Skip to main content

Vendor archive

freebsd CVEs

Beta · best-effort

542 CVEs tagged to vendor freebsd55 Critical, 224 High, 204 Medium, 59 Low, 0 Unrated.

CVE-2019-5603

Published Jul 26, 2019

In FreeBSD 12.0-STABLE before r350261, 12.0-RELEASE before 12.0-RELEASE-p8, 11.3-STABLE before r350263, 11.3-RELEASE before 11.3-RELEASE-p1, and 11.2-RELEASE before 11.2-RELEASE-p…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-5602

Published Jul 3, 2019

In FreeBSD 12.0-STABLE before r349628, 12.0-RELEASE before 12.0-RELEASE-p7, 11.3-PRERELEASE before r349629, 11.3-RC3 before 11.3-RC3-p1, and 11.2-RELEASE before 11.2-RELEASE-p11,…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-5601

Published Jul 3, 2019

In FreeBSD 12.0-STABLE before r347474, 12.0-RELEASE before 12.0-RELEASE-p7, 11.2-STABLE before r347475, and 11.2-RELEASE before 11.2-RELEASE-p11, a bug in the FFS implementation c…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-5600

Published Jul 3, 2019

In FreeBSD 12.0-STABLE before r349622, 12.0-RELEASE before 12.0-RELEASE-p7, 11.3-PRERELEASE before r349624, 11.3-RC3 before 11.3-RC3-p1, and 11.2-RELEASE before 11.2-RELEASE-p11,…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-5599

Published Jul 2, 2019

In FreeBSD 12.0-STABLE before r349197 and 12.0-RELEASE before 12.0-RELEASE-p6, a bug in the non-default RACK TCP stack can allow an attacker to cause several linked lists to grow…

CVSS 7.5 · High
evidence mentions
3
Buzz score
21.9
Vendor/product tagsBeta · best-effort

CVE-2019-5598

Published May 15, 2019

In FreeBSD 11.3-PRERELEASE before r345378, 12.0-STABLE before r345377, 11.2-RELEASE before 11.2-RELEASE-p10, and 12.0-RELEASE before 12.0-RELEASE-p4, a bug in pf does not check if…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-5597

Published May 15, 2019

In FreeBSD 11.3-PRERELEASE and 12.0-STABLE before r347591, 11.2-RELEASE before 11.2-RELEASE-p10, and 12.0-RELEASE before 12.0-RELEASE-p4, a bug in the pf IPv6 fragment reassembly…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-9495

Published Apr 17, 2019

The implementations of EAP-PWD in hostapd and wpa_supplicant are vulnerable to side-channel attacks as a result of cache access patterns. All versions of hostapd and wpa_supplican…

CVSS 3.7 · Low
evidence mentions
1
Buzz score
11.9

CVE-2019-5596

Published Feb 12, 2019

In FreeBSD 11.2-STABLE after r338618 and before r343786, 12.0-STABLE before r343781, and 12.0-RELEASE before 12.0-RELEASE-p3, a bug in the reference count implementation for UNIX…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-5595

Published Feb 12, 2019

In FreeBSD before 11.2-STABLE(r343782), 11.2-RELEASE-p9, 12.0-STABLE(r343781), and 12.0-RELEASE-p3, kernel callee-save registers are not properly sanitized before return from syst…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000998

Published Feb 4, 2019

FreeBSD CVSweb version 2.x contains a Cross Site Scripting (XSS) vulnerability in all pages that can result in limited impact--CVSweb is anonymous & read-only. It might impact oth…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-17161

Published Jan 3, 2019

In FreeBSD before 11.2-STABLE(r348229), 11.2-RELEASE-p7, 12.0-STABLE(r342228), and 12.0-RELEASE-p1, insufficient validation of network-provided data in bootpd may make it possible…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-17160

Published Dec 4, 2018

In FreeBSD before 11.2-STABLE(r341486) and 11.2-RELEASE-p6, insufficient bounds checking in one of the device models provided by bhyve can permit a guest operating system to overw…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-17159

Published Dec 4, 2018

In FreeBSD before 11.2-STABLE(r340854) and 11.2-RELEASE-p5, the NFS server lacks a bounds check in the READDIRPLUS NFS request. Unprivileged remote users with access to the NFS se…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-17158

Published Dec 4, 2018

In FreeBSD before 11.2-STABLE(r340854) and 11.2-RELEASE-p5, an integer overflow error can occur when handling the client address length field in an NFSv4 request. Unprivileged rem…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-17157

Published Dec 4, 2018

In FreeBSD before 11.2-STABLE(r340854) and 11.2-RELEASE-p5, an integer overflow error when handling opcodes can cause memory corruption by sending a specially crafted NFSv4 reques…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-17156

Published Nov 28, 2018

In FreeBSD before 11.2-STABLE(r340268) and 11.2-RELEASE-p5, due to incorrectly accounting for padding on 64-bit platforms, a buffer underwrite could occur when constructing an ICM…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-6925

Published Sep 28, 2018

In FreeBSD before 11.2-STABLE(r338986), 11.2-RELEASE-p4, 11.1-RELEASE-p15, 10.4-STABLE(r338985), and 10.4-RELEASE-p13, due to improper maintenance of IPv6 protocol control block f…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-17155

Published Sep 28, 2018

In FreeBSD before 11.2-STABLE(r338983), 11.2-RELEASE-p4, 11.1-RELEASE-p15, 10.4-STABLE(r338984), and 10.4-RELEASE-p13, due to insufficient initialization of memory copied to userl…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-17154

Published Sep 28, 2018

In FreeBSD before 11.2-STABLE(r338987), 11.2-RELEASE-p4, and 11.1-RELEASE-p15, due to insufficient memory checking in the freebsd4_getfsstat system call, a NULL pointer dereferenc…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 151-175 of 542 CVEsPage 7 of 22