BSDI maintains a focused portfolio centered on its BSD operating system and Gauntlet firewall product, both of which have hosted a sustained stream of low-level system vulnerabilities over time. The exposure concentrates in memory-safety and input-handling weakness classes—buffer overflows, improper input validation, and OS command injection—that are characteristic of native-code infrastructure software, and public exploit code has frequently accompanied these disclosures. The vendor's small but durable presence in the vulnerability landscape reflects the historical role these products played in early internet infrastructure, though the portfolio does not skew toward critical severity. Defenders maintaining legacy BSD or Gauntlet deployments should treat memory-safety and command-injection fixes as high-priority; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bsdi over time
Signals from CVEs in this vendor scope (39 CVEs).
39 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-1999-0046HIGH Buffer overflow of rlogin program using TERM environmental variable. | Feb 6, 1997 | 10.0 | 67 | NO | YES |
CVE-1999-0002HIGH Buffer overflow in NFS mountd gives root access to remote attackers, mostly in Linux systems. | Oct 12, 1998 | 10.0 | 56 | NO | YES |
CVE-1999-0043CRITICAL Command execution via shell metachars in INN daemon (innd) 1.5 using "newgroup" and "rmgroup" control messages, and others. | Dec 4, 1996 | 9.8 | 55 | NO | NO |
CVE-1999-0009HIGH Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases. | Apr 8, 1998 | 10.0 | 54 | NO | YES |
CVE-1999-0042HIGH Buffer overflow in University of Washington's implementation of IMAP and POP servers. | Apr 7, 1997 | 10.0 | 44 | NO | YES |
CVE-2008-4609HIGH The TCP implementation in (1) Linux, (2) platforms based on BSD Unix, (3) Microsoft Windows, (4) Cisco products, and probably other operating systems allows remote attackers to cau | Oct 20, 2008 | 7.1 | 40 | NO | NO |
CVE-1999-0879HIGH Buffer overflow in WU-FTPD and related FTP servers allows remote attackers to gain root privileges via macro variables in a message file. | Oct 1, 1999 | 10.0 | 39 | NO | YES |
CVE-1999-0704HIGH Buffer overflow in Berkeley automounter daemon (amd) logging facility provided in the Linux am-utils package and others. | Sep 16, 1999 | 9.3 | 34 | NO | YES |
CVE-1999-0038HIGH Buffer overflow in xlock program allows local users to execute commands as root. | Apr 26, 1997 | 8.4 | 32 | NO | YES |
CVE-1999-0040HIGH Buffer overflow in Xt library of X Windowing System allows local users to execute commands with root privileges. | May 1, 1997 | 7.2 | 29 | NO | YES |
Signals from CVEs in this vendor scope (39 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bsdi.
Media articles that mention a CVE ID that affects a product developed by Bsdi — matched by CVE ID, not by vendor name.