<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – FreeBSD (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/freebsd.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/freebsd-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – FreeBSD (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:47 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2026-45158 – OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.8, unsa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45158</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45158</guid>
    <pubDate>Wed, 13 May 2026 22:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-45158</strong></p>
  <p>OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.8, unsanitized user input is passed to the DHCP configuration of the configured interface, which is processed by a shell script, allowing remote code execution as root on the underlying operating system. This vulnerability is fixed in 26.1.8.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-88</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45158">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-44194 – OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.8, an a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44194</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44194</guid>
    <pubDate>Wed, 13 May 2026 22:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-44194</strong></p>
  <p>OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.8, an authenticated Remote Code Execution (RCE) vulnerability in the OPNsense core allows a user with user-management privileges to execute arbitrary system commands as root. An attacker can bypass input validation by formatting their malicious payload as a compliant email address, allowing shell commands to reach the underl…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44194">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-44193 – OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.7, the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44193</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44193</guid>
    <pubDate>Wed, 13 May 2026 22:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-44193</strong></p>
  <p>OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.7, the XMLRPC method opnsense.restore_config_section fails to sanitize user supplied input leading to Remote Code Execution. This vulnerability is fixed in 26.1.7.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-88</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44193">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34578 – OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.6, OPNs...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34578</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34578</guid>
    <pubDate>Thu, 09 Apr 2026 15:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34578</strong></p>
  <p>OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.6, OPNsense's LDAP authentication connector passes the login username directly into an LDAP search filter without calling ldap_escape(). An unauthenticated attacker can inject LDAP filter metacharacters into the username field of the WebGUI login page to enumerate valid LDAP usernames in the configured directory. When the LD…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-90</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34578">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-4747 – Each RPCSEC_GSS data packet is validated by a routine which checks a signature i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4747</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4747</guid>
    <pubDate>Thu, 26 Mar 2026 07:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-4747</strong></p>
  <p>Each RPCSEC_GSS data packet is validated by a routine which checks a signature in the packet.  This routine copies a portion of the packet into a stack buffer, but fails to ensure that the buffer is sufficiently large, and a malicious client can trigger a stack overflow.  Notably, this does not require the client to authenticate itself first.  As kgssapi.ko's RPCSEC_GSS implementation is vulnerab…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4747">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-4247 – When a challenge ACK is to be sent tcp_respond() constructs and sends the challe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4247</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4247</guid>
    <pubDate>Thu, 26 Mar 2026 07:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-4247</strong></p>
  <p>When a challenge ACK is to be sent tcp_respond() constructs and sends the challenge ACK and consumes the mbuf that is passed in.  When no challenge ACK should be sent the function returns and leaks the mbuf.  If an attacker is either on path with an established TCP connection, or can themselves establish a TCP connection, to an affected FreeBSD machine, they can easily craft and send packets whic…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-401</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4247">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-7589 – A signal handler in sshd(8) may call a logging function that is not async-signal...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-7589</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-7589</guid>
    <pubDate>Mon, 12 Aug 2024 13:38:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-7589</strong></p>
  <p>A signal handler in sshd(8) may call a logging function that is not async-signal-safe.  The signal handler is invoked when a client does not authenticate within the LoginGraceTime seconds (120 by default).  This signal handler executes in the context of the sshd(8)'s privileged code, which is not sandboxed and runs with full root privileges.  This issue is another instance of the problem in CVE-2…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-7589">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-29937 – NFS in a BSD derived codebase, as used in OpenBSD through 7.4 and FreeBSD throug...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-29937</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-29937</guid>
    <pubDate>Thu, 11 Apr 2024 01:25:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-29937</strong></p>
  <p>NFS in a BSD derived codebase, as used in OpenBSD through 7.4 and FreeBSD through 14.0-RELEASE, allows remote attackers to execute arbitrary code via a bug that is unrelated to memory corruption.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-29937">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-23088 – The 802.11 beacon handling routine failed to validate the length of an IEEE 802...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-23088</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-23088</guid>
    <pubDate>Thu, 15 Feb 2024 05:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-23088</strong></p>
  <p>The 802.11 beacon handling routine failed to validate the length of an IEEE 802.11s Mesh ID before copying it to a heap-allocated buffer.  While a FreeBSD Wi-Fi client is in scanning mode (i.e., not associated with a SSID) a malicious beacon frame may overwrite kernel memory, leading to remote code execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23088">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-23087 – The e1000 network adapters permit a variety of modifications to an Ethernet pack...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-23087</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-23087</guid>
    <pubDate>Thu, 15 Feb 2024 05:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-23087</strong></p>
  <p>The e1000 network adapters permit a variety of modifications to an Ethernet packet when it is being transmitted.  These include the insertion of IP and TCP checksums, insertion of an Ethernet VLAN header, and TCP segmentation offload ("TSO").  The e1000 device model uses an on-stack buffer to generate the modified packet header when simulating these modifications on transmitted packets.  When che…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23087">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-6534 – In versions of FreeBSD 14.0-RELEASE before 14-RELEASE-p2, FreeBSD 13.2-RELEASE b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-6534</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-6534</guid>
    <pubDate>Wed, 13 Dec 2023 09:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-6534</strong></p>
  <p>In versions of FreeBSD 14.0-RELEASE before 14-RELEASE-p2, FreeBSD 13.2-RELEASE before 13.2-RELEASE-p7 and FreeBSD 12.4-RELEASE before 12.4-RELEASE-p9, the pf(4) packet filter incorrectly validates TCP sequence numbers.  This could allow a malicious actor to execute a denial-of-service attack against hosts behind the firewall.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-6534">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-5978 – In versions of FreeBSD 13-RELEASE before 13-RELEASE-p5, under certain circumstan...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-5978</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-5978</guid>
    <pubDate>Wed, 08 Nov 2023 09:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-5978</strong></p>
  <p>In versions of FreeBSD 13-RELEASE before 13-RELEASE-p5, under certain circumstances the cap_net libcasper(3) service incorrectly validates that updated constraints are strictly subsets of the active constraints.  When only a list of resolvable domain names was specified without setting any other limitations, an application could submit a new list of domains including include entries not previousl…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-5978">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-5941 – In versions of FreeBSD 12.4-RELEASE prior to 12.4-RELEASE-p7 and FreeBSD 13.2-RE...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-5941</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-5941</guid>
    <pubDate>Wed, 08 Nov 2023 09:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-5941</strong></p>
  <p>In versions of FreeBSD 12.4-RELEASE prior to 12.4-RELEASE-p7 and FreeBSD 13.2-RELEASE prior to 13.2-RELEASE-p5 the __sflush() stdio function in libc does not correctly update FILE objects' write space members for write-buffered streams when the write(2) system call returns an error.  Depending on the nature of an application that calls libc's stdio functions and the presence of errors returned fr…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-131</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-5941">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-3326 – pam_krb5 authenticates a user by essentially running kinit with the password, ge...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-3326</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-3326</guid>
    <pubDate>Thu, 22 Jun 2023 17:15:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-3326</strong></p>
  <p>pam_krb5 authenticates a user by essentially running kinit with the password, getting a ticket-granting ticket (tgt) from the Kerberos KDC (Key Distribution Center) over the network, as a way to verify the password. However, if a keytab is not provisioned on the system, pam_krb5 has no way to validate the response from the KDC, and essentially trusts the tgt provided over the network as being val…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-303</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-3326">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-45188 – Netatalk through 3.1.13 has an afp_getappl heap-based buffer overflow resulting ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-45188</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-45188</guid>
    <pubDate>Sat, 12 Nov 2022 05:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-45188</strong></p>
  <p>Netatalk through 3.1.13 has an afp_getappl heap-based buffer overflow resulting in code execution via a crafted .appl file. This provides remote root access on some platforms such as FreeBSD (used for TrueNAS).</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-45188">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-40895 – In certain Nedi products, a vulnerability in the web UI of NeDi login &amp; Communit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-40895</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-40895</guid>
    <pubDate>Thu, 06 Oct 2022 18:16:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-40895</strong></p>
  <p>In certain Nedi products, a vulnerability in the web UI of NeDi login & Community login could allow an unauthenticated, remote attacker to affect the integrity of a device via a User Enumeration vulnerability. The vulnerability is due to insecure design, where a difference in forgot password utility could allow an attacker to determine if the user is valid or not, enabling a brute force attack wi…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-203</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-40895">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-32264 – sys/netinet/tcp_timer.h in FreeBSD before 7.0 contains a denial-of-service (DoS)...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-32264</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-32264</guid>
    <pubDate>Tue, 06 Sep 2022 18:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-32264</strong></p>
  <p>sys/netinet/tcp_timer.h in FreeBSD before 7.0 contains a denial-of-service (DoS) vulnerability due to improper handling of TSopt on TCP connections. NOTE: This vulnerability only affects products that are no longer supported by the maintainer</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-755</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-32264">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-29632 – In FreeBSD 13.0-STABLE before n247428-9352de39c3dc, 12.2-STABLE before r370674, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-29632</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-29632</guid>
    <pubDate>Tue, 18 Jan 2022 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-29632</strong></p>
  <p>In FreeBSD 13.0-STABLE before n247428-9352de39c3dc, 12.2-STABLE before r370674, 13.0-RELEASE before p6, and 12.2-RELEASE before p12, certain conditions involving use of the highlight buffer while text is scrolling on the console, console data may overwrite data structures associated with the system console or other kernel memory.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-29632">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-29630 – In FreeBSD 13.0-STABLE before n246938-0729ba2f49c9, 12.2-STABLE before r370383, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-29630</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-29630</guid>
    <pubDate>Mon, 30 Aug 2021 19:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-29630</strong></p>
  <p>In FreeBSD 13.0-STABLE before n246938-0729ba2f49c9, 12.2-STABLE before r370383, 11.4-STABLE before r370381, 13.0-RELEASE before p4, 12.2-RELEASE before p10, and 11.4-RELEASE before p13, the ggatec daemon does not validate the size of a response before writing it to a fixed-sized buffer allowing a malicious attacker in a privileged network position to overwrite the stack of ggatec and potentially…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-29630">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-29631 – In FreeBSD 13.0-STABLE before n246941-20f96f215562, 12.2-STABLE before r370400, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-29631</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-29631</guid>
    <pubDate>Mon, 30 Aug 2021 18:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-29631</strong></p>
  <p>In FreeBSD 13.0-STABLE before n246941-20f96f215562, 12.2-STABLE before r370400, 11.4-STABLE before r370399, 13.0-RELEASE before p4, 12.2-RELEASE before p10, and 11.4-RELEASE before p13, certain VirtIO-based device models in bhyve failed to handle errors when fetching I/O descriptors. A malicious guest may cause the device model to operate on uninitialized I/O vectors leading to memory corruption,…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-29631">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2010-4816 – It was found in FreeBSD 8.0, 6.3 and 4.9, and OpenBSD 4.6 that a null pointer de...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-4816</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-4816</guid>
    <pubDate>Tue, 22 Jun 2021 14:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2010-4816</strong></p>
  <p>It was found in FreeBSD 8.0, 6.3 and 4.9, and OpenBSD 4.6 that a null pointer dereference in ftpd/popen.c may lead to remote denial of service of the ftpd service.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-4816">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-7469 – In FreeBSD 12.2-STABLE before r367402, 11.4-STABLE before r368202, 12.2-RELEASE ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7469</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7469</guid>
    <pubDate>Fri, 04 Jun 2021 12:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-7469</strong></p>
  <p>In FreeBSD 12.2-STABLE before r367402, 11.4-STABLE before r368202, 12.2-RELEASE before p1, 12.1-RELEASE before p11 and 11.4-RELEASE before p5 the handler for a routing option caches a pointer into the packet buffer holding the ICMPv6 message. However, when processing subsequent options the packet buffer may be freed, rendering the cached pointer invalid. The network stack may later dereference th…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7469">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-29629 – In FreeBSD 13.0-STABLE before n245765-bec0d2c9c841, 12.2-STABLE before r369859, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-29629</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-29629</guid>
    <pubDate>Fri, 28 May 2021 15:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-29629</strong></p>
  <p>In FreeBSD 13.0-STABLE before n245765-bec0d2c9c841, 12.2-STABLE before r369859, 11.4-STABLE before r369866, 13.0-RELEASE before p1, 12.2-RELEASE before p7, and 11.4-RELEASE before p10, missing message validation in libradius(3) could allow malicious clients or servers to trigger denial of service in vulnerable servers or clients respectively.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-29629">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-29628 – In FreeBSD 13.0-STABLE before n245764-876ffe28796c, 12.2-STABLE before r369857, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-29628</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-29628</guid>
    <pubDate>Fri, 28 May 2021 15:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-29628</strong></p>
  <p>In FreeBSD 13.0-STABLE before n245764-876ffe28796c, 12.2-STABLE before r369857, 13.0-RELEASE before p1, and 12.2-RELEASE before p7, a system call triggering a fault could cause SMAP protections to be disabled for the duration of the system call. This weakness could be combined with other kernel bugs to craft an exploit.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-29628">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-29627 – In FreeBSD 13.0-STABLE before n245050, 12.2-STABLE before r369525, 13.0-RC4 befo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-29627</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-29627</guid>
    <pubDate>Wed, 07 Apr 2021 15:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-29627</strong></p>
  <p>In FreeBSD 13.0-STABLE before n245050, 12.2-STABLE before r369525, 13.0-RC4 before p0, and 12.2-RELEASE before p6, listening socket accept filters implementing the accf_create callback incorrectly freed a process supplied argument string. Additional operations on the socket can lead to a double free or use after free.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-415</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-29627">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-25584 – In FreeBSD 13.0-STABLE before n245118, 12.2-STABLE before r369552, 11.4-STABLE b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-25584</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-25584</guid>
    <pubDate>Wed, 07 Apr 2021 15:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-25584</strong></p>
  <p>In FreeBSD 13.0-STABLE before n245118, 12.2-STABLE before r369552, 11.4-STABLE before r369560, 13.0-RC5 before p1, 12.2-RELEASE before p6, and 11.4-RELEASE before p9, a superuser inside a FreeBSD jail configured with the non-default allow.mount permission could cause a race condition between the lookup of ".." and remounting a filesystem, allowing access to filesystem hierarchy outside of the jai…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-25584">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-25583 – In FreeBSD 12.2-STABLE before r368250, 11.4-STABLE before r368253, 12.2-RELEASE ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-25583</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-25583</guid>
    <pubDate>Mon, 29 Mar 2021 20:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-25583</strong></p>
  <p>In FreeBSD 12.2-STABLE before r368250, 11.4-STABLE before r368253, 12.2-RELEASE before p1, 12.1-RELEASE before p11 and 11.4-RELEASE before p5 when processing a DNSSL option, rtsold(8) decodes domain name labels per an encoding specified in RFC 1035 in which the first octet of each label contains the label's length. rtsold(8) did not validate label lengths correctly and could overflow the destinat…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-25583">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-25577 – In FreeBSD 12.2-STABLE before r368250, 11.4-STABLE before r368253, 12.2-RELEASE ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-25577</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-25577</guid>
    <pubDate>Mon, 29 Mar 2021 20:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-25577</strong></p>
  <p>In FreeBSD 12.2-STABLE before r368250, 11.4-STABLE before r368253, 12.2-RELEASE before p1, 12.1-RELEASE before p11 and 11.4-RELEASE before p5 rtsold(8) does not verify that the RDNSS option does not extend past the end of the received packet before processing its contents. While the kernel currently ignores such malformed packets, it passes them to userspace programs. Any programs expecting the k…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-25577">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-7468 – In FreeBSD 12.2-STABLE before r365772, 11.4-STABLE before r365773, 12.1-RELEASE ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7468</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7468</guid>
    <pubDate>Fri, 26 Mar 2021 21:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-7468</strong></p>
  <p>In FreeBSD 12.2-STABLE before r365772, 11.4-STABLE before r365773, 12.1-RELEASE before p10, 11.4-RELEASE before p4 and 11.3-RELEASE before p14 a ftpd(8) bug in the implementation of the file system sandbox, combined with capabilities available to an authenticated FTP user, can be used to escape the file system restriction configured in ftpchroot(5). Moreover, the bug allows a malicious client to…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7468">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-7467 – In FreeBSD 12.2-STABLE before r365767, 11.4-STABLE before r365769, 12.1-RELEASE ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7467</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7467</guid>
    <pubDate>Fri, 26 Mar 2021 21:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-7467</strong></p>
  <p>In FreeBSD 12.2-STABLE before r365767, 11.4-STABLE before r365769, 12.1-RELEASE before p10, 11.4-RELEASE before p4 and 11.3-RELEASE before p14 a number of AMD virtualization instructions operate on host physical addresses, are not subject to nested page table translation, and guest use of these instructions was not trapped.</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7467">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-7461 – In FreeBSD 12.1-STABLE before r365010, 11.4-STABLE before r365011, 12.1-RELEASE ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7461</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7461</guid>
    <pubDate>Fri, 26 Mar 2021 21:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-7461</strong></p>
  <p>In FreeBSD 12.1-STABLE before r365010, 11.4-STABLE before r365011, 12.1-RELEASE before p9, 11.4-RELEASE before p3, and 11.3-RELEASE before p13, dhclient(8) fails to handle certain malformed input related to handling of DHCP option 119 resulting a heap overflow. The heap overflow could in principle be exploited to achieve remote code execution. The affected process runs with reduced privileges in…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7461">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-25582 – In FreeBSD 12.2-STABLE before r369334, 11.4-STABLE before r369335, 12.2-RELEASE ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-25582</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-25582</guid>
    <pubDate>Fri, 26 Mar 2021 21:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-25582</strong></p>
  <p>In FreeBSD 12.2-STABLE before r369334, 11.4-STABLE before r369335, 12.2-RELEASE before p4 and 11.4-RELEASE before p8 when a process, such as jexec(8) or killall(1), calls jail_attach(2) to enter a jail, the jailed root can attach to it using ptrace(2) before the current working directory is changed.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-25582">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-25581 – In FreeBSD 12.2-STABLE before r369312, 11.4-STABLE before r369313, 12.2-RELEASE ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-25581</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-25581</guid>
    <pubDate>Fri, 26 Mar 2021 21:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-25581</strong></p>
  <p>In FreeBSD 12.2-STABLE before r369312, 11.4-STABLE before r369313, 12.2-RELEASE before p4 and 11.4-RELEASE before p8 due to a race condition in the jail_remove(2) implementation, it may fail to kill some of the processes.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-25581">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-24718 – bhyve, as used in FreeBSD through 12.1 and illumos (e.g., OmniOS CE through r151...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-24718</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-24718</guid>
    <pubDate>Fri, 25 Sep 2020 04:23:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-24718</strong></p>
  <p>bhyve, as used in FreeBSD through 12.1 and illumos (e.g., OmniOS CE through r151034 and OpenIndiana through Hipster 2020.04), does not properly restrict VMCS and VMCB read/write operations, as demonstrated by a root user in a container on an Intel system, who can gain privileges by modifying VMCS_HOST_RIP.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-24718">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-24045 – A sandbox escape issue was discovered in TitanHQ SpamTitan Gateway 7.07. It limi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-24045</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-24045</guid>
    <pubDate>Thu, 17 Sep 2020 17:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-24045</strong></p>
  <p>A sandbox escape issue was discovered in TitanHQ SpamTitan Gateway 7.07. It limits the admin user to a restricted shell, allowing execution of a small number of tools of the operating system. The restricted shell can be bypassed by presenting a fake vmware-tools ISO image to the guest virtual machine running SpamTitan Gateway. This ISO image should contain a valid Perl script at the vmware-freebs…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-345</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-24045">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-24717 – OpenZFS before 2.0.0-rc1, when used on FreeBSD, misinterprets group permissions ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-24717</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-24717</guid>
    <pubDate>Thu, 27 Aug 2020 19:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-24717</strong></p>
  <p>OpenZFS before 2.0.0-rc1, when used on FreeBSD, misinterprets group permissions as user permissions, as demonstrated by mode 0770 being equivalent to mode 0777.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-24717">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-24716 – OpenZFS before 2.0.0-rc1, when used on FreeBSD, allows execute permissions for a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-24716</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-24716</guid>
    <pubDate>Thu, 27 Aug 2020 19:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-24716</strong></p>
  <p>OpenZFS before 2.0.0-rc1, when used on FreeBSD, allows execute permissions for all directories.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-24716">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-7460 – In FreeBSD 12.1-STABLE before r363918, 12.1-RELEASE before p8, 11.4-STABLE befor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7460</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7460</guid>
    <pubDate>Thu, 06 Aug 2020 17:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-7460</strong></p>
  <p>In FreeBSD 12.1-STABLE before r363918, 12.1-RELEASE before p8, 11.4-STABLE before r363919, 11.4-RELEASE before p2, and 11.3-RELEASE before p12, the sendmsg system call in the compat32 subsystem on 64-bit platforms has a time-of-check to time-of-use vulnerability allowing a mailcious userspace program to modify control message headers after they were validation.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7460">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-7458 – In FreeBSD 12.1-STABLE before r362281, 11.4-STABLE before r362281, and 11.4-RELE...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7458</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7458</guid>
    <pubDate>Thu, 09 Jul 2020 14:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-7458</strong></p>
  <p>In FreeBSD 12.1-STABLE before r362281, 11.4-STABLE before r362281, and 11.4-RELEASE before p1, long values in the user-controlled PATH environment variable cause posix_spawnp to write beyond the end of the heap allocated stack possibly leading to arbitrary code execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7458">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-7457 – In FreeBSD 12.1-STABLE before r359565, 12.1-RELEASE before p7, 11.4-STABLE befor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7457</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7457</guid>
    <pubDate>Thu, 09 Jul 2020 14:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-7457</strong></p>
  <p>In FreeBSD 12.1-STABLE before r359565, 12.1-RELEASE before p7, 11.4-STABLE before r362975, 11.4-RELEASE before p1, and 11.3-RELEASE before p11, missing synchronization in the IPV6_2292PKTOPTIONS socket option set handler contained a race condition allowing a malicious application to modify memory after being freed, possibly resulting in code execution.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7457">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-13160 – AnyDesk before 5.5.3 on Linux and FreeBSD has a format string vulnerability that...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-13160</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-13160</guid>
    <pubDate>Tue, 09 Jun 2020 17:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-13160</strong></p>
  <p>AnyDesk before 5.5.3 on Linux and FreeBSD has a format string vulnerability that can be exploited for remote code execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-134</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-13160">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-7454 – In FreeBSD 12.1-STABLE before r360971, 12.1-RELEASE before p5, 11.4-STABLE befor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7454</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7454</guid>
    <pubDate>Wed, 13 May 2020 16:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-7454</strong></p>
  <p>In FreeBSD 12.1-STABLE before r360971, 12.1-RELEASE before p5, 11.4-STABLE before r360971, 11.4-BETA1 before p1 and 11.3-RELEASE before p9, libalias does not properly validate packet length resulting in modules causing an out of bounds read/write condition if no checking was built into the module.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7454">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-15880 – In FreeBSD 12.1-STABLE before r356911, and 12.1-RELEASE before p5, insufficient ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-15880</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-15880</guid>
    <pubDate>Wed, 13 May 2020 16:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-15880</strong></p>
  <p>In FreeBSD 12.1-STABLE before r356911, and 12.1-RELEASE before p5, insufficient checking in the cryptodev module allocated the size of a kernel buffer based on a user-supplied length allowing an unprivileged process to trigger a kernel panic.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-15880">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-15879 – In FreeBSD 12.1-STABLE before r356908, 12.1-RELEASE before p5, 11.3-STABLE befor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-15879</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-15879</guid>
    <pubDate>Wed, 13 May 2020 16:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-15879</strong></p>
  <p>In FreeBSD 12.1-STABLE before r356908, 12.1-RELEASE before p5, 11.3-STABLE before r356908, and 11.3-RELEASE before p9, a race condition in the cryptodev module permitted a data structure in the kernel to be used after it was freed, allowing an unprivileged process can overwrite arbitrary kernel memory.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-15879">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-15878 – In FreeBSD 12.1-STABLE before r352509, 11.3-STABLE before r352509, and 11.3-RELE...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-15878</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-15878</guid>
    <pubDate>Wed, 13 May 2020 16:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-15878</strong></p>
  <p>In FreeBSD 12.1-STABLE before r352509, 11.3-STABLE before r352509, and 11.3-RELEASE before p9, an unprivileged local user can trigger a use-after-free situation due to improper checking in SCTP when an application tries to update an SCTP-AUTH shared key.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-15878">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-7452 – In FreeBSD 12.1-STABLE before r357490, 12.1-RELEASE before 12.1-RELEASE-p3, 11.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7452</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7452</guid>
    <pubDate>Wed, 29 Apr 2020 00:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-7452</strong></p>
  <p>In FreeBSD 12.1-STABLE before r357490, 12.1-RELEASE before 12.1-RELEASE-p3, 11.3-STABLE before r357489, and 11.3-RELEASE before 11.3-RELEASE-p7, incorrect use of a user-controlled pointer in the epair virtual network module allowed vnet jailed privileged users to panic the host system and potentially execute arbitrary code in the kernel.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7452">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-5614 – In FreeBSD 12.1-STABLE before r356035, 12.1-RELEASE before 12.1-RELEASE-p4, 11.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5614</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5614</guid>
    <pubDate>Wed, 29 Apr 2020 00:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-5614</strong></p>
  <p>In FreeBSD 12.1-STABLE before r356035, 12.1-RELEASE before 12.1-RELEASE-p4, 11.3-STABLE before r356036, and 11.3-RELEASE before 11.3-RELEASE-p8, incomplete packet data validation may result in accessing out-of-bounds memory leading to a kernel panic or other unpredictable results.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5614">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-15874 – In FreeBSD 12.1-STABLE before r356035, 12.1-RELEASE before 12.1-RELEASE-p4, 11.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-15874</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-15874</guid>
    <pubDate>Wed, 29 Apr 2020 00:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-15874</strong></p>
  <p>In FreeBSD 12.1-STABLE before r356035, 12.1-RELEASE before 12.1-RELEASE-p4, 11.3-STABLE before r356036, and 11.3-RELEASE before 11.3-RELEASE-p8, incomplete packet data validation may result in memory access after it has been freed leading to a kernel panic or other unpredictable results.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-15874">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-10566 – grub2-bhyve, as used in FreeBSD bhyve before revision 525916 2020-02-12, mishand...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-10566</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-10566</guid>
    <pubDate>Sat, 14 Mar 2020 01:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-10566</strong></p>
  <p>grub2-bhyve, as used in FreeBSD bhyve before revision 525916 2020-02-12, mishandles font loading by a guest through a grub2.cfg file, leading to a buffer overflow.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-10566">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-10565 – grub2-bhyve, as used in FreeBSD bhyve before revision 525916 2020-02-12, does no...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-10565</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-10565</guid>
    <pubDate>Sat, 14 Mar 2020 01:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-10565</strong></p>
  <p>grub2-bhyve, as used in FreeBSD bhyve before revision 525916 2020-02-12, does not validate the address provided as part of a memrw command (read_* or write_*) by a guest through a grub2.cfg file. This allows an untrusted guest to perform arbitrary read or write operations in the context of the grub-bhyve process, resulting in code execution as root on the host OS.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-10565">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2012-5365 – The IPv6 implementation in FreeBSD and NetBSD (unknown versions, year 2012 and e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-5365</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-5365</guid>
    <pubDate>Thu, 20 Feb 2020 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2012-5365</strong></p>
  <p>The IPv6 implementation in FreeBSD and NetBSD (unknown versions, year 2012 and earlier) allows remote attackers to cause a denial of service via a flood of ICMPv6 Router Advertisement packets containing multiple Routing entries.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-5365">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2012-5363 – The IPv6 implementation in FreeBSD and NetBSD (unknown versions, year 2012 and e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-5363</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-5363</guid>
    <pubDate>Thu, 20 Feb 2020 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2012-5363</strong></p>
  <p>The IPv6 implementation in FreeBSD and NetBSD (unknown versions, year 2012 and earlier) allows remote attackers to cause a denial of service via a flood of ICMPv6 Neighbor Solicitation messages, a different vulnerability than CVE-2011-2393.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-5363">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-7450 – In FreeBSD 12.1-STABLE before r357213, 12.1-RELEASE before 12.1-RELEASE-p2, 12.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7450</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7450</guid>
    <pubDate>Tue, 18 Feb 2020 16:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-7450</strong></p>
  <p>In FreeBSD 12.1-STABLE before r357213, 12.1-RELEASE before 12.1-RELEASE-p2, 12.0-RELEASE before 12.0-RELEASE-p13, 11.3-STABLE before r357214, and 11.3-RELEASE before 11.3-RELEASE-p6, URL handling in libfetch with URLs containing username and/or password components is vulnerable to a heap buffer overflow allowing program misbehavior or malicious code execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7450">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-5613 – In FreeBSD 12.0-RELEASE before 12.0-RELEASE-p13, a missing check in the ipsec pa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5613</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5613</guid>
    <pubDate>Tue, 18 Feb 2020 16:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-5613</strong></p>
  <p>In FreeBSD 12.0-RELEASE before 12.0-RELEASE-p13, a missing check in the ipsec packet processor allows reinjection of an old packet to be accepted by the ipsec endpoint. Depending on the higher-level protocol in use over ipsec, this could allow an action to be repeated.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-345</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5613">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-14899 – A vulnerability was discovered in Linux, FreeBSD, OpenBSD, MacOS, iOS, and Andro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-14899</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-14899</guid>
    <pubDate>Wed, 11 Dec 2019 15:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-14899</strong></p>
  <p>A vulnerability was discovered in Linux, FreeBSD, OpenBSD, MacOS, iOS, and Android that allows a malicious access point, or an adjacent user, to determine if a connected user is using a VPN, make positive inferences about the websites they are visiting, and determine the correct sequence and acknowledgement numbers in use, allowing the bad actor to inject data into the TCP stream. This provides e…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-300</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-14899">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2012-4576 – FreeBSD: Input Validation Flaw allows local users to gain elevated privileges</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-4576</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-4576</guid>
    <pubDate>Mon, 02 Dec 2019 18:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2012-4576</strong></p>
  <p>FreeBSD: Input Validation Flaw allows local users to gain elevated privileges</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-4576">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2011-2480 – Information Disclosure vulnerability in the 802.11 stack, as used in FreeBSD bef...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-2480</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-2480</guid>
    <pubDate>Wed, 27 Nov 2019 19:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2011-2480</strong></p>
  <p>Information Disclosure vulnerability in the 802.11 stack, as used in FreeBSD before 8.2 and NetBSD when using certain non-x86 architectures. A signedness error in the IEEE80211_IOC_CHANINFO ioctl allows a local unprivileged user to cause the kernel to copy large amounts of kernel memory back to the user, disclosing potentially sensitive information.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-2480">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2012-2979 – FreeBSD NSD before 3.2.13 allows remote attackers to crash a NSD child server pr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-2979</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-2979</guid>
    <pubDate>Fri, 01 Nov 2019 15:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2012-2979</strong></p>
  <p>FreeBSD NSD before 3.2.13 allows remote attackers to crash a NSD child server process (SIGSEGV) and cause a denial of service in the NSD server.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-669</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-2979">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-0061 – The management daemon (MGD) is responsible for all configuration and management ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-0061</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-0061</guid>
    <pubDate>Wed, 09 Oct 2019 20:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-0061</strong></p>
  <p>The management daemon (MGD) is responsible for all configuration and management operations in Junos OS. The Junos CLI communicates with MGD over an internal unix-domain socket and is granted special permission to open this protected mode socket. Due to a misconfiguration of the internal socket, a local, authenticated user may be able to exploit this vulnerability to gain administrative privileges…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-657</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-0061">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-5612 – In FreeBSD 12.0-STABLE before r351264, 12.0-RELEASE before 12.0-RELEASE-p10, 11...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5612</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5612</guid>
    <pubDate>Fri, 30 Aug 2019 09:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-5612</strong></p>
  <p>In FreeBSD 12.0-STABLE before r351264, 12.0-RELEASE before 12.0-RELEASE-p10, 11.3-STABLE before r351265, 11.3-RELEASE before 11.3-RELEASE-p3, and 11.2-RELEASE before 11.2-RELEASE-p14, the kernel driver for /dev/midistat implements a read handler that is not thread-safe. A multi-threaded program can exploit races in the handler to copy out kernel memory outside the boundaries of midistat's data bu…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5612">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-5611 – In FreeBSD 12.0-STABLE before r350828, 12.0-RELEASE before 12.0-RELEASE-p10, 11...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5611</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5611</guid>
    <pubDate>Fri, 30 Aug 2019 09:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-5611</strong></p>
  <p>In FreeBSD 12.0-STABLE before r350828, 12.0-RELEASE before 12.0-RELEASE-p10, 11.3-STABLE before r350829, 11.3-RELEASE before 11.3-RELEASE-p3, and 11.2-RELEASE before 11.2-RELEASE-p14, a missing check in the function to arrange data in a chain of mbufs could cause data returned not to be contiguous. Extra checks in the IPv6 stack could catch the error condition and trigger a kernel panic, leading…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5611">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-5610 – In FreeBSD 12.0-STABLE before r350637, 12.0-RELEASE before 12.0-RELEASE-p9, 11.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5610</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5610</guid>
    <pubDate>Fri, 30 Aug 2019 09:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-5610</strong></p>
  <p>In FreeBSD 12.0-STABLE before r350637, 12.0-RELEASE before 12.0-RELEASE-p9, 11.3-STABLE before r350638, 11.3-RELEASE before 11.3-RELEASE-p2, and 11.2-RELEASE before 11.2-RELEASE-p13, the bsnmp library is not properly validating the submitted length from a type-length-value encoding. A remote user could cause an out-of-bounds read or trigger a crash of the software such as bsnmpd resulting in a de…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5610">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-5609 – In FreeBSD 12.0-STABLE before r350619, 12.0-RELEASE before 12.0-RELEASE-p9, 11.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5609</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5609</guid>
    <pubDate>Fri, 30 Aug 2019 09:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-5609</strong></p>
  <p>In FreeBSD 12.0-STABLE before r350619, 12.0-RELEASE before 12.0-RELEASE-p9, 11.3-STABLE before r350619, 11.3-RELEASE before 11.3-RELEASE-p2, and 11.2-RELEASE before 11.2-RELEASE-p13, the bhyve e1000 device emulation used a guest-provided value to determine the size of the on-stack buffer without validation when TCP segmentation offload is requested for a transmitted packet. A misbehaving bhyve gu…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5609">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-5608 – In FreeBSD 12.0-STABLE before r350648, 12.0-RELEASE before 12.0-RELEASE-p9, 11.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5608</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5608</guid>
    <pubDate>Fri, 30 Aug 2019 09:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-5608</strong></p>
  <p>In FreeBSD 12.0-STABLE before r350648, 12.0-RELEASE before 12.0-RELEASE-p9, 11.3-STABLE before r350650, 11.3-RELEASE before 11.3-RELEASE-p2, and 11.2-RELEASE before 11.2-RELEASE-p13, the ICMPv6 input path incorrectly handles cases where an MLDv2 listener query packet is internally fragmented across multiple mbufs. A remote attacker may be able to cause an out-of-bounds read or write that may caus…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5608">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-5607 – In FreeBSD 12.0-STABLE before r350222, 12.0-RELEASE before 12.0-RELEASE-p8, 11.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5607</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5607</guid>
    <pubDate>Fri, 26 Jul 2019 01:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-5607</strong></p>
  <p>In FreeBSD 12.0-STABLE before r350222, 12.0-RELEASE before 12.0-RELEASE-p8, 11.3-STABLE before r350223, 11.3-RELEASE before 11.3-RELEASE-p1, and 11.2-RELEASE before 11.2-RELEASE-p12, rights transmitted over a domain socket did not properly release a reference on transmission error allowing a malicious user to cause the reference counter to wrap, forcing a free event. This could allow a malicious…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-404</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5607">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-5606 – In FreeBSD 12.0-STABLE before r349805, 12.0-RELEASE before 12.0-RELEASE-p8, 11.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5606</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5606</guid>
    <pubDate>Fri, 26 Jul 2019 01:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-5606</strong></p>
  <p>In FreeBSD 12.0-STABLE before r349805, 12.0-RELEASE before 12.0-RELEASE-p8, 11.3-STABLE before r349806, 11.3-RELEASE before 11.3-RELEASE-p1, and 11.2-RELEASE before 11.2-RELEASE-p12, code which handles close of a descriptor created by posix_openpt fails to undo a signal configuration. This causes an incorrect signal to be raised leading to a write after free of kernel memory allowing a malicious…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5606">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-5604 – In FreeBSD 12.0-STABLE before r350246, 12.0-RELEASE before 12.0-RELEASE-p8, 11.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5604</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5604</guid>
    <pubDate>Fri, 26 Jul 2019 01:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-5604</strong></p>
  <p>In FreeBSD 12.0-STABLE before r350246, 12.0-RELEASE before 12.0-RELEASE-p8, 11.3-STABLE before r350247, 11.3-RELEASE before 11.3-RELEASE-p1, and 11.2-RELEASE before 11.2-RELEASE-p12, the emulated XHCI device included with the bhyve hypervisor did not properly validate data provided by the guest, allowing an out-of-bounds read. This provides a malicious guest the possibility to crash the system or…</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5604">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-5603 – In FreeBSD 12.0-STABLE before r350261, 12.0-RELEASE before 12.0-RELEASE-p8, 11.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5603</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5603</guid>
    <pubDate>Fri, 26 Jul 2019 01:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-5603</strong></p>
  <p>In FreeBSD 12.0-STABLE before r350261, 12.0-RELEASE before 12.0-RELEASE-p8, 11.3-STABLE before r350263, 11.3-RELEASE before 11.3-RELEASE-p1, and 11.2-RELEASE before 11.2-RELEASE-p12, system calls operating on file descriptors as part of mqueuefs did not properly release the reference allowing a malicious user to overflow the counter allowing access to files, directories, and sockets opened by pro…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-404</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5603">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-5602 – In FreeBSD 12.0-STABLE before r349628, 12.0-RELEASE before 12.0-RELEASE-p7, 11.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5602</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5602</guid>
    <pubDate>Wed, 03 Jul 2019 19:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-5602</strong></p>
  <p>In FreeBSD 12.0-STABLE before r349628, 12.0-RELEASE before 12.0-RELEASE-p7, 11.3-PRERELEASE before r349629, 11.3-RC3 before 11.3-RC3-p1, and 11.2-RELEASE before 11.2-RELEASE-p11, a bug in the cdrom driver allows users with read access to the cdrom device to arbitrarily overwrite kernel memory when media is present thereby allowing a malicious user in the operator group to gain root privileges.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5602">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-5600 – In FreeBSD 12.0-STABLE before r349622, 12.0-RELEASE before 12.0-RELEASE-p7, 11.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5600</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5600</guid>
    <pubDate>Wed, 03 Jul 2019 19:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-5600</strong></p>
  <p>In FreeBSD 12.0-STABLE before r349622, 12.0-RELEASE before 12.0-RELEASE-p7, 11.3-PRERELEASE before r349624, 11.3-RC3 before 11.3-RC3-p1, and 11.2-RELEASE before 11.2-RELEASE-p11, a bug in iconv implementation may allow an attacker to write past the end of an output buffer. Depending on the implementation, an attacker may be able to create a denial of service, provoke incorrect program behavior, o…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5600">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-5599 – In FreeBSD 12.0-STABLE before r349197 and 12.0-RELEASE before 12.0-RELEASE-p6, a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5599</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5599</guid>
    <pubDate>Tue, 02 Jul 2019 21:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-5599</strong></p>
  <p>In FreeBSD 12.0-STABLE before r349197 and 12.0-RELEASE before 12.0-RELEASE-p6, a bug in the non-default RACK TCP stack can allow an attacker to cause several linked lists to grow unbounded and cause an expensive list traversal on every packet being processed, leading to resource exhaustion and a denial of service.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5599">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-5598 – In FreeBSD 11.3-PRERELEASE before r345378, 12.0-STABLE before r345377, 11.2-RELE...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5598</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5598</guid>
    <pubDate>Wed, 15 May 2019 16:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-5598</strong></p>
  <p>In FreeBSD 11.3-PRERELEASE before r345378, 12.0-STABLE before r345377, 11.2-RELEASE before 11.2-RELEASE-p10, and 12.0-RELEASE before 12.0-RELEASE-p4, a bug in pf does not check if the outer ICMP or ICMP6 packet has the same destination IP as the source IP of the inner protocol packet allowing a maliciously crafted ICMP/ICMP6 packet could bypass the packet filter rules and be passed to a host that…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5598">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-5597 – In FreeBSD 11.3-PRERELEASE and 12.0-STABLE before r347591, 11.2-RELEASE before 1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5597</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5597</guid>
    <pubDate>Wed, 15 May 2019 16:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-5597</strong></p>
  <p>In FreeBSD 11.3-PRERELEASE and 12.0-STABLE before r347591, 11.2-RELEASE before 11.2-RELEASE-p10, and 12.0-RELEASE before 12.0-RELEASE-p4, a bug in the pf IPv6 fragment reassembly logic incorrectly uses the last extension header offset from the last received packet instead of the first packet allowing maliciously crafted IPv6 packets to cause a crash or potentially bypass the packet filter.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5597">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-0040 – On Junos OS, rpcbind should only be listening to port 111 on the internal routin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-0040</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-0040</guid>
    <pubDate>Wed, 10 Apr 2019 20:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-0040</strong></p>
  <p>On Junos OS, rpcbind should only be listening to port 111 on the internal routing instance (IRI). External packets destined to port 111 should be dropped. Due to an information leak vulnerability, responses were being generated from the source address of the management interface (e.g. fxp0) thus disclosing internal addressing and existence of the management interface itself. A high rate of crafte…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-0040">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-5596 – In FreeBSD 11.2-STABLE after r338618 and before r343786, 12.0-STABLE before r343...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5596</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5596</guid>
    <pubDate>Tue, 12 Feb 2019 05:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-5596</strong></p>
  <p>In FreeBSD 11.2-STABLE after r338618 and before r343786, 12.0-STABLE before r343781, and 12.0-RELEASE before 12.0-RELEASE-p3, a bug in the reference count implementation for UNIX domain sockets can cause a file structure to be incorrectly released potentially allowing a malicious local user to gain root privileges or escape from a jail.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5596">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-17161 – In FreeBSD before 11.2-STABLE(r348229), 11.2-RELEASE-p7, 12.0-STABLE(r342228), a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-17161</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-17161</guid>
    <pubDate>Thu, 03 Jan 2019 17:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-17161</strong></p>
  <p>In FreeBSD before 11.2-STABLE(r348229), 11.2-RELEASE-p7, 12.0-STABLE(r342228), and 12.0-RELEASE-p1, insufficient validation of network-provided data in bootpd may make it possible for a malicious attacker to craft a bootp packet which could cause a stack buffer overflow. It is possible that the buffer overflow could lead to a Denial of Service or remote code execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-17161">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-17160 – In FreeBSD before 11.2-STABLE(r341486) and 11.2-RELEASE-p6, insufficient bounds ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-17160</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-17160</guid>
    <pubDate>Tue, 04 Dec 2018 21:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-17160</strong></p>
  <p>In FreeBSD before 11.2-STABLE(r341486) and 11.2-RELEASE-p6, insufficient bounds checking in one of the device models provided by bhyve can permit a guest operating system to overwrite memory in the bhyve host possibly permitting arbitrary code execution. A guest OS using a firmware image can cause the bhyve process to crash, or possibly execute arbitrary code on the host as root.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-17160">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-17159 – In FreeBSD before 11.2-STABLE(r340854) and 11.2-RELEASE-p5, the NFS server lacks...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-17159</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-17159</guid>
    <pubDate>Tue, 04 Dec 2018 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-17159</strong></p>
  <p>In FreeBSD before 11.2-STABLE(r340854) and 11.2-RELEASE-p5, the NFS server lacks a bounds check in the READDIRPLUS NFS request. Unprivileged remote users with access to the NFS server can cause a resource exhaustion by forcing the server to allocate an arbitrarily large memory allocation.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-17159">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-17158 – In FreeBSD before 11.2-STABLE(r340854) and 11.2-RELEASE-p5, an integer overflow ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-17158</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-17158</guid>
    <pubDate>Tue, 04 Dec 2018 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-17158</strong></p>
  <p>In FreeBSD before 11.2-STABLE(r340854) and 11.2-RELEASE-p5, an integer overflow error can occur when handling the client address length field in an NFSv4 request. Unprivileged remote users with access to the NFS server can crash the system by sending a specially crafted NFSv4 request.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-17158">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-17157 – In FreeBSD before 11.2-STABLE(r340854) and 11.2-RELEASE-p5, an integer overflow ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-17157</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-17157</guid>
    <pubDate>Tue, 04 Dec 2018 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-17157</strong></p>
  <p>In FreeBSD before 11.2-STABLE(r340854) and 11.2-RELEASE-p5, an integer overflow error when handling opcodes can cause memory corruption by sending a specially crafted NFSv4 request. Unprivileged remote users with access to the NFS server may be able to execute arbitrary code.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-17157">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-0052 – If RSH service is enabled on Junos OS and if the PAM authentication is disabled,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-0052</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-0052</guid>
    <pubDate>Wed, 10 Oct 2018 18:29:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-0052</strong></p>
  <p>If RSH service is enabled on Junos OS and if the PAM authentication is disabled, a remote unauthenticated attacker can obtain root access to the device. RSH service is disabled by default on Junos. There is no documented CLI command to enable this service. However, an undocumented CLI command allows a privileged Junos user to enable RSH service and disable PAM, and hence expose the system to unau…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-0052">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-6924 – In FreeBSD before 11.1-STABLE, 11.2-RELEASE-p3, 11.1-RELEASE-p14, 10.4-STABLE, a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-6924</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-6924</guid>
    <pubDate>Wed, 12 Sep 2018 14:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-6924</strong></p>
  <p>In FreeBSD before 11.1-STABLE, 11.2-RELEASE-p3, 11.1-RELEASE-p14, 10.4-STABLE, and 10.4-RELEASE-p12, insufficient validation in the ELF header parser could allow a malicious ELF binary to cause a kernel crash or disclose kernel memory.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-6924">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-1085 – In FreeBSD before 11.2-RELEASE, an application which calls setrlimit() to increa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-1085</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-1085</guid>
    <pubDate>Wed, 12 Sep 2018 14:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-1085</strong></p>
  <p>In FreeBSD before 11.2-RELEASE, an application which calls setrlimit() to increase RLIMIT_STACK may turn a read-only memory region below the stack into a read-write region. A specially crafted executable could be exploited to execute arbitrary code in the user context.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-1085">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-1084 – In FreeBSD before 11.2-RELEASE, multiple issues with the implementation of the s...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-1084</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-1084</guid>
    <pubDate>Wed, 12 Sep 2018 14:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-1084</strong></p>
  <p>In FreeBSD before 11.2-RELEASE, multiple issues with the implementation of the stack guard-page reduce the protections afforded by the guard-page. This results in the possibility a poorly written process could be cause a stack overflow.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-1084">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-1083 – In FreeBSD before 11.2-RELEASE, a stack guard-page is available but is disabled ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-1083</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-1083</guid>
    <pubDate>Wed, 12 Sep 2018 14:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-1083</strong></p>
  <p>In FreeBSD before 11.2-RELEASE, a stack guard-page is available but is disabled by default. This results in the possibility a poorly written process could be cause a stack overflow.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-1083">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-1082 – In FreeBSD 11.x before 11.1-RELEASE and 10.x before 10.4-RELEASE, the qsort algo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-1082</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-1082</guid>
    <pubDate>Wed, 12 Sep 2018 14:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-1082</strong></p>
  <p>In FreeBSD 11.x before 11.1-RELEASE and 10.x before 10.4-RELEASE, the qsort algorithm has a deterministic recursion pattern. Feeding a pathological input to the algorithm can lead to excessive stack usage and potential overflow. Applications that use qsort to handle large data set may crash if the input follows the pathological pattern.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-1082">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-6923 – In FreeBSD before 11.1-STABLE, 11.2-RELEASE-p2, 11.1-RELEASE-p13, ip fragment re...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-6923</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-6923</guid>
    <pubDate>Tue, 04 Sep 2018 18:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-6923</strong></p>
  <p>In FreeBSD before 11.1-STABLE, 11.2-RELEASE-p2, 11.1-RELEASE-p13, ip fragment reassembly code is vulnerable to a denial of service due to excessive system resource consumption. This issue can allow a remote attacker who is able to send an arbitrary ip fragments to cause the machine to consume excessive resources.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-6923">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-14939 – The get_app_path function in desktop/unx/source/start.c in LibreOffice through 6...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-14939</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-14939</guid>
    <pubDate>Sun, 05 Aug 2018 18:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-14939</strong></p>
  <p>The get_app_path function in desktop/unx/source/start.c in LibreOffice through 6.0.5 mishandles the realpath function in certain environments such as FreeBSD libc, which might allow attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact if LibreOffice is automatically launched during web browsing with pathnames controlled by a remo…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-14939">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2016-6559 – Improper bounds checking of the obuf variable in the link_ntoa() function in lin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-6559</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-6559</guid>
    <pubDate>Fri, 13 Jul 2018 20:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2016-6559</strong></p>
  <p>Improper bounds checking of the obuf variable in the link_ntoa() function in linkaddr.c of the BSD libc library may allow an attacker to read or write from memory. The full impact and severity depends on the method of exploit and how the library is used by applications. According to analysis by FreeBSD developers, it is very unlikely that applications exist that utilize link_ntoa() in an exploita…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6559">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-14480 – In the MMM::Agent::Helpers::Network::clear_ip function in MySQL Multi-Master Rep...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-14480</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-14480</guid>
    <pubDate>Wed, 09 May 2018 20:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-14480</strong></p>
  <p>In the MMM::Agent::Helpers::Network::clear_ip function in MySQL Multi-Master Replication Manager (MMM) mmm_agentd 2.2.1 (for FreeBSD), a specially crafted MMM protocol message can cause a shell command injection resulting in arbitrary command execution with the privileges of the mmm\_agentd process. An attacker that can initiate a TCP session with mmm\_agentd can trigger this vulnerability.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-14480">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-14477 – In the MMM::Agent::Helpers::Network::add_ip function in MySQL Multi-Master Repli...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-14477</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-14477</guid>
    <pubDate>Wed, 09 May 2018 20:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-14477</strong></p>
  <p>In the MMM::Agent::Helpers::Network::add_ip function in MySQL Multi-Master Replication Manager (MMM) mmm_agentd 2.2.1 (for FreeBSD), a specially crafted MMM protocol message can cause a shell command injection resulting in arbitrary command execution with the privileges of the mmm\_agentd process. An attacker that can initiate a TCP session with mmm\_agentd can trigger this vulnerability.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-14477">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-8897 – A statement in the System Programming Guide of the Intel 64 and IA-32 Architectu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-8897</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-8897</guid>
    <pubDate>Tue, 08 May 2018 18:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-8897</strong></p>
  <p>A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) was mishandled in the development of some or all operating-system kernels, resulting in unexpected behavior for #DB exceptions that are deferred by MOV SS or POP SS, as demonstrated by (for example) privilege escalation in Windows, macOS, some Xen configurations, or FreeBSD, or a…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-8897">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-1081 – In FreeBSD before 11.0-STABLE, 11.0-RELEASE-p10, 10.3-STABLE, and 10.3-RELEASE-p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-1081</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-1081</guid>
    <pubDate>Tue, 10 Apr 2018 13:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-1081</strong></p>
  <p>In FreeBSD before 11.0-STABLE, 11.0-RELEASE-p10, 10.3-STABLE, and 10.3-RELEASE-p19, ipfilter using "keep state" or "keep frags" options can cause a kernel panic when fed specially crafted packet fragments due to incorrect memory handling.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-1081">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-1000156 – GNU Patch version 2.7.6 contains an input validation vulnerability when processi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1000156</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1000156</guid>
    <pubDate>Fri, 06 Apr 2018 13:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-1000156</strong></p>
  <p>GNU Patch version 2.7.6 contains an input validation vulnerability when processing patch files, specifically the EDITOR_PROGRAM invocation (using ed) can result in code execution. This attack appear to be exploitable via a patch file processed via the patch utility. This is similar to FreeBSD's CVE-2015-1418 however although they share a common ancestry the code bases have diverged over time.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1000156">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-6919 – In FreeBSD before 11.1-STABLE, 11.1-RELEASE-p9, 10.4-STABLE, 10.4-RELEASE-p8 and...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-6919</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-6919</guid>
    <pubDate>Wed, 04 Apr 2018 14:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-6919</strong></p>
  <p>In FreeBSD before 11.1-STABLE, 11.1-RELEASE-p9, 10.4-STABLE, 10.4-RELEASE-p8 and 10.3-RELEASE-p28, due to insufficient initialization of memory copied to userland, small amounts of kernel memory may be disclosed to userland processes. Unprivileged users may be able to access small amounts privileged kernel data.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-6919">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-6918 – In FreeBSD before 11.1-STABLE, 11.1-RELEASE-p9, 10.4-STABLE, 10.4-RELEASE-p8 and...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-6918</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-6918</guid>
    <pubDate>Wed, 04 Apr 2018 14:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-6918</strong></p>
  <p>In FreeBSD before 11.1-STABLE, 11.1-RELEASE-p9, 10.4-STABLE, 10.4-RELEASE-p8 and 10.3-RELEASE-p28, the length field of the ipsec option header does not count the size of the option header itself, causing an infinite loop when the length is zero. This issue can allow a remote attacker who is able to send an arbitrary packet to cause the machine to crash.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-835</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-6918">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-6917 – In FreeBSD before 11.1-STABLE, 11.1-RELEASE-p9, 10.4-STABLE, 10.4-RELEASE-p8 and...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-6917</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-6917</guid>
    <pubDate>Wed, 04 Apr 2018 14:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-6917</strong></p>
  <p>In FreeBSD before 11.1-STABLE, 11.1-RELEASE-p9, 10.4-STABLE, 10.4-RELEASE-p8 and 10.3-RELEASE-p28, insufficient validation of user-provided font parameters can result in an integer overflow, leading to the use of arbitrary kernel memory as glyph data. Unprivileged users may be able to access privileged kernel data.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-6917">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-6916 – In FreeBSD before 11.1-STABLE, 11.1-RELEASE-p7, 10.4-STABLE, 10.4-RELEASE-p7, an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-6916</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-6916</guid>
    <pubDate>Fri, 09 Mar 2018 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-6916</strong></p>
  <p>In FreeBSD before 11.1-STABLE, 11.1-RELEASE-p7, 10.4-STABLE, 10.4-RELEASE-p7, and 10.3-RELEASE-p28, the kernel does not properly validate IPsec packets coming from a trusted host. Additionally, a use-after-free vulnerability exists in the IPsec AH handling code. This issue could cause a system crash or other unpredictable results.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-6916">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-1418 – The do_ed_script function in pch.c in GNU patch through 2.7.6, and patch in Free...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-1418</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-1418</guid>
    <pubDate>Mon, 05 Feb 2018 16:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-1418</strong></p>
  <p>The do_ed_script function in pch.c in GNU patch through 2.7.6, and patch in FreeBSD 10.1 before 10.1-RELEASE-p17, 10.2 before 10.2-BETA2-p3, 10.2-RC1 before 10.2-RC1-p2, and 0.2-RC2 before 10.2-RC2-p1, allows remote attackers to execute arbitrary commands via a crafted patch file, because a '!' character can be passed to the ed program.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-1418">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-1416 – Larry Wall's patch; patch in FreeBSD 10.2-RC1 before 10.2-RC1-p1, 10.2 before 10...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-1416</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-1416</guid>
    <pubDate>Mon, 05 Feb 2018 16:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-1416</strong></p>
  <p>Larry Wall's patch; patch in FreeBSD 10.2-RC1 before 10.2-RC1-p1, 10.2 before 10.2-BETA2-p2, and 10.1 before 10.1-RELEASE-p16; Bitrig; GNU patch before 2.2.5; and possibly other patch variants allow remote attackers to execute arbitrary shell commands via a crafted patch file.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-1416">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
