2024-09-05
FreeBSD HIGH 8.8
CVE-2024-43110

The ctl_request_sense function could expose up to three bytes of the kernel heap to userspace. Malicious software running in a guest VM that exposes…

Fix: 13.3+
Fix from $1,950 2024-09-05
FreeBSD HIGH 8.8
CVE-2024-45063

The function ctl_write_buffer incorrectly set a flag which resulted in a kernel Use-After-Free when a command finished processing. Malicious softwar…

Fix: 13.3+
Fix from $1,950 2024-09-05
FreeBSD HIGH 8.8
CVE-2024-8178

The ctl_write_buffer and ctl_read_buffer functions allocated memory to be returned to userspace, without initializing it. Malicious software running…

Fix: 13.3+
Fix from $1,950 2024-09-05
FreeBSD HIGH 8.2
CVE-2024-32668

An insufficient boundary validation in the USB code could lead to an out-of-bounds write on the heap, with data controlled by the caller. A maliciou…

Fix: 13.3+
Fix from $1,950 2024-09-05
FreeBSD HIGH 7.5
CVE-2024-45287

A malicious value of size in a structure of packed libnv can cause an integer overflow, leading to the allocation of a smaller buffer than required f…

Fix: 13.3+
Fix from $1,950 2024-09-05
FreeBSD HIGH 8.1
CVE-2024-7589

A signal handler in sshd(8) may call a logging function that is not async-signal-safe. The signal handler is invoked when a client does not authenti…

Fix: 13.0 / 13.3+
Fix from $1,950 2024-08-12
FreeBSD HIGH 7.5
CVE-2024-6760

A logic bug in the code which disables kernel tracing for setuid programs meant that tracing was not disabled when it should have, allowing unprivile…

Fix: 13.0 / 13.3+
Fix from $1,950 2024-08-12
FreeBSD MEDIUM 5.3
CVE-2024-6759

When mounting a remote filesystem using NFS, the kernel did not sanitize remotely provided filenames for the path separator character, "/". This all…

Fix: 13.0 / 13.3+
Fix from $1,600 2024-08-12
FreeBSD CRITICAL 9.8
CVE-2024-29937

NFS in a BSD derived codebase, as used in OpenBSD through 7.4 and FreeBSD through 14.0-RELEASE, allows remote attackers to execute arbitrary code via…

Fix: after 7.4
Fix from $2,300 2024-04-11
FreeBSD HIGH 8.8
CVE-2022-23092

The implementation of lib9p's handling of RWALK messages was missing a bounds check needed when unpacking the message contents. The missing check me…

Mitigation only
Fix from $1,950 2024-02-15
FreeBSD HIGH 7.7
CVE-2022-23090

The aio_aqueue function, used by the lio_listio system call, fails to release a reference to a credential in an error case. An attacker may cause th…

Mitigation only
Fix from $1,950 2024-02-15
FreeBSD MEDIUM 6.5
CVE-2022-23093

ping reads raw IP packets from the network to process responses in the pr_pack() function. As part of processing a response ping has to reconstruct …

Mitigation only
Fix from $1,600 2024-02-15
FreeBSD MEDIUM 6.3
CVE-2024-25940

`bhyveload -h <host-path>` may be used to grant loader access to the <host-path> directory tree on the host. Affected versions of bhyveload(8) do no…

Fix: 13.2 / 14.0+
Fix from $1,600 2024-02-15
FreeBSD CRITICAL 9.8
CVE-2022-23088

The 802.11 beacon handling routine failed to validate the length of an IEEE 802.11s Mesh ID before copying it to a heap-allocated buffer. While a Fr…

Fix: 12.3 / 13.0+
Fix from $2,300 2024-02-15
FreeBSD HIGH 8.8
CVE-2022-23087

The e1000 network adapters permit a variety of modifications to an Ethernet packet when it is being transmitted. These include the insertion of IP a…

Fix: 12.3+
Fix from $1,950 2024-02-15
FreeBSD HIGH 8.2
CVE-2022-23085

A user-provided integer option was passed to nmreq_copyin() without checking if it would overflow. This insufficient bounds checking could lead to k…

Fix: 12.3+
Fix from $1,950 2024-02-15
FreeBSD HIGH 7.8
CVE-2022-23086

Handlers for *_CFG_PAGE read / write ioctls in the mpr, mps, and mpt drivers allocated a buffer of a caller-specified size, but copied to it a fixed …

Fix: 12.3+
Fix from $1,950 2024-02-15
FreeBSD HIGH 7.5
CVE-2022-23084

The total size of the user-provided nmreq to nmreq_copyin() was first computed and then trusted during the copyin. This time-of-check to time-of-use…

Fix: 12.3+
Fix from $1,950 2024-02-15
FreeBSD MEDIUM 5.3
CVE-2023-51765

sendmail through 8.17.2 allows SMTP smuggling in certain configurations. Remote attackers can use a published exploitation technique to inject e-mail…

Fix: 8.18.0.2 / 11.0+
Fix from $1,600 2023-12-24
FreeBSD HIGH 7.5
CVE-2023-6534

In versions of FreeBSD 14.0-RELEASE before 14-RELEASE-p2, FreeBSD 13.2-RELEASE before 13.2-RELEASE-p7 and FreeBSD 12.4-RELEASE before 12.4-RELEASE-p9…

Mitigation only
Fix from $1,950 2023-12-13
FreeBSD MEDIUM 6.5
CVE-2023-6660

When a program running on an affected system appends data to a file via an NFS client mount, the bug can cause the NFS client to fail to copy in the …

Mitigation only
Fix from $1,600 2023-12-13
FreeBSD CRITICAL 9.8
CVE-2023-5941

In versions of FreeBSD 12.4-RELEASE prior to 12.4-RELEASE-p7 and FreeBSD 13.2-RELEASE prior to 13.2-RELEASE-p5 the __sflush() stdio function in libc …

Fix: 12.4 / 13.2+
Fix from $2,300 2023-11-08
FreeBSD HIGH 7.5
CVE-2023-5978

In versions of FreeBSD 13-RELEASE before 13-RELEASE-p5, under certain circumstances the cap_net libcasper(3) service incorrectly validates that updat…

Fix: 13.2+
Fix from $1,950 2023-11-08
FreeBSD MEDIUM 5.5
CVE-2023-5370

On CPU 0 the check for the SMCCC workaround is called before SMCCC support has been initialized. This resulted in no speculative execution workaround…

Mitigation only
Fix from $1,600 2023-10-04