freebsd
35 known vulnerabilities affecting freebsd products.
Products
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2000-0963 | Medium | 0.7% | 7.2 | Buffer overflow in ncurses library allows local users to execute arbitrary comma… | |
| CVE-2026-58095 | Medium | 0.6% | 8.8 | mp_Enddisc() used incorrect length calculations when formatting endpoint discrim… | |
| CVE-2026-58096 | Medium | 0.6% | 8.8 | LcpDecodeConfig() did not validate the length of received endpoint discriminator… | |
| CVE-2002-0062 | Medium | 0.5% | 7.2 | Buffer overflow in ncurses 5.0, and the ncurses4 compatibility package as used i… | |
| CVE-2026-45250 | Medium | 0.4% | 7.8 | The setcred(2) system call is only available to privileged users. However, befo… | |
| CVE-2026-58081 | Medium | 0.4% | 9.8 | Several encoding modules, including HZ, UTF-7, VIQR, and ZW, did not properly ch… | |
| CVE-2026-58082 | Medium | 0.4% | 9.8 | The ISO-2022 encoding module used a stack buffer sized to MB_LEN_MAX (6 bytes) f… | |
| CVE-2026-45255 | Medium | 0.3% | 7.5 | When bsdinstall or bsdconfig are prompted to scan for nearby Wi-Fi networks, the… | |
| CVE-2026-49419 | Medium | 0.3% | 8.8 | When the JAIL_AT_DESC flag is specified, kern_jail_set() and kern_jail_get() rel… | |
| CVE-2026-49428 | Medium | 0.3% | 8.4 | Certain system calls, such open(2) with the O_TRUNC flag set, and fspacectl(2), … | |
| CVE-2026-49418 | Medium | 0.3% | 8.8 | When msync(MS_INVALIDATE) is called on a mapping of an unmanaged device object, … | |
| CVE-2026-49427 | Medium | 0.3% | 8.8 | Pages belonging to largepage shared memory objects were not explicitly wired. W… | |
| CVE-2026-49420 | Medium | 0.3% | 8.8 | The RTSP handler in libalias rewrote outgoing packets into a fixed-length stack … | |
| CVE-2026-58086 | Medium | 0.3% | 8.1 | As an inadvertent side effect of an unrelated code change, PRIV_KTRACE was alway… | |
| CVE-2026-58085 | Medium | 0.2% | 7.5 | After dispatching a decrypt operation to OCF and receiving the result, the wg(4)… | |
| CVE-2026-49415 | Medium | 0.2% | 8.8 | During execve(2) of a SUID binary, the new virtual address space is installed be… | |
| CVE-2026-58097 | Medium | 0.2% | 7.8 | mp_SetEnddisc() copied a user-supplied PSN endpoint value without length validat… | |
| CVE-2026-45253 | Medium | 0.2% | 8.4 | ptrace(PT_SC_REMOTE) failed to properly validate parameters for the syscall(2) a… | |
| CVE-2026-39461 | Medium | 0.2% | 8.8 | libcasper(3) communicates with helper processes via UNIX domain sockets, and use… | |
| CVE-2026-45251 | Medium | 0.2% | 7.8 | A file descriptor can be closed while a thread is blocked in a poll(2) or select… | |
| CVE-2026-49429 | Medium | 0.2% | 7.8 | The ZFS_IOC_USERSPACE_MANY ioctl, used by zfs-userspace(8), truncated a 64-bit o… | |
| CVE-2026-49430 | Medium | 0.2% | 7.8 | The ZFS_IOC_RECV_NEW ioctl, in the heal receive path, similarly truncated a 64-b… | |
| CVE-2026-49422 | Medium | 0.1% | 8.4 | The RACK setsockopt(2) handler drops the connection lock in order to copy option… | |
| CVE-2026-58083 | Medium | 0.1% | 8.4 | While the kernel was copying knotes during fork, a knote with a timer-based filt… | |
| CVE-2026-58087 | Medium | 0.1% | 7.8 | The GETALL and SETALL commands in semctl(2) recorded the number of semaphores in… | |
| CVE-2026-58088 | Medium | 0.1% | 7.4 | The ELF core dump code counted the number of dumpable VM map entries, allocated … | |
| CVE-2026-49421 | Medium | 0.1% | 7.1 | The kernel function that implements unlinkat(2) and funlinkat(2) validated the A… | |
| CVE-2026-45252 | Low | 0.3% | 5.5 | When a fusefs file system implements extended attributes, the kernel may send a … | |
| CVE-2026-45254 | Low | 0.2% | 6.5 | In the case of the cap_net service, when a key present in the old limit was omit… | |
| CVE-2026-49431 | Low | 0.1% | 3.3 | The ZFS_IOC_SET_PROP ioctl, used by zfs-set(8), incorrectly validated the callin… | |
| CVE-2026-49424 | Low | 0.1% | 5.5 | The Linux waitid() implementation translates a FreeBSD siginfo_t struct into a s… | |
| CVE-2026-49425 | Low | 0.1% | 5.5 | The compat32 kevent() handler translates a 64-bit kevent struct into a stack- de… | |
| CVE-2026-58084 | Low | 0.1% | 5.5 | To retrieve the previous timer value, the kernel calls realtimer_gettime(), whic… | |
| CVE-2026-49423 | Low | 0.1% | 3.3 | When building the iovec array for a received TLS 1.2 CBC record, ktls_ocf_tls_cb… | |
| CVE-2026-49426 | Low | 0.1% | 3.3 | When auditing a system call executed via ptrace(PT_SC_REMOTE), the kernel passed… |