FreeBSD

First CVE: Jan 20, 2005Active for: 22 years
206
CVEs Published
More CVEs Published than 80% of tracked CNAs
12.1
Avg CVEs / Year
More Avg CVEs / Year than 59% of tracked CNAs
7.2
Avg CVSS Score
Higher Avg CVSS Score than 50% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by FreeBSD as a CNA, 90.3% affect products that FreeBSD develops as a vendor.

90.3%
Self-reported: 186Third-party: 20

Of all the CVEs published that affect products developed by FreeBSD, 31.6% are self-published by FreeBSD as a CNA.

31.6%
68.4%
Self-published: 186Published by other CNAs: 402

Trends Over Time

The number and severity of CVEs published by FreeBSD over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 20, 2005
21 years ago
Most Recent CVE
Jun 27, 2026
28 days ago

Top CVEs

All CVEs published by FreeBSD as a CNA, regardless of affected vendor or product.

206 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and earlier, Heimdal 1.5.1 and earlier, GNU
Dec 25, 201110.092NOYES
The rtsol(8) and rtsold(8) programs do not validate the domain search list options provided in router advertisement messages; the option body is passed to resolvconf(8) unmodified.
Mar 9, 20267.251NOYES
In FreeBSD 12.1-STABLE before r359565, 12.1-RELEASE before p7, 11.4-STABLE before r362975, 11.4-RELEASE before p1, and 11.3-RELEASE before p11, missing synchronization in the IPV6_
Jul 9, 20208.147NOYES
In FreeBSD before 11.2-RELEASE, multiple issues with the implementation of the stack guard-page reduce the protections afforded by the guard-page. This results in the possibility a
Sep 12, 20187.543NOYES
In FreeBSD before 11.2-STABLE(r340854) and 11.2-RELEASE-p5, an integer overflow error when handling opcodes can cause memory corruption by sending a specially crafted NFSv4 request
Dec 4, 20189.842NONO
Each RPCSEC_GSS data packet is validated by a routine which checks a signature in the packet. This routine copies a portion of the packet into a stack buffer, but fails to ensure
Mar 26, 20268.840NONO
The setcred(2) system call is only available to privileged users. However, before the privilege level of the caller is checked, the user-supplied list of supplementary groups is c
May 21, 20267.838NONO
The BOOTP file field is written to the lease file without escaping embedded double-quotes, allowing injection of arbitrary dhclient.conf directives. When the lease file is subsequ
Apr 30, 20268.138NONO
The KTLS receive path decrypted each record in place, assuming that the mbufs holding received data were anonymous and safe to modify. This assumption does not hold for data place
Jun 26, 20267.837NONO
In FreeBSD 11.2-STABLE after r338618 and before r343786, 12.0-STABLE before r343781, and 12.0-RELEASE before 12.0-RELEASE-p3, a bug in the reference count implementation for UNIX d
Feb 12, 20198.837NOYES

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA206 CVEs
Severity distribution among all CVEs352,427 CVEs
LowMediumHighCritical
Attack Vector
Local66 (32.0%)
Network103 (50.0%)
Unknown33 (16.0%)
Physical3 (1.5%)
Adjacent Network1 (0.5%)
Attack Complexity
Low158 (76.7%)
High15 (7.3%)
Unknown33 (16.0%)
User Interaction
None171 (83.0%)
Unknown33 (16.0%)
Required2 (1.0%)
Privileges Required
Low67 (32.5%)
High11 (5.3%)
None95 (46.1%)
Unknown33 (16.0%)

Exploit Exposure

Signals from CVEs in this cna scope (206 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
3 CVEs
1.5% of CVEs· 90th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
9 CVEs
4.4% of CVEs· 94th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID published by FreeBSD as a CNA.

Media Mentions

Media articles that mention a CVE ID published by FreeBSD as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs