Exposure of FreeBSD

Operating systems
135
exposure score
2,482
sites use
0
exploited
9
critical
Vexday analysis

Com 162 CVEs catalogadas e nenhuma entrada no catálogo CISA KEV, o FreeBSD apresenta taxa de exploração ativa abaixo da média geral do catálogo, o que sugere um perfil de risco relativamente contido em termos de ameaças confirmadas em produção. Ainda assim, 7 vulnerabilidades de severidade crítica e 16 surgidas nos últimos 90 dias indicam uma superfície ativa que requer monitoramento contínuo. O tipo de falha mais frequente é CWE-787 (escrita fora dos limites de memória), classe de vulnerabilidade com histórico relevante de exploração em sistemas de baixo nível. A CVE com maior pontuação EPSS no conjunto é CVE-2020-7457, com valor de 0,33, sinalizando probabilidade não desprezível de exploração e merecendo atenção prioritária em ambientes que ainda não aplicaram a correção correspondente.

CVEs

203 results
CVE-2026-2261HIGHblocklistd(8) socket leakEPSS 0.4%CVE-2019-5595In FreeBSD before 11.2-STABLE(r343782), 11.2-RELEASE-p9, 12.0-STABLE(r343781), and 12.0-RELEASE-p3, kernel callee-save registers are not proEPSS 0.3%CVE-2020-7453In FreeBSD 12.1-STABLE before r359021, 12.1-RELEASE before 12.1-RELEASE-p3, 11.3-STABLE before r359020, and 11.3-RELEASE before 11.3-RELEASEEPSS 0.3%CVE-2021-29626In FreeBSD 13.0-STABLE before n245117, 12.2-STABLE before r369551, 11.4-STABLE before r369559, 13.0-RC5 before p1, 12.2-RELEASE before p6, aEPSS 0.3%CVE-2019-15878In FreeBSD 12.1-STABLE before r352509, 11.3-STABLE before r352509, and 11.3-RELEASE before p9, an unprivileged local user can trigger a use-EPSS 0.3%CVE-2018-17154In FreeBSD before 11.2-STABLE(r338987), 11.2-RELEASE-p4, and 11.1-RELEASE-p15, due to insufficient memory checking in the freebsd4_getfsstatEPSS 0.3%CVE-2018-6925In FreeBSD before 11.2-STABLE(r338986), 11.2-RELEASE-p4, 11.1-RELEASE-p15, 10.4-STABLE(r338985), and 10.4-RELEASE-p13, due to improper maintEPSS 0.3%CVE-2024-51563MEDIUMbhyve(8) virtio_vq_recordon time-of-check to time-of-use raceEPSS 0.3%CVE-2026-35547HIGHHeap overflow in libnvEPSS 0.3%CVE-2018-6921In FreeBSD before 11.1-STABLE(r332066) and 11.1-RELEASE-p10, due to insufficient initialization of memory copied to userland in the network EPSS 0.3%CVE-2018-6920In FreeBSD before 11.1-STABLE(r332303), 11.1-RELEASE-p10, 10.4-STABLE(r332321), and 10.4-RELEASE-p9, due to insufficient initialization of mEPSS 0.3%CVE-2026-45255HIGHRemote code execution via installer Wi-Fi access point scansEPSS 0.3%CVE-2024-45288HIGHMultiple vulnerabilities in libnvEPSS 0.3%CVE-2025-0374MEDIUMUnprivileged access to system filesEPSS 0.3%CVE-2026-49419HIGHJail reference count underflowEPSS 0.3%CVE-2026-49428HIGHposixshm: system calls can incorrectly free memory of largepage objectsEPSS 0.3%CVE-2019-15875In FreeBSD 12.1-STABLE before r354734, 12.1-RELEASE before 12.1-RELEASE-p2, 12.0-RELEASE before 12.0-RELEASE-p13, 11.3-STABLE before r354735EPSS 0.3%CVE-2026-49418HIGHUse-after-free in device pager page listEPSS 0.3%CVE-2021-29631In FreeBSD 13.0-STABLE before n246941-20f96f215562, 12.2-STABLE before r370400, 11.4-STABLE before r370399, 13.0-RELEASE before p4, 12.2-RELEPSS 0.3%CVE-2026-45252MEDIUMHeap overflow in FUSE_LISTXATTREPSS 0.3%