Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Netbsd

First CVE: Aug 21, 1996Active for: 30 yearsTotal CVEs: 180
49.3
VTI Score
High

NetBSD is a small, highly specialized Unix-like operating system and kernel that punches above its weight in the vulnerability landscape, with a deployment footprint spanning embedded systems, research infrastructure, and specialized server environments where its portability and modularity are valued. The vendor's disclosure profile is characterized by memory-safety and input-handling weakness classes—including buffer overflows, improper bounds checking, and input-validation flaws—that recur across the core kernel and foundational utilities such as ftpd and tnftpd, reflecting the low-level systems programming inherent to operating-system development. A notable share of NetBSD's vulnerabilities acquire public exploit code, underscoring the research and proof-of-concept interest in kernel-level flaws and the appeal of the platform to security practitioners. Defenders deploying NetBSD in production should prioritize patching memory-safety and protocol-parsing issues and maintain current tracking of the operating-system release cycle; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
180
Total CVEs
More Total CVEs than 100% of tracked vendors
1.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 76% of tracked vendors
5.7
Avg CVSS Score
Higher Avg CVSS Score than 25% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Netbsd over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 21, 1996
29 years ago
Most Recent CVE
Jul 1, 2024
754 days ago

Products(5 total)

Top CVEs

Signals from CVEs in this vendor scope (180 CVEs).

180 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-6387HIGH
A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauth
Jul 1, 20248.189NOYES
CVE-2003-0466CRITICAL
Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code, as demonstrated in wu-ftpd 2.5.0 throug
Aug 27, 20039.881NOYES
CVE-2002-1337HIGH
Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related to sender and recipient header comments a
Mar 7, 200310.080NOYES
CVE-1999-0016MEDIUM
Land IP denial of service.
Dec 1, 19975.079NOYES
CVE-2014-3566LOW
The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain clear
Oct 15, 20143.478NOYES
CVE-2014-8517HIGH
The fetch_url function in usr.bin/ftp/fetch.c in tnftp, as used in NetBSD 5.1 through 5.1.4, 5.2 through 5.2.2, 6.0 through 6.0.6, and 6.1 through 6.1.5 allows remote attackers to
Nov 17, 20147.574NOYES
CVE-2004-0230MEDIUM
TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to persistent TCP connections by
Aug 18, 20045.074NOYES
CVE-2003-0694HIGH
The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c.
Oct 6, 200310.073NOYES
CVE-2003-0001MEDIUM
Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote attackers to obtain information from previous packets or kernel
Jan 17, 20035.067NOYES
CVE-1999-0046HIGH
Buffer overflow of rlogin program using TERM environmental variable.
Feb 6, 199710.067NOYES
View all 180 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products180 CVEs
20%
40%
37%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local3 (1.7%)
Network15 (8.3%)
Unknown160 (88.9%)
Physical0 (0.0%)
Adjacent Network2 (1.1%)
Attack Complexity
Low17 (9.4%)
High3 (1.7%)
Unknown160 (88.9%)
User Interaction
None19 (10.6%)
Unknown160 (88.9%)
Required1 (0.6%)
Privileges Required
Low3 (1.7%)
High0 (0.0%)
None17 (9.4%)
Unknown160 (88.9%)

Exploit Exposure

Signals from CVEs in this vendor scope (180 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
5 CVEs
2.8% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
45 CVEs
25.0% of CVEs· 78th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Netbsd.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Netbsd — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Netbsd's Products

View all 7 CNAs →

Top CWEs