Vulnerability index

Browse CVEs

387 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

FreeBSD MEDIUM 5.5
CVE-2018-17155

In FreeBSD before 11.2-STABLE(r338983), 11.2-RELEASE-p4, 11.1-RELEASE-p15, 10.4-STABLE(r338984), and 10.4-RELEASE-p13, due to insufficient initializa…

Fix: 11.2+
Fix from $1,600 2018-09-28
FreeBSD HIGH 7.1
CVE-2018-6924

In FreeBSD before 11.1-STABLE, 11.2-RELEASE-p3, 11.1-RELEASE-p14, 10.4-STABLE, and 10.4-RELEASE-p12, insufficient validation in the ELF header parser…

Fix: 11.1+
Fix from $1,950 2018-09-12
FreeBSD HIGH 7.8
CVE-2017-1085

In FreeBSD before 11.2-RELEASE, an application which calls setrlimit() to increase RLIMIT_STACK may turn a read-only memory region below the stack in…

Fix: 11.2+
Fix from $1,950 2018-09-12
FreeBSD HIGH 7.5
CVE-2017-1082

In FreeBSD 11.x before 11.1-RELEASE and 10.x before 10.4-RELEASE, the qsort algorithm has a deterministic recursion pattern. Feeding a pathological i…

Fix: 11.1+
Fix from $1,950 2018-09-12
FreeBSD HIGH 7.5
CVE-2017-1083

In FreeBSD before 11.2-RELEASE, a stack guard-page is available but is disabled by default. This results in the possibility a poorly written process …

Fix: 11.2+
Fix from $1,950 2018-09-12
FreeBSD HIGH 7.5
CVE-2017-1084EPSS 15%

In FreeBSD before 11.2-RELEASE, multiple issues with the implementation of the stack guard-page reduce the protections afforded by the guard-page. Th…

Fix: 11.2+
Fix from $1,950 2018-09-12
FreeBSD HIGH 7.5
CVE-2018-6923

In FreeBSD before 11.1-STABLE, 11.2-RELEASE-p2, 11.1-RELEASE-p13, ip fragment reassembly code is vulnerable to a denial of service due to excessive s…

Mitigation only
Fix from $1,950 2018-09-04
FreeBSD MEDIUM 5.3
CVE-2018-6922

One of the data structures that holds TCP segments in all versions of FreeBSD prior to 11.2-RELEASE-p1, 11.1-RELEASE-p12, and 10.4-RELEASE-p10 uses a…

Patch available
Fix from $1,600 2018-08-09
FreeBSD CRITICAL 9.8
CVE-2016-6559

Improper bounds checking of the obuf variable in the link_ntoa() function in linkaddr.c of the BSD libc library may allow an attacker to read or writ…

Mitigation only
Fix from $2,300 2018-07-13
FreeBSD MEDIUM 5.9
CVE-2016-9042

An exploitable denial of service vulnerability exists in the origin timestamp check functionality of ntpd 4.2.8p9. A specially crafted unauthenticate…

No fix yet
Fix from $1,600 2018-06-04
FreeBSD MEDIUM 5.5
CVE-2018-6920

In FreeBSD before 11.1-STABLE(r332303), 11.1-RELEASE-p10, 10.4-STABLE(r332321), and 10.4-RELEASE-p9, due to insufficient initialization of memory cop…

Fix: 10.4 / 11.1+
Fix from $1,600 2018-05-08
FreeBSD MEDIUM 5.5
CVE-2018-6921

In FreeBSD before 11.1-STABLE(r332066) and 11.1-RELEASE-p10, due to insufficient initialization of memory copied to userland in the network subsystem…

Fix: 11.1+
Fix from $1,600 2018-05-08
FreeBSD HIGH 7.5
CVE-2017-1081

In FreeBSD before 11.0-STABLE, 11.0-RELEASE-p10, 10.3-STABLE, and 10.3-RELEASE-p19, ipfilter using "keep state" or "keep frags" options can cause a k…

Fix: after 11.0
Fix from $1,950 2018-04-10
FreeBSD HIGH 7.5
CVE-2018-6917

In FreeBSD before 11.1-STABLE, 11.1-RELEASE-p9, 10.4-STABLE, 10.4-RELEASE-p8 and 10.3-RELEASE-p28, insufficient validation of user-provided font para…

Fix: 10.4 / 11.1+
Fix from $1,950 2018-04-04
FreeBSD HIGH 7.5
CVE-2018-6918

In FreeBSD before 11.1-STABLE, 11.1-RELEASE-p9, 10.4-STABLE, 10.4-RELEASE-p8 and 10.3-RELEASE-p28, the length field of the ipsec option header does n…

Fix: 10.4 / 11.1+
Fix from $1,950 2018-04-04
FreeBSD HIGH 7.5
CVE-2018-6919

In FreeBSD before 11.1-STABLE, 11.1-RELEASE-p9, 10.4-STABLE, 10.4-RELEASE-p8 and 10.3-RELEASE-p28, due to insufficient initialization of memory copie…

Fix: 10.4 / 11.1+
Fix from $1,950 2018-04-04
FreeBSD CRITICAL 9.8
CVE-2018-6916

In FreeBSD before 11.1-STABLE, 11.1-RELEASE-p7, 10.4-STABLE, 10.4-RELEASE-p7, and 10.3-RELEASE-p28, the kernel does not properly validate IPsec packe…

Fix: 11.1+
Fix from $2,300 2018-03-09
FreeBSD CRITICAL 9.8
CVE-2018-7183EPSS 10%

Buffer overflow in the decodearr function in ntpq in ntp 4.2.8p6 through 4.2.8p10 allows remote attackers to execute arbitrary code by leveraging an …

Mitigation only
Fix from $2,300 2018-03-08
FreeBSD HIGH 7.8
CVE-2015-1416

Larry Wall's patch; patch in FreeBSD 10.2-RC1 before 10.2-RC1-p1, 10.2 before 10.2-BETA2-p2, and 10.1 before 10.1-RELEASE-p16; Bitrig; GNU patch befo…

Mitigation only
Fix from $1,950 2018-02-05
FreeBSD HIGH 7.8
CVE-2015-1418

The do_ed_script function in pch.c in GNU patch through 2.7.6, and patch in FreeBSD 10.1 before 10.1-RELEASE-p17, 10.2 before 10.2-BETA2-p3, 10.2-RC1…

Mitigation only
Fix from $1,950 2018-02-05
FreeBSD MEDIUM 6.5
CVE-2015-5674

The routed daemon in FreeBSD 9.3 before 9.3-RELEASE-p22, 10.2-RC2 before 10.2-RC2-p1, 10.2-RC1 before 10.2-RC1-p2, 10.2 before 10.2-BETA2-p3, and 10.…

Mitigation only
Fix from $1,600 2018-02-05
FreeBSD HIGH 7.8
CVE-2017-1087

In FreeBSD 10.x before 10.4-STABLE, 10.4-RELEASE-p3, and 10.3-RELEASE-p24 named paths are globally scoped, meaning a process located in one jail can …

Mitigation only
Fix from $1,950 2017-11-16
FreeBSD HIGH 7.8
CVE-2015-5675

The sys_amd64 IRET Handler in the kernel in FreeBSD 9.3 and 10.1 allows local users to gain privileges or cause a denial of service (kernel panic).

No fix yet
Fix from $1,950 2017-10-10
FreeBSD HIGH 8.1
CVE-2017-15037

In FreeBSD through 11.1, the smb_strdupin function in sys/netsmb/smb_subr.c has a race condition with a resultant out-of-bounds read, because it can …

Fix: after 11.1
Fix from $1,950 2017-10-05
FreeBSD HIGH 7.5
CVE-2015-1417

The inet module in FreeBSD 10.2x before 10.2-PRERELEASE, 10.2-BETA2-p2, 10.2-RC1-p1, 10.1x before 10.1-RELEASE-p16, 9.x before 9.3-STABLE, 9.3-RELEAS…

Mitigation only
Fix from $1,950 2017-07-25
FreeBSD HIGH 8.1
CVE-2017-11103EPSS 5%

Heimdal before 7.4 allows remote attackers to impersonate services with Orpheus' Lyre attacks because it obtains service-principal names in a way tha…

Fix: 4.4.15 / 4.5.12+
Fix from $1,950 2017-07-13
FreeBSD HIGH 7.8
CVE-2016-1880

The Linux compatibility layer in the kernel in FreeBSD 9.3, 10.1, and 10.2 allows local users to read portions of kernel memory and potentially gain …

Mitigation only
Fix from $1,950 2017-02-15
FreeBSD HIGH 7.8
CVE-2016-1881

The kernel in FreeBSD 9.3, 10.1, and 10.2 allows local users to cause a denial of service (crash) or potentially gain privilege via a crafted Linux c…

Mitigation only
Fix from $1,950 2017-02-15
FreeBSD HIGH 7.8
CVE-2016-1883

The issetugid system call in the Linux compatibility layer in FreeBSD 9.3, 10.1, and 10.2 allows local users to gain privilege via unspecified vector…

Mitigation only
Fix from $1,950 2017-02-15
FreeBSD HIGH 7.8
CVE-2016-1889

Integer overflow in the bhyve hypervisor in FreeBSD 10.1, 10.2, 10.3, and 11.0 when configured with a large amount of guest memory, allows local user…

Mitigation only
Fix from $1,950 2017-02-15