Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
FreeBSD Number Of NVD 488 CRITICAL 29 HIGH 219 MEDIUM 185 LOW 55
URL https://www.freebsd.org/
Explanation Starting with FreeBSD 11, we are switching to a model of supporting major versions for at least 5 years.
We plan to release updates to the major versions every two years.
Older versions will be supported until three months after a new minor version is released.
Tag
  • BSD

Add Information URL
No Type Name URL
1 https://www.freebsd.org/security/
2 https://www.freebsd.org/releases/
3 https://www.freebsd.org/security/unsupported.html

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
241 FreeBSD 15 15.1 June 16, 2026 June 16, 2026 March 31, 2027 March 31, 2027 0 0 0 0
242 FreeBSD 13 13.2 April 11, 2023 April 13, 2021 April 13, 2021 3 29 6 0
243 FreeBSD 12 12.4 Dec. 5, 2022 Dec. 11, 2018 June 30, 2024 18 39 22 2
244 FreeBSD 11 11.4 June 16, 2020 Oct. 10, 2016 Sept. 30, 2021 21 48 40 2
245 FreeBSD 10 10.4 Jan. 20, 2014 Jan. 20, 2014 Feb. 28, 2015 7 40 46 2
246 FreeBSD 9 9.3 July 16, 2014 Jan. 10, 2012 Dec. 31, 2016 5 38 33 6
247 FreeBSD 8 8.4 June 9, 2013 Nov. 25, 2009 Aug. 1, 2015 5 38 33 6
248 FreeBSD 7 7.4 Feb. 24, 2011 Feb. 27, 2008 Feb. 28, 2013 5 37 31 5
249 FreeBSD 6 6.4 Nov. 28, 2008 Nov. 4, 2005 Nov. 30, 2010 6 43 46 15
250 FreeBSD 5 5.5 May 25, 2006 Nov. 6, 2004 May 31, 2008 7 42 50 18
251 FreeBSD 4 4.0 March 14, 2000 Jan. 31, 2007 8 67 61 23
252 FreeBSD 3 3.0 Oct. 16, 1998 Jan. 1, 1900 6 57 47 16
253 FreeBSD 2 2.0.5 Nov. 22, 1994 Jan. 1, 1900 6 51 41 10
254 FreeBSD 1 1.0 Oct. 1, 1993 Jan. 1, 1900 26 112 90 9
255 FreeBSD 0.4_1 0.4_1 Jan. 1, 1900 6 27 30 4
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
241 -
7.2
HIGH The _rtld function in the Run-Time Link-Editor (rtld) in libexec/rtld-elf/rtld.c in FreeBSD 7.1 and 8.0 does not clear the (1) LD_LIBMAP, (2) LD_LIBRARY_PATH, (3) LD_LIBMAP_DISABLE, (4) LD_DEBUG, and… CWE-264
Permissions, Privileges, and Access Controls
CVE-2009-4147 cpe:2.3:o:freebsd:freebsd:8.0:*
cpe:2.3:o:freebsd:freebsd:7.1:*
2026-04-23 09:35
2009-12-3
Show GitHub Exploit DB Packet Storm
242 -
7.2
HIGH The _rtld function in the Run-Time Link-Editor (rtld) in libexec/rtld-elf/rtld.c in FreeBSD 7.1, 7.2, and 8.0 does not clear the LD_PRELOAD environment variable, which allows local users to gain priv… CWE-264
Permissions, Privileges, and Access Controls
CVE-2009-4146 cpe:2.3:o:freebsd:freebsd:8.0:*
cpe:2.3:o:freebsd:freebsd:7.2:*
cpe:2.3:o:freebsd:freebsd:7.1:*
2026-04-23 09:35
2009-12-3
Show GitHub Exploit DB Packet Storm
243 -
6.9
MEDIUM Race condition in the Pipe (IPC) close function in FreeBSD 6.3 and 6.4 allows local users to cause a denial of service (crash) or gain privileges via vectors related to kqueues, which triggers a use … CWE-362
Race Condition
CVE-2009-3527 cpe:2.3:o:freebsd:freebsd:6.4:*
cpe:2.3:o:freebsd:freebsd:6.3:*
2026-04-23 09:35
2009-10-7
Show GitHub Exploit DB Packet Storm
244 -
4.7
MEDIUM The IATA (ata) driver in FreeBSD 6.0 and 8.0, when read access to /dev is available, allows local users to cause a denial of service (kernel panic) via a certain IOCTL request with a large count, whi… CWE-264
Permissions, Privileges, and Access Controls
CVE-2009-2649 cpe:2.3:o:freebsd:freebsd:8.0:*
cpe:2.3:o:freebsd:freebsd:6.0:*
2026-04-23 09:35
2009-07-31
Show GitHub Exploit DB Packet Storm
245 -
6.8
MEDIUM Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the (2) gdtoa (aka new dtoa) implementation in gdtoa/misc.c in libc, as used in multiple operating systems and products in… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2009-0689 cpe:2.3:o:freebsd:freebsd:7.2:stable
cpe:2.3:o:freebsd:freebsd:7.2:pre-release
cpe:2.3:o:freebsd:freebsd:7.2:*
2026-04-23 09:35
2009-07-1
Show GitHub Exploit DB Packet Storm
246 -
3.6
LOW FreeBSD 6.3, 6.4, 7.1, and 7.2 does not enforce permissions on the SIOCSIFINFO_IN6 IOCTL, which allows local users to modify or disable IPv6 network interfaces, as demonstrated by modifying the MTU. CWE-264
Permissions, Privileges, and Access Controls
CVE-2009-2208 cpe:2.3:o:freebsd:freebsd:7.2:stable
cpe:2.3:o:freebsd:freebsd:7.2:pre-release
cpe:2.3:o:freebsd:freebsd:7.2:*
2026-04-23 09:35
2009-06-25
Show GitHub Exploit DB Packet Storm
247 -
4.9
MEDIUM Integer overflow in the pipe_build_write_buffer function (sys/kern/sys_pipe.c) in the direct write optimization feature in the pipe implementation in FreeBSD 7.1 through 7.2 and 6.3 through 6.4 allow… CWE-189
Numeric Errors
CVE-2009-1935 cpe:2.3:o:freebsd:freebsd:7.2:pre-release
cpe:2.3:o:freebsd:freebsd:7.2:*
cpe:2.3:o:freebsd:freebsd:7.1:stable
2026-04-23 09:35
2009-06-19
Show GitHub Exploit DB Packet Storm
248 -
4.9
MEDIUM The db interface in libc in FreeBSD 6.3, 6.4, 7.0, 7.1, and 7.2-PRERELEASE does not properly initialize memory for Berkeley DB 1.85 database structures, which allows local users to obtain sensitive i… CWE-20
 Improper Input Validation 
CVE-2009-1436 cpe:2.3:o:freebsd:freebsd:7.2:pre-release
cpe:2.3:o:freebsd:freebsd:7.1:release-p5
cpe:2.3:o:freebsd:freebsd:7.1:…
2026-04-23 09:35
2009-04-28
Show GitHub Exploit DB Packet Storm
249 -
7.2
HIGH The ktimer feature (sys/kern/kern_time.c) in FreeBSD 7.0, 7.1, and 7.2 allows local users to overwrite arbitrary kernel memory via an out-of-bounds timer value. CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2009-1041 cpe:2.3:o:freebsd:freebsd:7.2:*
cpe:2.3:o:freebsd:freebsd:7.1:stable
cpe:2.3:o:freebsd:freebsd:7.1:release-p2
2026-04-23 09:35
2009-03-26
Show GitHub Exploit DB Packet Storm
250 -
9.3
HIGH sys_term.c in telnetd in FreeBSD 7.0-RELEASE and other 7.x versions deletes dangerous environment variables with a method that was valid only in older FreeBSD distributions, which might allow remote … CWE-16
CWE-264
Configuration
Permissions, Privileges, and Access Controls
CVE-2009-0641 cpe:2.3:o:freebsd:freebsd:7.1:rc1
cpe:2.3:o:freebsd:freebsd:7.1:*
cpe:2.3:o:freebsd:freebsd:7.0_releng:*
cpe:2…
2026-04-23 09:35
2009-02-20
Show GitHub Exploit DB Packet Storm