Vulnerabilidades en FreeBSD
152 resultadosAnálisis Vexday
O FreeBSD acumula 111 CVEs catalogadas, com taxa de exploração ativa abaixo da média geral do catálogo — nenhuma entrada registrada no CISA KEV —, o que sugere um perfil de risco operacional relativamente contido no momento. Ainda assim, sete vulnerabilidades de severidade crítica e cinco com prova de conceito pública representam superfícies de ataque concretas que exigem atenção prioritária. A falha mais comum é do tipo CWE-787 (escrita fora dos limites), e a CVE com maior pontuação EPSS é a CVE-2018-17157, com índice de 0,2417, indicando probabilidade não trivial de exploração apesar da antiguidade da falha. O surgimento de 16 novas CVEs nos últimos 90 dias reforça a necessidade de monitoramento contínuo e aplicação ágil de correções.
CVE-2026-7164HIGHpf can overflow the stack parsing crafted SCTP packetsEPSS 0.4%CVE-2026-42511HIGHRemote code execution via malicious DHCP optionsEPSS 0.4%CVE-2025-0373MEDIUMBuffer overflow in some filesystems via NFSEPSS 0.4%CVE-2012-4576—FreeBSD: Input Validation Flaw allows local users to gain elevated privilegesEPSS 0.4%CVE-2017-1087—In FreeBSD 10.x before 10.4-STABLE, 10.4-RELEASE-p3, and 10.3-RELEASE-p24 named paths are globally scoped, meaning a process located in one EPSS 0.4%CVE-2024-51562MEDIUMbhyve(8) nvme_opc_get_log_page buffer over-readEPSS 0.4%CVE-2026-45250HIGHStack buffer overflow via setcred(2)EPSS 0.4%CVE-2018-6924—In FreeBSD before 11.1-STABLE, 11.2-RELEASE-p3, 11.1-RELEASE-p14, 10.4-STABLE, and 10.4-RELEASE-p12, insufficient validation in the ELF headEPSS 0.4%CVE-2024-51565MEDIUMbhyve(8) hda driver buffer over-readEPSS 0.4%CVE-2024-42416HIGHMultiple issues in ctl(4) CAM Target LayerEPSS 0.4%CVE-2024-43110HIGHMultiple issues in ctl(4) CAM Target LayerEPSS 0.4%CVE-2024-51566MEDIUMbhyve(8) NVMe driver to guest-induced infinite loops.EPSS 0.4%CVE-2017-1088—In FreeBSD before 11.1-STABLE, 11.1-RELEASE-p4, 11.0-RELEASE-p15, 10.4-STABLE, 10.4-RELEASE-p3, and 10.3-RELEASE-p24, the kernel does not prEPSS 0.4%CVE-2018-17155—In FreeBSD before 11.2-STABLE(r338983), 11.2-RELEASE-p4, 11.1-RELEASE-p15, 10.4-STABLE(r338984), and 10.4-RELEASE-p13, due to insufficient iEPSS 0.4%CVE-2026-4652HIGHRemote denial of service via null pointer dereferenceEPSS 0.4%CVE-2026-58081CRITICALHeap based buffer overflow in iconv(3)EPSS 0.4%CVE-2026-58082CRITICALStack based buffer overflow in iconv(3)EPSS 0.4%CVE-2017-1086—In FreeBSD before 11.1-STABLE, 11.1-RELEASE-p4, 11.0-RELEASE-p15, 10.4-STABLE, 10.4-RELEASE-p3, and 10.3-RELEASE-p24, not all information inEPSS 0.4%CVE-2025-0662MEDIUMUninitialized kernel memory disclosure via ktrace(2)EPSS 0.4%CVE-2026-2261HIGHblocklistd(8) socket leakEPSS 0.4%