| FreeBSD | Number Of NVD | 488 | CRITICAL | 29 | HIGH | 219 | MEDIUM | 185 | LOW | 55 |
| URL | https://www.freebsd.org/ | ||||||||
|---|---|---|---|---|---|---|---|---|---|
| Explanation | Starting with FreeBSD 11, we are switching to a model of supporting major versions for at least 5 years. We plan to release updates to the major versions every two years. Older versions will be supported until three months after a new minor version is released. |
||||||||
| Tag | |||||||||
| No | Type | Name | URL |
|---|---|---|---|
| 1 | https://www.freebsd.org/security/ | ||
| 2 | https://www.freebsd.org/releases/ | ||
| 3 | https://www.freebsd.org/security/unsupported.html |
| No | Name | Latest Version | Release date | Initial release | Normal Support | Security Support Service Pack Support |
Extended for a fee |
Critical | High | Medium | Low |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 171 | FreeBSD 15 | 15.1 | June 16, 2026 | June 16, 2026 | March 31, 2027 | March 31, 2027 | 0 | 0 | 0 | 0 | |
| 172 | FreeBSD 13 | 13.2 | April 11, 2023 | April 13, 2021 | April 13, 2021 | 3 | 29 | 6 | 0 | ||
| 173 | FreeBSD 12 | 12.4 | Dec. 5, 2022 | Dec. 11, 2018 | June 30, 2024 | 18 | 39 | 22 | 2 | ||
| 174 | FreeBSD 11 | 11.4 | June 16, 2020 | Oct. 10, 2016 | Sept. 30, 2021 | 21 | 48 | 40 | 2 | ||
| 175 | FreeBSD 10 | 10.4 | Jan. 20, 2014 | Jan. 20, 2014 | Feb. 28, 2015 | 7 | 40 | 46 | 2 | ||
| 176 | FreeBSD 9 | 9.3 | July 16, 2014 | Jan. 10, 2012 | Dec. 31, 2016 | 5 | 38 | 33 | 6 | ||
| 177 | FreeBSD 8 | 8.4 | June 9, 2013 | Nov. 25, 2009 | Aug. 1, 2015 | 5 | 38 | 33 | 6 | ||
| 178 | FreeBSD 7 | 7.4 | Feb. 24, 2011 | Feb. 27, 2008 | Feb. 28, 2013 | 5 | 37 | 31 | 5 | ||
| 179 | FreeBSD 6 | 6.4 | Nov. 28, 2008 | Nov. 4, 2005 | Nov. 30, 2010 | 6 | 43 | 46 | 15 | ||
| 180 | FreeBSD 5 | 5.5 | May 25, 2006 | Nov. 6, 2004 | May 31, 2008 | 7 | 42 | 50 | 18 | ||
| 181 | FreeBSD 4 | 4.0 | March 14, 2000 | Jan. 31, 2007 | 8 | 67 | 61 | 23 | |||
| 182 | FreeBSD 3 | 3.0 | Oct. 16, 1998 | Jan. 1, 1900 | 6 | 57 | 47 | 16 | |||
| 183 | FreeBSD 2 | 2.0.5 | Nov. 22, 1994 | Jan. 1, 1900 | 6 | 51 | 41 | 10 | |||
| 184 | FreeBSD 1 | 1.0 | Oct. 1, 1993 | Jan. 1, 1900 | 26 | 112 | 90 | 9 | |||
| 185 | FreeBSD 0.4_1 | 0.4_1 | Jan. 1, 1900 | 6 | 27 | 30 | 4 |
| No | CVSS3 CVSS2 |
Level Attach Vector |
Title | CWE | CVE | cpe23Uri | or higher | or less | more than | less than | Update date Published date |
Show Affected | Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 171 |
8.1 6.8 |
HIGH
Network |
Heimdal before 7.4 allows remote attackers to impersonate services with Orpheus' Lyre attacks because it obtains service-principal names in a way that violates the Kerberos 5 protocol specification. … |
CWE-345
Insufficient Verification of Data Authenticity |
CVE-2017-11103 | cpe:2.3:o:freebsd:freebsd:-:* |
2024-11-21 12:07 2017-07-13 |
Show | GitHub Exploit DB Packet Storm | ||||
| 172 |
7.8 7.2 |
HIGH
Local |
Integer overflow in the bhyve hypervisor in FreeBSD 10.1, 10.2, 10.3, and 11.0 when configured with a large amount of guest memory, allows local users to gain privilege via a crafted device descripto… |
CWE-190
Integer Overflow or Wraparound |
CVE-2016-1889 |
cpe:2.3:o:freebsd:freebsd:11.0:* cpe:2.3:o:freebsd:freebsd:10.3:* cpe:2.3:o:freebsd:freebsd:10.2:* cpe:2.3:o:f… |
2024-11-21 11:47 2017-02-16 |
Show | GitHub Exploit DB Packet Storm | ||||
| 173 |
7.5 5.0 |
HIGH
Network |
The telnetd service in FreeBSD 9.3, 10.1, 10.2, 10.3, and 11.0 allows remote attackers to inject arguments to login and bypass authentication via vectors involving a "sequence of memory allocation fa… |
CWE-287
Improper Authentication |
CVE-2016-1888 |
cpe:2.3:o:freebsd:freebsd:9.3:* cpe:2.3:o:freebsd:freebsd:11.0:* cpe:2.3:o:freebsd:freebsd:10.3:* cpe:2.3:o:fr… |
2024-11-21 11:47 2017-02-16 |
Show | GitHub Exploit DB Packet Storm | ||||
| 174 |
7.8 7.2 |
HIGH
Local |
The issetugid system call in the Linux compatibility layer in FreeBSD 9.3, 10.1, and 10.2 allows local users to gain privilege via unspecified vectors. |
CWE-264
Permissions, Privileges, and Access Controls |
CVE-2016-1883 |
cpe:2.3:o:freebsd:freebsd:9.3:* cpe:2.3:o:freebsd:freebsd:10.2:* cpe:2.3:o:freebsd:freebsd:10.1:* |
2024-11-21 11:47 2017-02-16 |
Show | GitHub Exploit DB Packet Storm | ||||
| 175 |
7.8 7.2 |
HIGH
Local |
The kernel in FreeBSD 9.3, 10.1, and 10.2 allows local users to cause a denial of service (crash) or potentially gain privilege via a crafted Linux compatibility layer setgroups system call. |
CWE-264
Permissions, Privileges, and Access Controls |
CVE-2016-1881 |
cpe:2.3:o:freebsd:freebsd:9.3:* cpe:2.3:o:freebsd:freebsd:10.2:* cpe:2.3:o:freebsd:freebsd:10.1:* |
2024-11-21 11:47 2017-02-16 |
Show | GitHub Exploit DB Packet Storm | ||||
| 176 |
7.8 7.2 |
HIGH
Local |
The Linux compatibility layer in the kernel in FreeBSD 9.3, 10.1, and 10.2 allows local users to read portions of kernel memory and potentially gain privilege via unspecified vectors, related to "han… |
CWE-264
Permissions, Privileges, and Access Controls |
CVE-2016-1880 |
cpe:2.3:o:freebsd:freebsd:9.3:* cpe:2.3:o:freebsd:freebsd:10.2:* cpe:2.3:o:freebsd:freebsd:10.1:* |
2024-11-21 11:47 2017-02-16 |
Show | GitHub Exploit DB Packet Storm | ||||
| 177 |
5.5 2.1 |
MEDIUM
Local |
bsnmpd, as used in FreeBSD 9.3, 10.1, and 10.2, uses world-readable permissions on the snmpd.config file, which allows local users to obtain the secret key for USM authentication by reading the file. |
CWE-200
Information Exposure |
CVE-2015-5677 |
cpe:2.3:o:freebsd:freebsd:9.3:* cpe:2.3:o:freebsd:freebsd:10.2:* cpe:2.3:o:freebsd:freebsd:10.1:* |
2024-11-21 11:33 2017-02-8 |
Show | GitHub Exploit DB Packet Storm | ||||
| 178 |
5.9 4.3 |
MEDIUM
Network |
ntpd in NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to cause a denial of service (NULL pointer dereference) via a ntpdc reslist command. |
CWE-476
NULL Pointer Dereference |
CVE-2015-7977 |
cpe:2.3:o:freebsd:freebsd:9.3:p9 cpe:2.3:o:freebsd:freebsd:9.3:p8 cpe:2.3:o:freebsd:freebsd:9.3:p7 cpe:2.3:o:f… |
2024-11-21 11:37 2017-01-31 |
Show | GitHub Exploit DB Packet Storm | ||||
| 179 |
5.3 5.0 |
MEDIUM
Network |
The MATCH_ASSOC function in NTP before version 4.2.8p9 and 4.3.x before 4.3.92 allows remote attackers to cause an out-of-bounds reference via an addpeer request with a large hmode value. |
CWE-125
Out-of-bounds Read |
CVE-2016-2518 |
cpe:2.3:o:freebsd:freebsd:9.3:p9 cpe:2.3:o:freebsd:freebsd:9.3:p8 cpe:2.3:o:freebsd:freebsd:9.3:p7 cpe:2.3:o:f… |
2024-11-21 11:48 2017-01-31 |
Show | GitHub Exploit DB Packet Storm | ||||
| 180 |
6.5 5.8 |
MEDIUM
Network |
NTP before 4.2.8p6 and 4.3.x before 4.3.90, when configured in broadcast mode, allows man-in-the-middle attackers to conduct replay attacks by sniffing the network. |
CWE-254
7PK - Security Features |
CVE-2015-7973 |
cpe:2.3:o:freebsd:freebsd:9.3:p9 cpe:2.3:o:freebsd:freebsd:9.3:p8 cpe:2.3:o:freebsd:freebsd:9.3:p7 cpe:2.3:o:f… |
10.0 | 10.1 |
2024-11-21 11:37 2017-01-31 |
Show | GitHub Exploit DB Packet Storm |