Skip to main content

Vendor archive

freebsd CVEs

Beta · best-effort

542 CVEs tagged to vendor freebsd55 Critical, 224 High, 204 Medium, 59 Low, 0 Unrated.

CVE-2018-6924

Published Sep 12, 2018

In FreeBSD before 11.1-STABLE, 11.2-RELEASE-p3, 11.1-RELEASE-p14, 10.4-STABLE, and 10.4-RELEASE-p12, insufficient validation in the ELF header parser could allow a malicious ELF b…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2017-1085

Published Sep 12, 2018

In FreeBSD before 11.2-RELEASE, an application which calls setrlimit() to increase RLIMIT_STACK may turn a read-only memory region below the stack into a read-write region. A spec…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-1084

Published Sep 12, 2018

In FreeBSD before 11.2-RELEASE, multiple issues with the implementation of the stack guard-page reduce the protections afforded by the guard-page. This results in the possibility…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-1083

Published Sep 12, 2018

In FreeBSD before 11.2-RELEASE, a stack guard-page is available but is disabled by default. This results in the possibility a poorly written process could be cause a stack overflo…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-1082

Published Sep 12, 2018

In FreeBSD 11.x before 11.1-RELEASE and 10.x before 10.4-RELEASE, the qsort algorithm has a deterministic recursion pattern. Feeding a pathological input to the algorithm can lead…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-6923

Published Sep 4, 2018

In FreeBSD before 11.1-STABLE, 11.2-RELEASE-p2, 11.1-RELEASE-p13, ip fragment reassembly code is vulnerable to a denial of service due to excessive system resource consumption. Th…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-6922

Published Aug 9, 2018

One of the data structures that holds TCP segments in all versions of FreeBSD prior to 11.2-RELEASE-p1, 11.1-RELEASE-p12, and 10.4-RELEASE-p10 uses an inefficient algorithm to rea…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-6559

Published Jul 13, 2018

Improper bounds checking of the obuf variable in the link_ntoa() function in linkaddr.c of the BSD libc library may allow an attacker to read or write from memory. The full impact…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-3665

Published Jun 21, 2018

System software utilizing Lazy FP state restore technique on systems using Intel Core-based microprocessors may potentially allow a local process to infer data from another proces…

CVSS 5.6 · Medium
evidence mentions
7
Buzz score
28.8

CVE-2018-6921

Published May 8, 2018

In FreeBSD before 11.1-STABLE(r332066) and 11.1-RELEASE-p10, due to insufficient initialization of memory copied to userland in the network subsystem, small amounts of kernel memo…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-6920

Published May 8, 2018

In FreeBSD before 11.1-STABLE(r332303), 11.1-RELEASE-p10, 10.4-STABLE(r332321), and 10.4-RELEASE-p9, due to insufficient initialization of memory copied to userland in the Linux s…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-8897

Published May 8, 2018

A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) was mishandled in the development of some or all operating-sy…

CVSS 7.8 · High
evidence mentions
3
Buzz score
20.4

CVE-2017-1081

Published Apr 10, 2018

In FreeBSD before 11.0-STABLE, 11.0-RELEASE-p10, 10.3-STABLE, and 10.3-RELEASE-p19, ipfilter using "keep state" or "keep frags" options can cause a kernel panic when fed specially…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-6919

Published Apr 4, 2018

In FreeBSD before 11.1-STABLE, 11.1-RELEASE-p9, 10.4-STABLE, 10.4-RELEASE-p8 and 10.3-RELEASE-p28, due to insufficient initialization of memory copied to userland, small amounts o…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-6918

Published Apr 4, 2018

In FreeBSD before 11.1-STABLE, 11.1-RELEASE-p9, 10.4-STABLE, 10.4-RELEASE-p8 and 10.3-RELEASE-p28, the length field of the ipsec option header does not count the size of the optio…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-6917

Published Apr 4, 2018

In FreeBSD before 11.1-STABLE, 11.1-RELEASE-p9, 10.4-STABLE, 10.4-RELEASE-p8 and 10.3-RELEASE-p28, insufficient validation of user-provided font parameters can result in an intege…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-6916

Published Mar 9, 2018

In FreeBSD before 11.1-STABLE, 11.1-RELEASE-p7, 10.4-STABLE, 10.4-RELEASE-p7, and 10.3-RELEASE-p28, the kernel does not properly validate IPsec packets coming from a trusted host.…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-5674

Published Feb 5, 2018

The routed daemon in FreeBSD 9.3 before 9.3-RELEASE-p22, 10.2-RC2 before 10.2-RC2-p1, 10.2-RC1 before 10.2-RC1-p2, 10.2 before 10.2-BETA2-p3, and 10.1 before 10.1-RELEASE-p17 allo…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1418

Published Feb 5, 2018

The do_ed_script function in pch.c in GNU patch through 2.7.6, and patch in FreeBSD 10.1 before 10.1-RELEASE-p17, 10.2 before 10.2-BETA2-p3, 10.2-RC1 before 10.2-RC1-p2, and 0.2-R…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2015-1416

Published Feb 5, 2018

Larry Wall's patch; patch in FreeBSD 10.2-RC1 before 10.2-RC1-p1, 10.2 before 10.2-BETA2-p2, and 10.1 before 10.1-RELEASE-p16; Bitrig; GNU patch before 2.2.5; and possibly other p…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-1088

Published Nov 16, 2017

In FreeBSD before 11.1-STABLE, 11.1-RELEASE-p4, 11.0-RELEASE-p15, 10.4-STABLE, 10.4-RELEASE-p3, and 10.3-RELEASE-p24, the kernel does not properly clear the memory of the kld_file…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort
Showing 176-200 of 542 CVEsPage 8 of 22