Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.8
CVE-2025-15547
By default, jailed processes cannot mount filesystems, including nullfs(4). However, the allow.mount.nullfs option enables mounting nullfs filesyste…
FreeBSD
Mitigation only
HIGH 7.5
CVE-2025-14769
In some cases, the `tcp-setmss` handler may free the packet data and throw an error without halting the rule processing engine. A subsequent rule ca…
FreeBSD
Mitigation only
HIGH 7.5
CVE-2025-15576
If two sibling jails are restricted to separate filesystem trees, which is to say that neither of the two jail root directories is an ancestor of the…
FreeBSD
Mitigation only
HIGH 7.2
CVE-2025-14558EPSS 6%
The rtsol(8) and rtsold(8) programs do not validate the domain search list options provided in router advertisement messages; the option body is pass…
FreeBSD
No fix yet
CRITICAL 10.0
CVE-2024-43102
Concurrent removals of certain anonymous shared memory mappings by using the UMTX_SHM_DESTROY sub-request of UMTX_OP_SHM can lead to decreasing the r…
FreeBSD
13.3+
HIGH 8.8
CVE-2024-42416
The ctl_report_supported_opcodes function did not sufficiently validate a field provided by userspace, allowing an arbitrary write to a limited amoun…
FreeBSD
13.3+
HIGH 8.8
CVE-2024-43110
The ctl_request_sense function could expose up to three bytes of the kernel heap to userspace.
Malicious software running in a guest VM that exposes…
FreeBSD
13.3+
HIGH 8.8
CVE-2024-45063
The function ctl_write_buffer incorrectly set a flag which resulted in a kernel Use-After-Free when a command finished processing.
Malicious softwar…
FreeBSD
13.3+
HIGH 8.8
CVE-2024-8178
The ctl_write_buffer and ctl_read_buffer functions allocated memory to be returned to userspace, without initializing it.
Malicious software running…
FreeBSD
13.3+
HIGH 8.2
CVE-2024-32668
An insufficient boundary validation in the USB code could lead to an out-of-bounds write on the heap, with data controlled by the caller.
A maliciou…
FreeBSD
13.3+
HIGH 7.5
CVE-2024-45287
A malicious value of size in a structure of packed libnv can cause an integer overflow, leading to the allocation of a smaller buffer than required f…
FreeBSD
13.3+
HIGH 8.1
CVE-2024-7589
A signal handler in sshd(8) may call a logging function that is not async-signal-safe. The signal handler is invoked when a client does not authenti…
FreeBSD
13.0 / 13.3+
HIGH 7.5
CVE-2024-6760
A logic bug in the code which disables kernel tracing for setuid programs meant that tracing was not disabled when it should have, allowing unprivile…
FreeBSD
13.0 / 13.3+
MEDIUM 5.3
CVE-2024-6759
When mounting a remote filesystem using NFS, the kernel did not sanitize remotely provided filenames for the path separator character, "/". This all…
FreeBSD
13.0 / 13.3+
CRITICAL 9.8
CVE-2024-29937
NFS in a BSD derived codebase, as used in OpenBSD through 7.4 and FreeBSD through 14.0-RELEASE, allows remote attackers to execute arbitrary code via…
FreeBSD
after 7.4
HIGH 8.8
CVE-2022-23092
The implementation of lib9p's handling of RWALK messages was missing a bounds check needed when unpacking the message contents. The missing check me…
FreeBSD
Mitigation only
HIGH 7.7
CVE-2022-23090
The aio_aqueue function, used by the lio_listio system call, fails to release a reference to a credential in an error case.
An attacker may cause th…
FreeBSD
Mitigation only
MEDIUM 6.5
CVE-2022-23093
ping reads raw IP packets from the network to process responses in the pr_pack() function. As part of processing a response ping has to reconstruct …
FreeBSD
Mitigation only
MEDIUM 6.3
CVE-2024-25940
`bhyveload -h <host-path>` may be used to grant loader access to the <host-path> directory tree on the host. Affected versions of bhyveload(8) do no…
FreeBSD
13.2 / 14.0+
CRITICAL 9.8
CVE-2022-23088
The 802.11 beacon handling routine failed to validate the length of an IEEE 802.11s Mesh ID before copying it to a heap-allocated buffer.
While a Fr…
FreeBSD
12.3 / 13.0+
HIGH 8.8
CVE-2022-23087
The e1000 network adapters permit a variety of modifications to an Ethernet packet when it is being transmitted. These include the insertion of IP a…
FreeBSD
12.3+
HIGH 8.2
CVE-2022-23085
A user-provided integer option was passed to nmreq_copyin() without checking if it would overflow. This insufficient bounds checking could lead to k…
FreeBSD
12.3+
HIGH 7.8
CVE-2022-23086
Handlers for *_CFG_PAGE read / write ioctls in the mpr, mps, and mpt drivers allocated a buffer of a caller-specified size, but copied to it a fixed …
FreeBSD
12.3+
HIGH 7.5
CVE-2022-23084
The total size of the user-provided nmreq to nmreq_copyin() was first computed and then trusted during the copyin. This time-of-check to time-of-use…
FreeBSD
12.3+
MEDIUM 5.3
CVE-2023-51765
sendmail through 8.17.2 allows SMTP smuggling in certain configurations. Remote attackers can use a published exploitation technique to inject e-mail…
FreeBSD
8.18.0.2 / 11.0+
HIGH 7.5
CVE-2023-6534
In versions of FreeBSD 14.0-RELEASE before 14-RELEASE-p2, FreeBSD 13.2-RELEASE before 13.2-RELEASE-p7 and FreeBSD 12.4-RELEASE before 12.4-RELEASE-p9…
FreeBSD
Mitigation only
MEDIUM 6.5
CVE-2023-6660
When a program running on an affected system appends data to a file via an NFS client mount, the bug can cause the NFS client to fail to copy in the …
FreeBSD
Mitigation only
CRITICAL 9.8
CVE-2023-5941
In versions of FreeBSD 12.4-RELEASE prior to 12.4-RELEASE-p7 and FreeBSD 13.2-RELEASE prior to 13.2-RELEASE-p5 the __sflush() stdio function in libc …
FreeBSD
12.4 / 13.2+
HIGH 7.5
CVE-2023-5978
In versions of FreeBSD 13-RELEASE before 13-RELEASE-p5, under certain circumstances the cap_net libcasper(3) service incorrectly validates that updat…
FreeBSD
13.2+
MEDIUM 5.5
CVE-2023-5370
On CPU 0 the check for the SMCCC workaround is called before SMCCC support has been initialized. This resulted in no speculative execution workaround…
FreeBSD
Mitigation only