Vulnerabilidades em FreeBSD
152 resultadosAnálise Vexday
O FreeBSD acumula 111 CVEs catalogadas, com taxa de exploração ativa abaixo da média geral do catálogo — nenhuma entrada registrada no CISA KEV —, o que sugere um perfil de risco operacional relativamente contido no momento. Ainda assim, sete vulnerabilidades de severidade crítica e cinco com prova de conceito pública representam superfícies de ataque concretas que exigem atenção prioritária. A falha mais comum é do tipo CWE-787 (escrita fora dos limites), e a CVE com maior pontuação EPSS é a CVE-2018-17157, com índice de 0,2417, indicando probabilidade não trivial de exploração apesar da antiguidade da falha. O surgimento de 16 novas CVEs nos últimos 90 dias reforça a necessidade de monitoramento contínuo e aplicação ágil de correções.
CVE-2019-5595—In FreeBSD before 11.2-STABLE(r343782), 11.2-RELEASE-p9, 12.0-STABLE(r343781), and 12.0-RELEASE-p3, kernel callee-save registers are not proEPSS 0.3%CVE-2018-17154—In FreeBSD before 11.2-STABLE(r338987), 11.2-RELEASE-p4, and 11.1-RELEASE-p15, due to insufficient memory checking in the freebsd4_getfsstatEPSS 0.3%CVE-2018-6925—In FreeBSD before 11.2-STABLE(r338986), 11.2-RELEASE-p4, 11.1-RELEASE-p15, 10.4-STABLE(r338985), and 10.4-RELEASE-p13, due to improper maintEPSS 0.3%CVE-2024-51563MEDIUMbhyve(8) virtio_vq_recordon time-of-check to time-of-use raceEPSS 0.3%CVE-2026-35547HIGHHeap overflow in libnvEPSS 0.3%CVE-2018-6920—In FreeBSD before 11.1-STABLE(r332303), 11.1-RELEASE-p10, 10.4-STABLE(r332321), and 10.4-RELEASE-p9, due to insufficient initialization of mEPSS 0.3%CVE-2018-6921—In FreeBSD before 11.1-STABLE(r332066) and 11.1-RELEASE-p10, due to insufficient initialization of memory copied to userland in the network EPSS 0.3%CVE-2026-45255HIGHRemote code execution via installer Wi-Fi access point scansEPSS 0.3%CVE-2024-45288HIGHMultiple vulnerabilities in libnvEPSS 0.3%CVE-2025-0374MEDIUMUnprivileged access to system filesEPSS 0.3%CVE-2026-49419HIGHJail reference count underflowEPSS 0.3%CVE-2026-49428HIGHposixshm: system calls can incorrectly free memory of largepage objectsEPSS 0.3%CVE-2026-49418HIGHUse-after-free in device pager page listEPSS 0.3%CVE-2026-45252MEDIUMHeap overflow in FUSE_LISTXATTREPSS 0.3%CVE-2026-49427HIGHposixshm: largepage shared memory objects not explicitly wiredEPSS 0.3%CVE-2024-45289HIGHUnbounded allocation in ctl(4) CAM Target LayerEPSS 0.3%CVE-2026-49420HIGHBuffer overflow in libalias RTSP handlerEPSS 0.3%CVE-2026-58086HIGHktrace(2) privilege incorrectly validated in jailsEPSS 0.3%CVE-2026-4748HIGHpf silently ignores certain rulesEPSS 0.3%CVE-2024-41928HIGHbhyve(8) privileged guest escape via TPM device passthroughEPSS 0.2%