Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
FreeBSD Number Of NVD 488 CRITICAL 29 HIGH 219 MEDIUM 185 LOW 55
URL https://www.freebsd.org/
Explanation Starting with FreeBSD 11, we are switching to a model of supporting major versions for at least 5 years.
We plan to release updates to the major versions every two years.
Older versions will be supported until three months after a new minor version is released.
Tag
  • BSD

Add Information URL
No Type Name URL
1 https://www.freebsd.org/security/
2 https://www.freebsd.org/releases/
3 https://www.freebsd.org/security/unsupported.html

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
331 FreeBSD 15 15.1 June 16, 2026 June 16, 2026 March 31, 2027 March 31, 2027 0 0 0 0
332 FreeBSD 13 13.2 April 11, 2023 April 13, 2021 April 13, 2021 3 29 6 0
333 FreeBSD 12 12.4 Dec. 5, 2022 Dec. 11, 2018 June 30, 2024 18 39 22 2
334 FreeBSD 11 11.4 June 16, 2020 Oct. 10, 2016 Sept. 30, 2021 21 48 40 2
335 FreeBSD 10 10.4 Jan. 20, 2014 Jan. 20, 2014 Feb. 28, 2015 7 40 46 2
336 FreeBSD 9 9.3 July 16, 2014 Jan. 10, 2012 Dec. 31, 2016 5 38 33 6
337 FreeBSD 8 8.4 June 9, 2013 Nov. 25, 2009 Aug. 1, 2015 5 38 33 6
338 FreeBSD 7 7.4 Feb. 24, 2011 Feb. 27, 2008 Feb. 28, 2013 5 37 31 5
339 FreeBSD 6 6.4 Nov. 28, 2008 Nov. 4, 2005 Nov. 30, 2010 6 43 46 15
340 FreeBSD 5 5.5 May 25, 2006 Nov. 6, 2004 May 31, 2008 7 42 50 18
341 FreeBSD 4 4.0 March 14, 2000 Jan. 31, 2007 8 67 61 23
342 FreeBSD 3 3.0 Oct. 16, 1998 Jan. 1, 1900 6 57 47 16
343 FreeBSD 2 2.0.5 Nov. 22, 1994 Jan. 1, 1900 6 51 41 10
344 FreeBSD 1 1.0 Oct. 1, 1993 Jan. 1, 1900 26 112 90 9
345 FreeBSD 0.4_1 0.4_1 Jan. 1, 1900 6 27 30 4
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
331 9.8
10.0
CRITICAL
Network
Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code, as demonstrated in wu-ftpd 2.5.0 through 2.6.2 via command… CWE-193
 Off-by-one Error
CVE-2003-0466 cpe:2.3:o:freebsd:freebsd:*:* 4.0 5.0 2024-02-9 00:50
2003-08-27
Show GitHub Exploit DB Packet Storm
332 -
7.2
HIGH Buffer overflow in the lprm command in the lprold lpr package on SuSE 7.1 through 7.3, OpenBSD 3.2 and earlier, and possibly other operating systems, allows local users to gain root privileges via lo… NVD-CWE-Other
CVE-2003-0144 cpe:2.3:o:freebsd:freebsd:2.2:*
cpe:2.3:o:freebsd:freebsd:2.2.6:*
cpe:2.3:o:freebsd:freebsd:2.2.5:*
cpe:2.3:o:…
2017-07-11 10:29
2003-03-31
Show GitHub Exploit DB Packet Storm
333 -
7.5
HIGH Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, all… NVD-CWE-Other
CVE-2003-0028 cpe:2.3:o:freebsd:freebsd:5.0:*
cpe:2.3:o:freebsd:freebsd:4.7:stable
cpe:2.3:o:freebsd:freebsd:4.7:release
cpe…
2020-01-22 00:45
2003-03-25
Show GitHub Exploit DB Packet Storm
334 -
5.0
MEDIUM ssl3_get_record in s3_pkt.c for OpenSSL before 0.9.7a and 0.9.6 before 0.9.6i does not perform a MAC computation if an incorrect block cipher padding is used, which causes an information leak (timing… CWE-203
 Information Exposure Through Discrepancy
CVE-2003-0078 cpe:2.3:o:freebsd:freebsd:5.0:*
cpe:2.3:o:freebsd:freebsd:4.7:*
cpe:2.3:o:freebsd:freebsd:4.6:*
cpe:2.3:o:free…
2024-02-15 00:07
2003-03-3
Show GitHub Exploit DB Packet Storm
335 -
7.5
HIGH Double-free vulnerability in CVS 1.11.4 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a malformed Directory request, as demonstrated by bypa… CWE-415
 Double Free
CVE-2003-0015 cpe:2.3:o:freebsd:freebsd:5.0:*
cpe:2.3:o:freebsd:freebsd:4.7:*
cpe:2.3:o:freebsd:freebsd:4.6:*
cpe:2.3:o:free…
2018-05-3 10:29
2003-02-7
Show GitHub Exploit DB Packet Storm
336 -
5.0
MEDIUM Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote attackers to obtain information from previous packets or kernel memory by using ma… CWE-200
Information Exposure
CVE-2003-0001 cpe:2.3:o:freebsd:freebsd:4.7:*
cpe:2.3:o:freebsd:freebsd:4.6:*
cpe:2.3:o:freebsd:freebsd:4.5:*
cpe:2.3:o:free…
2019-04-30 23:27
2003-01-17
Show GitHub Exploit DB Packet Storm
337 -
2.1
LOW The virtual memory management system in FreeBSD 4.5-RELEASE and earlier does not properly check the existence of a VM object during page invalidation, which allows local users to cause a denial of se… NVD-CWE-Other
CVE-2002-1667 cpe:2.3:o:freebsd:freebsd:4.5:stable
cpe:2.3:o:freebsd:freebsd:4.5:release
2017-07-11 10:29
2002-12-31
Show GitHub Exploit DB Packet Storm
338 -
2.1
LOW pkg_add in FreeBSD 4.2 through 4.4 creates a temporary directory with world-searchable permissions, which may allow local users to modify world-writable parts of the package during installation. NVD-CWE-Other
CVE-2002-1669 cpe:2.3:o:freebsd:freebsd:4.4:*
cpe:2.3:o:freebsd:freebsd:4.3:*
cpe:2.3:o:freebsd:freebsd:4.2:*
2017-07-11 10:29
2002-12-31
Show GitHub Exploit DB Packet Storm
339 -
1.2
LOW procfs on FreeBSD before 4.5 allows local users to cause a denial of service (kernel panic) by removing a file that the fstatfs function refers to. NVD-CWE-Other
CVE-2002-1674 cpe:2.3:o:freebsd:freebsd:4.5:*
cpe:2.3:o:freebsd:freebsd:4.4:*
cpe:2.3:o:freebsd:freebsd:4.3:*
cpe:2.3:o:free…
2017-07-11 10:29
2002-12-31
Show GitHub Exploit DB Packet Storm
340 -
3.7
LOW Race condition in exec in OpenBSD 4.0 and earlier, NetBSD 1.5.2 and earlier, and FreeBSD 4.4 and earlier allows local users to gain privileges by attaching a debugger to a process before the kernel h… NVD-CWE-Other
CVE-2002-2092 cpe:2.3:o:freebsd:freebsd:4.4:stable
cpe:2.3:o:freebsd:freebsd:4.4:releng
cpe:2.3:o:freebsd:freebsd:4.4:*
cpe:…
2017-12-19 11:29
2002-12-31
Show GitHub Exploit DB Packet Storm