Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

FreeBSD

First CVE: May 9, 1990Active for: 36 yearsTotal CVEs: 588
55.6
VTI Score
TOP TARGET

FreeBSD is among the most prominent operating systems in the vulnerability landscape, supporting a wide range of deployment contexts from embedded systems and servers to high-performance network infrastructure, despite a modest product count. Its vulnerability profile concentrates in the core FreeBSD kernel and system utilities, alongside widely embedded components such as libarchive, and skews toward serious outcomes with a meaningful share reaching critical severity; the vendor's disclosures frequently acquire public exploit tooling, reflecting the appeal of operating-system flaws to security researchers and tool developers. The recurring weakness classes—including improper input validation, memory-buffer boundary violations, out-of-bounds writes, and information exposure—reflect the memory-safety and parsing challenges inherent to a large native codebase operating at the system level. Defenders should treat FreeBSD advisories as broadly applicable to deployed infrastructure and embedded systems; current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
588
Total CVEs
More Total CVEs than 100% of tracked vendors
1.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 76% of tracked vendors
6.4
Avg CVSS Score
Higher Avg CVSS Score than 39% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by FreeBSD over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 9, 1990
36 years ago
Most Recent CVE
Jun 27, 2026
27 days ago

Self-Reporting Analysis

Of all the CVEs published by FreeBSD as a CNA, 90.3% affect products that FreeBSD develops as a vendor.

90.3%
Self-reported: 186 (90.3%)
Third-party: 20 (9.7%)

Of all the CVEs published that affect products developed by FreeBSD, 31.6% are self-published by FreeBSD as a CNA.

31.6%
68.4%
Self-published: 186 (31.6%)
Other CNAs: 402 (68.4%)

Products(13 total)

Top CVEs

Signals from CVEs in this vendor scope (588 CVEs).

588 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2011-4862HIGH
Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and earlier, Heimdal 1.5.1 and earlier, GNU
Dec 25, 201110.092NOYES
CVE-2024-6387HIGH
A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauth
Jul 1, 20248.189NOYES
CVE-2020-13160CRITICAL
AnyDesk before 5.5.3 on Linux and FreeBSD has a format string vulnerability that can be exploited for remote code execution.
Jun 9, 20209.884NOYES
CVE-2023-48795MEDIUM
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packet
Dec 18, 20235.981NOYES
CVE-2003-0466CRITICAL
Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code, as demonstrated in wu-ftpd 2.5.0 throug
Aug 27, 20039.881NOYES
CVE-2007-3798CRITICAL
Integer overflow in print-bgp.c in the BGP dissector in tcpdump 3.9.6 and earlier allows remote attackers to execute arbitrary code via crafted TLVs in a BGP packet, related to an
Jul 16, 20079.878NOYES
CVE-2003-0694HIGH
The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c.
Oct 6, 200310.073NOYES
CVE-2006-0900HIGH
nfsd in FreeBSD 6.0 kernel allows remote attackers to cause a denial of service via a crafted NFS mount request, as demonstrated by the ProtoVer NFS test suite.
Feb 27, 20067.872NOYES
CVE-2005-0356MEDIUM
Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connect
May 31, 20055.069NOYES
CVE-2019-6111MEDIUM
An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses which files/directories are sent to the client. However, the s
Jan 31, 20195.967NOYES
View all 588 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products588 CVEs
11%
37%
46%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local102 (17.3%)
Network137 (23.3%)
Unknown333 (56.6%)
Physical3 (0.5%)
Adjacent Network13 (2.2%)
Attack Complexity
Low214 (36.4%)
High41 (7.0%)
Unknown333 (56.6%)
User Interaction
None246 (41.8%)
Unknown333 (56.6%)
Required9 (1.5%)
Privileges Required
Low100 (17.0%)
High10 (1.7%)
None145 (24.7%)
Unknown333 (56.6%)

Exploit Exposure

Signals from CVEs in this vendor scope (588 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
12 CVEs
2.0% of CVEs· 97th percentile
Nuclei
1 CVE
0.2% of CVEs· 95th percentile
ExploitDB
100 CVEs
17.0% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by FreeBSD.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by FreeBSD — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For FreeBSD's Products

View all 11 CNAs →

Top CWEs