NetBSD is a small, highly specialized Unix-like operating system and kernel that punches above its weight in the vulnerability landscape, with a deployment footprint spanning embedded systems, research infrastructure, and specialized server environments where its portability and modularity are valued. The vendor's disclosure profile is characterized by memory-safety and input-handling weakness classes—including buffer overflows, improper bounds checking, and input-validation flaws—that recur across the core kernel and foundational utilities such as ftpd and tnftpd, reflecting the low-level systems programming inherent to operating-system development. A notable share of NetBSD's vulnerabilities acquire public exploit code, underscoring the research and proof-of-concept interest in kernel-level flaws and the appeal of the platform to security practitioners. Defenders deploying NetBSD in production should prioritize patching memory-safety and protocol-parsing issues and maintain current tracking of the operating-system release cycle; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Netbsd over time
Signals from CVEs in this vendor scope (180 CVEs).
180 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-6387HIGH A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauth | Jul 1, 2024 | 8.1 | 89 | NO | YES |
CVE-2003-0466CRITICAL Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code, as demonstrated in wu-ftpd 2.5.0 throug | Aug 27, 2003 | 9.8 | 81 | NO | YES |
CVE-2002-1337HIGH Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related to sender and recipient header comments a | Mar 7, 2003 | 10.0 | 80 | NO | YES |
CVE-1999-0016MEDIUM Land IP denial of service. | Dec 1, 1997 | 5.0 | 79 | NO | YES |
The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain clear | Oct 15, 2014 | 3.4 | 78 | NO | YES |
CVE-2014-8517HIGH The fetch_url function in usr.bin/ftp/fetch.c in tnftp, as used in NetBSD 5.1 through 5.1.4, 5.2 through 5.2.2, 6.0 through 6.0.6, and 6.1 through 6.1.5 allows remote attackers to | Nov 17, 2014 | 7.5 | 74 | NO | YES |
CVE-2004-0230MEDIUM TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to persistent TCP connections by | Aug 18, 2004 | 5.0 | 74 | NO | YES |
CVE-2003-0694HIGH The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c. | Oct 6, 2003 | 10.0 | 73 | NO | YES |
CVE-2003-0001MEDIUM Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote attackers to obtain information from previous packets or kernel | Jan 17, 2003 | 5.0 | 67 | NO | YES |
CVE-1999-0046HIGH Buffer overflow of rlogin program using TERM environmental variable. | Feb 6, 1997 | 10.0 | 67 | NO | YES |
Signals from CVEs in this vendor scope (180 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Netbsd.
Media articles that mention a CVE ID that affects a product developed by Netbsd — matched by CVE ID, not by vendor name.