Vulnerability index

Browse CVEs

387 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2025-15547 By default, jailed processes cannot mount filesystems, including nullfs(4). However, the allow.mount.nullfs option enables mounting nullfs filesyste… FreeBSD Mitigation only Fix from $1,9502026-03-09 HIGH 7.5 CVE-2025-14769 In some cases, the `tcp-setmss` handler may free the packet data and throw an error without halting the rule processing engine. A subsequent rule ca… FreeBSD Mitigation only Fix from $1,9502026-03-09 HIGH 7.5 CVE-2025-15576 If two sibling jails are restricted to separate filesystem trees, which is to say that neither of the two jail root directories is an ancestor of the… FreeBSD Mitigation only Fix from $1,9502026-03-09 HIGH 7.2 CVE-2025-14558EPSS 6% The rtsol(8) and rtsold(8) programs do not validate the domain search list options provided in router advertisement messages; the option body is pass… FreeBSD No fix yet Fix from $1,9502026-03-09 CRITICAL 10.0 CVE-2024-43102 Concurrent removals of certain anonymous shared memory mappings by using the UMTX_SHM_DESTROY sub-request of UMTX_OP_SHM can lead to decreasing the r… FreeBSD 13.3+ Fix from $2,3002024-09-05 HIGH 8.8 CVE-2024-42416 The ctl_report_supported_opcodes function did not sufficiently validate a field provided by userspace, allowing an arbitrary write to a limited amoun… FreeBSD 13.3+ Fix from $1,9502024-09-05 HIGH 8.8 CVE-2024-43110 The ctl_request_sense function could expose up to three bytes of the kernel heap to userspace. Malicious software running in a guest VM that exposes… FreeBSD 13.3+ Fix from $1,9502024-09-05 HIGH 8.8 CVE-2024-45063 The function ctl_write_buffer incorrectly set a flag which resulted in a kernel Use-After-Free when a command finished processing. Malicious softwar… FreeBSD 13.3+ Fix from $1,9502024-09-05 HIGH 8.8 CVE-2024-8178 The ctl_write_buffer and ctl_read_buffer functions allocated memory to be returned to userspace, without initializing it. Malicious software running… FreeBSD 13.3+ Fix from $1,9502024-09-05 HIGH 8.2 CVE-2024-32668 An insufficient boundary validation in the USB code could lead to an out-of-bounds write on the heap, with data controlled by the caller. A maliciou… FreeBSD 13.3+ Fix from $1,9502024-09-05 HIGH 7.5 CVE-2024-45287 A malicious value of size in a structure of packed libnv can cause an integer overflow, leading to the allocation of a smaller buffer than required f… FreeBSD 13.3+ Fix from $1,9502024-09-05 HIGH 8.1 CVE-2024-7589 A signal handler in sshd(8) may call a logging function that is not async-signal-safe. The signal handler is invoked when a client does not authenti… FreeBSD 13.0 / 13.3+ Fix from $1,9502024-08-12 HIGH 7.5 CVE-2024-6760 A logic bug in the code which disables kernel tracing for setuid programs meant that tracing was not disabled when it should have, allowing unprivile… FreeBSD 13.0 / 13.3+ Fix from $1,9502024-08-12 MEDIUM 5.3 CVE-2024-6759 When mounting a remote filesystem using NFS, the kernel did not sanitize remotely provided filenames for the path separator character, "/". This all… FreeBSD 13.0 / 13.3+ Fix from $1,6002024-08-12 CRITICAL 9.8 CVE-2024-29937 NFS in a BSD derived codebase, as used in OpenBSD through 7.4 and FreeBSD through 14.0-RELEASE, allows remote attackers to execute arbitrary code via… FreeBSD after 7.4 Fix from $2,3002024-04-11 HIGH 8.8 CVE-2022-23092 The implementation of lib9p's handling of RWALK messages was missing a bounds check needed when unpacking the message contents. The missing check me… FreeBSD Mitigation only Fix from $1,9502024-02-15 HIGH 7.7 CVE-2022-23090 The aio_aqueue function, used by the lio_listio system call, fails to release a reference to a credential in an error case. An attacker may cause th… FreeBSD Mitigation only Fix from $1,9502024-02-15 MEDIUM 6.5 CVE-2022-23093 ping reads raw IP packets from the network to process responses in the pr_pack() function. As part of processing a response ping has to reconstruct … FreeBSD Mitigation only Fix from $1,6002024-02-15 MEDIUM 6.3 CVE-2024-25940 `bhyveload -h <host-path>` may be used to grant loader access to the <host-path> directory tree on the host. Affected versions of bhyveload(8) do no… FreeBSD 13.2 / 14.0+ Fix from $1,6002024-02-15 CRITICAL 9.8 CVE-2022-23088 The 802.11 beacon handling routine failed to validate the length of an IEEE 802.11s Mesh ID before copying it to a heap-allocated buffer. While a Fr… FreeBSD 12.3 / 13.0+ Fix from $2,3002024-02-15 HIGH 8.8 CVE-2022-23087 The e1000 network adapters permit a variety of modifications to an Ethernet packet when it is being transmitted. These include the insertion of IP a… FreeBSD 12.3+ Fix from $1,9502024-02-15 HIGH 8.2 CVE-2022-23085 A user-provided integer option was passed to nmreq_copyin() without checking if it would overflow. This insufficient bounds checking could lead to k… FreeBSD 12.3+ Fix from $1,9502024-02-15 HIGH 7.8 CVE-2022-23086 Handlers for *_CFG_PAGE read / write ioctls in the mpr, mps, and mpt drivers allocated a buffer of a caller-specified size, but copied to it a fixed … FreeBSD 12.3+ Fix from $1,9502024-02-15 HIGH 7.5 CVE-2022-23084 The total size of the user-provided nmreq to nmreq_copyin() was first computed and then trusted during the copyin. This time-of-check to time-of-use… FreeBSD 12.3+ Fix from $1,9502024-02-15 MEDIUM 5.3 CVE-2023-51765 sendmail through 8.17.2 allows SMTP smuggling in certain configurations. Remote attackers can use a published exploitation technique to inject e-mail… FreeBSD 8.18.0.2 / 11.0+ Fix from $1,6002023-12-24 HIGH 7.5 CVE-2023-6534 In versions of FreeBSD 14.0-RELEASE before 14-RELEASE-p2, FreeBSD 13.2-RELEASE before 13.2-RELEASE-p7 and FreeBSD 12.4-RELEASE before 12.4-RELEASE-p9… FreeBSD Mitigation only Fix from $1,9502023-12-13 MEDIUM 6.5 CVE-2023-6660 When a program running on an affected system appends data to a file via an NFS client mount, the bug can cause the NFS client to fail to copy in the … FreeBSD Mitigation only Fix from $1,6002023-12-13 CRITICAL 9.8 CVE-2023-5941 In versions of FreeBSD 12.4-RELEASE prior to 12.4-RELEASE-p7 and FreeBSD 13.2-RELEASE prior to 13.2-RELEASE-p5 the __sflush() stdio function in libc … FreeBSD 12.4 / 13.2+ Fix from $2,3002023-11-08 HIGH 7.5 CVE-2023-5978 In versions of FreeBSD 13-RELEASE before 13-RELEASE-p5, under certain circumstances the cap_net libcasper(3) service incorrectly validates that updat… FreeBSD 13.2+ Fix from $1,9502023-11-08 MEDIUM 5.5 CVE-2023-5370 On CPU 0 the check for the SMCCC workaround is called before SMCCC support has been initialized. This resulted in no speculative execution workaround… FreeBSD Mitigation only Fix from $1,6002023-10-04