Vulnerabilities in FreeBSD
111 resultsCVE-2012-4576—FreeBSD: Input Validation Flaw allows local users to gain elevated privilegesEPSS 0.4%CVE-2017-1087—In FreeBSD 10.x before 10.4-STABLE, 10.4-RELEASE-p3, and 10.3-RELEASE-p24 named paths are globally scoped, meaning a process located in one EPSS 0.4%CVE-2026-45250HIGHStack buffer overflow via setcred(2)EPSS 0.4%CVE-2018-6924—In FreeBSD before 11.1-STABLE, 11.2-RELEASE-p3, 11.1-RELEASE-p14, 10.4-STABLE, and 10.4-RELEASE-p12, insufficient validation in the ELF headEPSS 0.4%CVE-2024-51562MEDIUMbhyve(8) nvme_opc_get_log_page buffer over-readEPSS 0.4%CVE-2024-42416HIGHMultiple issues in ctl(4) CAM Target LayerEPSS 0.4%CVE-2024-43110HIGHMultiple issues in ctl(4) CAM Target LayerEPSS 0.4%CVE-2025-0373MEDIUMBuffer overflow in some filesystems via NFSEPSS 0.4%CVE-2024-51565MEDIUMbhyve(8) hda driver buffer over-readEPSS 0.4%CVE-2017-1088—In FreeBSD before 11.1-STABLE, 11.1-RELEASE-p4, 11.0-RELEASE-p15, 10.4-STABLE, 10.4-RELEASE-p3, and 10.3-RELEASE-p24, the kernel does not prEPSS 0.4%CVE-2024-51566MEDIUMbhyve(8) NVMe driver to guest-induced infinite loops.EPSS 0.4%CVE-2018-17155—In FreeBSD before 11.2-STABLE(r338983), 11.2-RELEASE-p4, 11.1-RELEASE-p15, 10.4-STABLE(r338984), and 10.4-RELEASE-p13, due to insufficient iEPSS 0.4%CVE-2026-4652HIGHRemote denial of service via null pointer dereferenceEPSS 0.4%CVE-2017-1086—In FreeBSD before 11.1-STABLE, 11.1-RELEASE-p4, 11.0-RELEASE-p15, 10.4-STABLE, 10.4-RELEASE-p3, and 10.3-RELEASE-p24, not all information inEPSS 0.4%CVE-2026-2261HIGHblocklistd(8) socket leakEPSS 0.4%CVE-2019-5595—In FreeBSD before 11.2-STABLE(r343782), 11.2-RELEASE-p9, 12.0-STABLE(r343781), and 12.0-RELEASE-p3, kernel callee-save registers are not proEPSS 0.3%CVE-2025-0662MEDIUMUninitialized kernel memory disclosure via ktrace(2)EPSS 0.3%CVE-2018-6921—In FreeBSD before 11.1-STABLE(r332066) and 11.1-RELEASE-p10, due to insufficient initialization of memory copied to userland in the network EPSS 0.3%CVE-2018-6920—In FreeBSD before 11.1-STABLE(r332303), 11.1-RELEASE-p10, 10.4-STABLE(r332321), and 10.4-RELEASE-p9, due to insufficient initialization of mEPSS 0.3%CVE-2018-17154—In FreeBSD before 11.2-STABLE(r338987), 11.2-RELEASE-p4, and 11.1-RELEASE-p15, due to insufficient memory checking in the freebsd4_getfsstatEPSS 0.3%