29 Total CVEs
29 AI Analyzed
0 CISA KEV
3 Critical

Profile

0% ended up actively exploited 0 of 29 added to CISA KEV
10% rated critical (CVSS 9.0+) 3 critical, 26 high
0 with a public exploit on record positive-only index; absence is not proof

Last 12 months

29 CVEs in the last 12 months

Products

  • FreeBSD11
  • SAP Software (RPCSEC_GSS implementation)1
  • libnv1
  • list options1

4 products in total

Every figure counts the high and critical CVEs CVE Brief has published for this vendor, not every CVE the vendor has ever received. Exploitation means listing in the CISA Known Exploited Vulnerabilities catalog. No patch-availability figure is shown because CVE Brief does not measure it.

All Vendors
Showing 1-29 of 29 CVEs
CVE-2026-7270
Analyzed
7.8
FreeBSD Multiple Products

An operator precedence bug in the kernel results in a scenario where a buffer overflow causes attacker-controlled data to overwrite adjacent execve(2)...

2026-05-01
CVE-2026-7164
Analyzed
7.5
FreeBSD Multiple Products

Incorrect packet validation allowed unbounded recursion parsing SCTP chunk parameters

2026-05-01
CVE-2026-58097
Analyzed
7.8
FreeBSD FreeBSD

mp_SetEnddisc() copied a user-supplied PSN endpoint value without length validation, allowing a buffer overflow via the ppp(8) command interface. A l...

2026-09-01
CVE-2026-58096
Analyzed
9.8
FreeBSD FreeBSD

The LcpDecodeConfig function in FreeBSD fails to validate the length of endpoint discriminator options, leading to an out-of-bounds write vulnerabilit...

2026-08-27
CVE-2026-58095
Analyzed
9.8
FreeBSD FreeBSD

A heap-based buffer overflow in the mp_Enddisc function of FreeBSD allows unauthenticated remote attackers to cause a crash or execute arbitrary code...

2026-08-27
CVE-2026-58094
Analyzed
7.8
FreeBSD FreeBSD

The FIOSSHMLPGCNF ioctl(2) operation configures the page size for a largepage shared memory object. This is intended to be used immediately after cre...

2026-09-02
CVE-2026-58093
Analyzed
7
FreeBSD FreeBSD

The TIOCSCTTY ioctl handler drops the tty lock in order to acquire the process tree lock. After reacquiring the tty lock, the handler did not revalid...

2026-08-31
CVE-2026-58092
Analyzed
8.1
FreeBSD FreeBSD

In FreeBSD 15.0, the kernel structure used to represent user credentials changed: previously the primary group ID was stored in the first element of t...

2026-09-01
CVE-2026-58091
Analyzed
7.8
FreeBSD FreeBSD

The implementation of this ioctl attempts to acquire locks on all channels in a sync group. If locking a channel would block, it releases the sync gr...

2026-09-01
CVE-2026-58090
Analyzed
7.8
FreeBSD FreeBSD

The SOCK_STREAM receive path in the unix socket implementation failed to fully detach control messages from the socket buffer before processing them....

2026-09-01
CVE-2026-58089
Analyzed
7.8
FreeBSD FreeBSD

When a process calls execve(2) to execute a setuid or setgid image, hwpmc(4) is supposed to detach PMCs owned by unprivileged processes. An inverted...

2026-08-31
CVE-2026-5398
Analyzed
8.4
FreeBSD Multiple Products

The implementation of TIOCNOTTY failed to clear a back-pointer from the structure representing the controlling terminal to the calling process' sessio...

2026-04-23
CVE-2026-49420
Analyzed
8.8
FreeBSD FreeBSD

The RTSP handler in libalias rewrote outgoing packets into a fixed-length stack buffer without checking whether the rewritten data fit in the buffer,...

2026-08-20
CVE-2026-4748
Analyzed
7.5
FreeBSD Multiple Products

A regression in the way hashes were calculated caused rules containing the address range syntax (x

2026-04-02
CVE-2026-4747
Analyzed
8.8
FreeBSD SAP Software (RPCSEC_GSS implementation)

Each RPCSEC_GSS data packet is validated by a routine which checks a signature in the packet

2026-03-27
CVE-2026-45257
Analyzed
7.8
FreeBSD FreeBSD

The KTLS receive path decrypted each record in place, assuming that the mbufs holding received data were anonymous and safe to modify

2026-06-27
CVE-2026-45255
Analyzed
7.5
FreeBSD Multiple Products

When bsdinstall or bsdconfig are prompted to scan for nearby Wi-Fi networks, they build up a list of network names and use bsddialog(1) to prompt the...

2026-05-22
CVE-2026-45253
Analyzed
8.4
FreeBSD Multiple Products

ptrace(PT_SC_REMOTE) failed to properly validate parameters for the syscall(2) and __syscall(2) meta-system calls

2026-05-22
CVE-2026-45251
Analyzed
7.8
FreeBSD Multiple Products

A file descriptor can be closed while a thread is blocked in a poll(2) or select(2) call waiting for that descriptor

2026-05-22
CVE-2026-45250
Analyzed
7.8
FreeBSD Multiple Products

The setcred(2) system call is only available to privileged users

2026-05-22
CVE-2026-42512
Analyzed
7.3
FreeBSD Multiple Products

As dhclient is building an environment to pass to dhclient-script, it may need to resize the array of string pointers

2026-05-01
CVE-2026-42511
Analyzed
7.3
FreeBSD Multiple Products

The BOOTP file field is written to the lease file without escaping embedded double-quotes, allowing injection of arbitrary dhclient

2026-05-01
CVE-2026-39461
Analyzed
8.8
FreeBSD Multiple Products

libcasper(3) communicates with helper processes via UNIX domain sockets, and uses the select(2) system call to wait for data to become available

2026-05-22
CVE-2026-39457
Analyzed
7.8
FreeBSD Multiple Products

When exchanging data over a socket, libnv uses select(2) to wait for data to arrive

2026-05-01
CVE-2026-35547
Analyzed
9.1
FreeBSD libnv

A heap-based buffer overflow in libnv, caused by improper message size validation, allows for system crashes or potential privilege escalation.

2026-05-01
CVE-2026-3038
Analyzed
7.5
FreeBSD Multiple Products

The rtsock_msg_buffer() function serializes routing information into a buffer

2026-03-10
CVE-2025-15547
Analyzed
8.8
FreeBSD Multiple Products

By default, jailed processes cannot mount filesystems, including nullfs(4)

2026-03-11
CVE-2025-14769
Analyzed
7.5
FreeBSD Multiple Products

In some cases, the `tcp-setmss` handler may free the packet data and throw an error without halting the rule processing engine

2026-03-10
CVE-2025-14558
Analyzed
7.2
FreeBSD list options

The rtsol(8) and rtsold(8) programs do not validate the domain search list options provided in router advertisement messages; the option body is passe...

2026-03-10