FreeBSD is among the most prominent operating systems in the vulnerability landscape, supporting a wide range of deployment contexts from embedded systems and servers to high-performance network infrastructure, despite a modest product count. Its vulnerability profile concentrates in the core FreeBSD kernel and system utilities, alongside widely embedded components such as libarchive, and skews toward serious outcomes with a meaningful share reaching critical severity; the vendor's disclosures frequently acquire public exploit tooling, reflecting the appeal of operating-system flaws to security researchers and tool developers. The recurring weakness classes—including improper input validation, memory-buffer boundary violations, out-of-bounds writes, and information exposure—reflect the memory-safety and parsing challenges inherent to a large native codebase operating at the system level. Defenders should treat FreeBSD advisories as broadly applicable to deployed infrastructure and embedded systems; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by FreeBSD over time
Of all the CVEs published by FreeBSD as a CNA, 90.3% affect products that FreeBSD develops as a vendor.
Of all the CVEs published that affect products developed by FreeBSD, 31.6% are self-published by FreeBSD as a CNA.
Signals from CVEs in this vendor scope (588 CVEs).
588 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-4862HIGH Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and earlier, Heimdal 1.5.1 and earlier, GNU | Dec 25, 2011 | 10.0 | 92 | NO | YES |
CVE-2024-6387HIGH A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauth | Jul 1, 2024 | 8.1 | 89 | NO | YES |
CVE-2020-13160CRITICAL AnyDesk before 5.5.3 on Linux and FreeBSD has a format string vulnerability that can be exploited for remote code execution. | Jun 9, 2020 | 9.8 | 84 | NO | YES |
CVE-2023-48795MEDIUM The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packet | Dec 18, 2023 | 5.9 | 81 | NO | YES |
CVE-2003-0466CRITICAL Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code, as demonstrated in wu-ftpd 2.5.0 throug | Aug 27, 2003 | 9.8 | 81 | NO | YES |
CVE-2007-3798CRITICAL Integer overflow in print-bgp.c in the BGP dissector in tcpdump 3.9.6 and earlier allows remote attackers to execute arbitrary code via crafted TLVs in a BGP packet, related to an | Jul 16, 2007 | 9.8 | 78 | NO | YES |
CVE-2003-0694HIGH The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c. | Oct 6, 2003 | 10.0 | 73 | NO | YES |
CVE-2006-0900HIGH nfsd in FreeBSD 6.0 kernel allows remote attackers to cause a denial of service via a crafted NFS mount request, as demonstrated by the ProtoVer NFS test suite. | Feb 27, 2006 | 7.8 | 72 | NO | YES |
CVE-2005-0356MEDIUM Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connect | May 31, 2005 | 5.0 | 69 | NO | YES |
CVE-2019-6111MEDIUM An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses which files/directories are sent to the client. However, the s | Jan 31, 2019 | 5.9 | 67 | NO | YES |
Signals from CVEs in this vendor scope (588 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by FreeBSD.
Media articles that mention a CVE ID that affects a product developed by FreeBSD — matched by CVE ID, not by vendor name.