<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – FreeBSD</title>
  <link>https://cvedaily.com/pages/tags/freebsd.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/freebsd.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – FreeBSD</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:47 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2026-45158 – OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.8, unsa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45158</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45158</guid>
    <pubDate>Wed, 13 May 2026 22:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-45158</strong></p>
  <p>OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.8, unsanitized user input is passed to the DHCP configuration of the configured interface, which is processed by a shell script, allowing remote code execution as root on the underlying operating system. This vulnerability is fixed in 26.1.8.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-88</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45158">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-44195 – OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.7, a lo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44195</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44195</guid>
    <pubDate>Wed, 13 May 2026 22:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-44195</strong></p>
  <p>OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.7, a logic flaw in the OPNsense lockout_handler allows an unauthenticated attacker to continuously reset the authentication failure counter for their IP address. By interjecting a crafted username containing a success keyword ("Accepted" or "Successful login") between normal brute-force attempts, an attacker can prevent the…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-307</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44195">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-44194 – OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.8, an a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44194</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44194</guid>
    <pubDate>Wed, 13 May 2026 22:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-44194</strong></p>
  <p>OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.8, an authenticated Remote Code Execution (RCE) vulnerability in the OPNsense core allows a user with user-management privileges to execute arbitrary system commands as root. An attacker can bypass input validation by formatting their malicious payload as a compliant email address, allowing shell commands to reach the underl…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44194">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-44193 – OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.7, the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44193</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44193</guid>
    <pubDate>Wed, 13 May 2026 22:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-44193</strong></p>
  <p>OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.7, the XMLRPC method opnsense.restore_config_section fails to sanitize user supplied input leading to Remote Code Execution. This vulnerability is fixed in 26.1.7.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-88</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44193">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-35362 – The safe_traversal module in uutils coreutils, which provides protection against...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35362</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35362</guid>
    <pubDate>Wed, 22 Apr 2026 17:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-35362</strong></p>
  <p>The safe_traversal module in uutils coreutils, which provides protection against Time-of-Check to Time-of-Use (TOCTOU) symlink races using file-descriptor-relative syscalls, is incorrectly limited to Linux targets. On other Unix-like systems such as macOS and FreeBSD, the utility fails to utilize these protections, leaving directory traversal operations vulnerable to symlink race conditions.</p>
  <p><strong>CVSS:</strong> 3.6 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35362">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34578 – OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.6, OPNs...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34578</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34578</guid>
    <pubDate>Thu, 09 Apr 2026 15:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34578</strong></p>
  <p>OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.6, OPNsense's LDAP authentication connector passes the login username directly into an LDAP search filter without calling ldap_escape(). An unauthenticated attacker can inject LDAP filter metacharacters into the username field of the WebGUI login page to enumerate valid LDAP usernames in the configured directory. When the LD…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-90</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34578">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-4747 – Each RPCSEC_GSS data packet is validated by a routine which checks a signature i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4747</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4747</guid>
    <pubDate>Thu, 26 Mar 2026 07:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-4747</strong></p>
  <p>Each RPCSEC_GSS data packet is validated by a routine which checks a signature in the packet.  This routine copies a portion of the packet into a stack buffer, but fails to ensure that the buffer is sufficiently large, and a malicious client can trigger a stack overflow.  Notably, this does not require the client to authenticate itself first.  As kgssapi.ko's RPCSEC_GSS implementation is vulnerab…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4747">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-4247 – When a challenge ACK is to be sent tcp_respond() constructs and sends the challe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4247</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4247</guid>
    <pubDate>Thu, 26 Mar 2026 07:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-4247</strong></p>
  <p>When a challenge ACK is to be sent tcp_respond() constructs and sends the challenge ACK and consumes the mbuf that is passed in.  When no challenge ACK should be sent the function returns and leaks the mbuf.  If an attacker is either on path with an established TCP connection, or can themselves establish a TCP connection, to an affected FreeBSD machine, they can easily craft and send packets whic…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-401</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4247">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-30868 – OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.4, mult...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30868</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30868</guid>
    <pubDate>Wed, 11 Mar 2026 17:16:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-30868</strong></p>
  <p>OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.4, multiple OPNsense MVC API endpoints perform state‑changing operations but are accessible via HTTP GET requests without CSRF protection. The framework CSRF validation in ApiControllerBase only applies to POST/PUT/DELETE methods, allowing authenticated GET requests to bypass CSRF verification. As a result, a malicious websi…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30868">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-21776 – In the Linux kernel, the following vulnerability has been resolved:

USB: hub: I...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-21776</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-21776</guid>
    <pubDate>Thu, 27 Feb 2025 03:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-21776</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  USB: hub: Ignore non-compliant devices with too many configs or interfaces  Robert Morris created a test program which can cause usb_hub_to_struct_hub() to dereference a NULL or inappropriate pointer:  Oops: general protection fault, probably for non-canonical address 0xcccccccccccccccc: 0000 [#1] SMP DEBUG_PAGEALLOC PTI CPU: 7…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-21776">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-7589 – A signal handler in sshd(8) may call a logging function that is not async-signal...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-7589</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-7589</guid>
    <pubDate>Mon, 12 Aug 2024 13:38:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-7589</strong></p>
  <p>A signal handler in sshd(8) may call a logging function that is not async-signal-safe.  The signal handler is invoked when a client does not authenticate within the LoginGraceTime seconds (120 by default).  This signal handler executes in the context of the sshd(8)'s privileged code, which is not sandboxed and runs with full root privileges.  This issue is another instance of the problem in CVE-2…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-7589">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-29937 – NFS in a BSD derived codebase, as used in OpenBSD through 7.4 and FreeBSD throug...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-29937</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-29937</guid>
    <pubDate>Thu, 11 Apr 2024 01:25:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-29937</strong></p>
  <p>NFS in a BSD derived codebase, as used in OpenBSD through 7.4 and FreeBSD through 14.0-RELEASE, allows remote attackers to execute arbitrary code via a bug that is unrelated to memory corruption.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-29937">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-23093 – ping reads raw IP packets from the network to process responses in the pr_pack()...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-23093</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-23093</guid>
    <pubDate>Thu, 15 Feb 2024 06:15:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-23093</strong></p>
  <p>ping reads raw IP packets from the network to process responses in the pr_pack() function.  As part of processing a response ping has to reconstruct the IP header, the ICMP header and if present a "quoted packet," which represents the packet that generated an ICMP error.  The quoted packet again has an IP header and an ICMP header.  The pr_pack() copies received IP and ICMP headers into stack buf…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23093">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-23088 – The 802.11 beacon handling routine failed to validate the length of an IEEE 802...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-23088</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-23088</guid>
    <pubDate>Thu, 15 Feb 2024 05:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-23088</strong></p>
  <p>The 802.11 beacon handling routine failed to validate the length of an IEEE 802.11s Mesh ID before copying it to a heap-allocated buffer.  While a FreeBSD Wi-Fi client is in scanning mode (i.e., not associated with a SSID) a malicious beacon frame may overwrite kernel memory, leading to remote code execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23088">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-23087 – The e1000 network adapters permit a variety of modifications to an Ethernet pack...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-23087</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-23087</guid>
    <pubDate>Thu, 15 Feb 2024 05:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-23087</strong></p>
  <p>The e1000 network adapters permit a variety of modifications to an Ethernet packet when it is being transmitted.  These include the insertion of IP and TCP checksums, insertion of an Ethernet VLAN header, and TCP segmentation offload ("TSO").  The e1000 device model uses an on-stack buffer to generate the modified packet header when simulating these modifications on transmitted packets.  When che…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23087">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-6534 – In versions of FreeBSD 14.0-RELEASE before 14-RELEASE-p2, FreeBSD 13.2-RELEASE b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-6534</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-6534</guid>
    <pubDate>Wed, 13 Dec 2023 09:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-6534</strong></p>
  <p>In versions of FreeBSD 14.0-RELEASE before 14-RELEASE-p2, FreeBSD 13.2-RELEASE before 13.2-RELEASE-p7 and FreeBSD 12.4-RELEASE before 12.4-RELEASE-p9, the pf(4) packet filter incorrectly validates TCP sequence numbers.  This could allow a malicious actor to execute a denial-of-service attack against hosts behind the firewall.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-6534">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-5978 – In versions of FreeBSD 13-RELEASE before 13-RELEASE-p5, under certain circumstan...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-5978</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-5978</guid>
    <pubDate>Wed, 08 Nov 2023 09:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-5978</strong></p>
  <p>In versions of FreeBSD 13-RELEASE before 13-RELEASE-p5, under certain circumstances the cap_net libcasper(3) service incorrectly validates that updated constraints are strictly subsets of the active constraints.  When only a list of resolvable domain names was specified without setting any other limitations, an application could submit a new list of domains including include entries not previousl…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-5978">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-5941 – In versions of FreeBSD 12.4-RELEASE prior to 12.4-RELEASE-p7 and FreeBSD 13.2-RE...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-5941</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-5941</guid>
    <pubDate>Wed, 08 Nov 2023 09:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-5941</strong></p>
  <p>In versions of FreeBSD 12.4-RELEASE prior to 12.4-RELEASE-p7 and FreeBSD 13.2-RELEASE prior to 13.2-RELEASE-p5 the __sflush() stdio function in libc does not correctly update FILE objects' write space members for write-buffered streams when the write(2) system call returns an error.  Depending on the nature of an application that calls libc's stdio functions and the presence of errors returned fr…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-131</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-5941">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-3326 – pam_krb5 authenticates a user by essentially running kinit with the password, ge...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-3326</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-3326</guid>
    <pubDate>Thu, 22 Jun 2023 17:15:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-3326</strong></p>
  <p>pam_krb5 authenticates a user by essentially running kinit with the password, getting a ticket-granting ticket (tgt) from the Kerberos KDC (Key Distribution Center) over the network, as a way to verify the password. However, if a keytab is not provisioned on the system, pam_krb5 has no way to validate the response from the KDC, and essentially trusts the tgt provided over the network as being val…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-303</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-3326">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-24626 – socket.c in GNU Screen through 4.9.0, when installed setuid or setgid (the defau...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-24626</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-24626</guid>
    <pubDate>Sat, 08 Apr 2023 05:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-24626</strong></p>
  <p>socket.c in GNU Screen through 4.9.0, when installed setuid or setgid (the default on platforms such as Arch Linux and FreeBSD), allows local users to send a privileged SIGHUP signal to any PID, causing a denial of service or disruption of the target process.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-24626">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-28436 – Tailscale is software for using Wireguard and multi-factor authentication (MFA)...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-28436</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-28436</guid>
    <pubDate>Thu, 23 Mar 2023 20:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-28436</strong></p>
  <p>Tailscale is software for using Wireguard and multi-factor authentication (MFA). A vulnerability identified in the implementation of Tailscale SSH starting in version 1.34.0 and prior to prior to 1.38.2 in FreeBSD allows commands to be run with a higher privilege group ID than that specified in Tailscale SSH access rules. A difference in the behavior of the FreeBSD `setgroups` system call from PO…</p>
  <p><strong>CVSS:</strong> 5.7 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-28436">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-45188 – Netatalk through 3.1.13 has an afp_getappl heap-based buffer overflow resulting ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-45188</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-45188</guid>
    <pubDate>Sat, 12 Nov 2022 05:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-45188</strong></p>
  <p>Netatalk through 3.1.13 has an afp_getappl heap-based buffer overflow resulting in code execution via a crafted .appl file. This provides remote root access on some platforms such as FreeBSD (used for TrueNAS).</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-45188">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-40895 – In certain Nedi products, a vulnerability in the web UI of NeDi login &amp; Communit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-40895</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-40895</guid>
    <pubDate>Thu, 06 Oct 2022 18:16:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-40895</strong></p>
  <p>In certain Nedi products, a vulnerability in the web UI of NeDi login & Community login could allow an unauthenticated, remote attacker to affect the integrity of a device via a User Enumeration vulnerability. The vulnerability is due to insecure design, where a difference in forgot password utility could allow an attacker to determine if the user is valid or not, enabling a brute force attack wi…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-203</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-40895">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-32264 – sys/netinet/tcp_timer.h in FreeBSD before 7.0 contains a denial-of-service (DoS)...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-32264</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-32264</guid>
    <pubDate>Tue, 06 Sep 2022 18:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-32264</strong></p>
  <p>sys/netinet/tcp_timer.h in FreeBSD before 7.0 contains a denial-of-service (DoS) vulnerability due to improper handling of TSopt on TCP connections. NOTE: This vulnerability only affects products that are no longer supported by the maintainer</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-755</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-32264">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-29632 – In FreeBSD 13.0-STABLE before n247428-9352de39c3dc, 12.2-STABLE before r370674, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-29632</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-29632</guid>
    <pubDate>Tue, 18 Jan 2022 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-29632</strong></p>
  <p>In FreeBSD 13.0-STABLE before n247428-9352de39c3dc, 12.2-STABLE before r370674, 13.0-RELEASE before p6, and 12.2-RELEASE before p12, certain conditions involving use of the highlight buffer while text is scrolling on the console, console data may overwrite data structures associated with the system console or other kernel memory.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-29632">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2011-1075 – FreeBSD's crontab calculates the MD5 sum of the previous and new cronjob to dete...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-1075</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-1075</guid>
    <pubDate>Tue, 19 Oct 2021 15:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2011-1075</strong></p>
  <p>FreeBSD's crontab calculates the MD5 sum of the previous and new cronjob to determine if any changes have been made before copying the new version in. In particular, it uses the MD5File() function, which takes a pathname as an argument, and is called with euid 0. A race condition in this process may lead to an arbitrary MD5 comparison regardless of the read permissions.</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-1075">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-29630 – In FreeBSD 13.0-STABLE before n246938-0729ba2f49c9, 12.2-STABLE before r370383, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-29630</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-29630</guid>
    <pubDate>Mon, 30 Aug 2021 19:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-29630</strong></p>
  <p>In FreeBSD 13.0-STABLE before n246938-0729ba2f49c9, 12.2-STABLE before r370383, 11.4-STABLE before r370381, 13.0-RELEASE before p4, 12.2-RELEASE before p10, and 11.4-RELEASE before p13, the ggatec daemon does not validate the size of a response before writing it to a fixed-sized buffer allowing a malicious attacker in a privileged network position to overwrite the stack of ggatec and potentially…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-29630">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-29631 – In FreeBSD 13.0-STABLE before n246941-20f96f215562, 12.2-STABLE before r370400, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-29631</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-29631</guid>
    <pubDate>Mon, 30 Aug 2021 18:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-29631</strong></p>
  <p>In FreeBSD 13.0-STABLE before n246941-20f96f215562, 12.2-STABLE before r370400, 11.4-STABLE before r370399, 13.0-RELEASE before p4, 12.2-RELEASE before p10, and 11.4-RELEASE before p13, certain VirtIO-based device models in bhyve failed to handle errors when fetching I/O descriptors. A malicious guest may cause the device model to operate on uninitialized I/O vectors leading to memory corruption,…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-29631">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2010-4816 – It was found in FreeBSD 8.0, 6.3 and 4.9, and OpenBSD 4.6 that a null pointer de...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-4816</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-4816</guid>
    <pubDate>Tue, 22 Jun 2021 14:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2010-4816</strong></p>
  <p>It was found in FreeBSD 8.0, 6.3 and 4.9, and OpenBSD 4.6 that a null pointer dereference in ftpd/popen.c may lead to remote denial of service of the ftpd service.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-4816">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-7469 – In FreeBSD 12.2-STABLE before r367402, 11.4-STABLE before r368202, 12.2-RELEASE ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7469</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7469</guid>
    <pubDate>Fri, 04 Jun 2021 12:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-7469</strong></p>
  <p>In FreeBSD 12.2-STABLE before r367402, 11.4-STABLE before r368202, 12.2-RELEASE before p1, 12.1-RELEASE before p11 and 11.4-RELEASE before p5 the handler for a routing option caches a pointer into the packet buffer holding the ICMPv6 message. However, when processing subsequent options the packet buffer may be freed, rendering the cached pointer invalid. The network stack may later dereference th…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7469">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-29629 – In FreeBSD 13.0-STABLE before n245765-bec0d2c9c841, 12.2-STABLE before r369859, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-29629</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-29629</guid>
    <pubDate>Fri, 28 May 2021 15:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-29629</strong></p>
  <p>In FreeBSD 13.0-STABLE before n245765-bec0d2c9c841, 12.2-STABLE before r369859, 11.4-STABLE before r369866, 13.0-RELEASE before p1, 12.2-RELEASE before p7, and 11.4-RELEASE before p10, missing message validation in libradius(3) could allow malicious clients or servers to trigger denial of service in vulnerable servers or clients respectively.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-29629">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-29628 – In FreeBSD 13.0-STABLE before n245764-876ffe28796c, 12.2-STABLE before r369857, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-29628</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-29628</guid>
    <pubDate>Fri, 28 May 2021 15:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-29628</strong></p>
  <p>In FreeBSD 13.0-STABLE before n245764-876ffe28796c, 12.2-STABLE before r369857, 13.0-RELEASE before p1, and 12.2-RELEASE before p7, a system call triggering a fault could cause SMAP protections to be disabled for the duration of the system call. This weakness could be combined with other kernel bugs to craft an exploit.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-29628">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-29627 – In FreeBSD 13.0-STABLE before n245050, 12.2-STABLE before r369525, 13.0-RC4 befo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-29627</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-29627</guid>
    <pubDate>Wed, 07 Apr 2021 15:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-29627</strong></p>
  <p>In FreeBSD 13.0-STABLE before n245050, 12.2-STABLE before r369525, 13.0-RC4 before p0, and 12.2-RELEASE before p6, listening socket accept filters implementing the accf_create callback incorrectly freed a process supplied argument string. Additional operations on the socket can lead to a double free or use after free.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-415</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-29627">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-29626 – In FreeBSD 13.0-STABLE before n245117, 12.2-STABLE before r369551, 11.4-STABLE b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-29626</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-29626</guid>
    <pubDate>Wed, 07 Apr 2021 15:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-29626</strong></p>
  <p>In FreeBSD 13.0-STABLE before n245117, 12.2-STABLE before r369551, 11.4-STABLE before r369559, 13.0-RC5 before p1, 12.2-RELEASE before p6, and 11.4-RELEASE before p9, copy-on-write logic failed to invalidate shared memory page mappings between multiple processes allowing an unprivileged process to maintain a mapping after it is freed, allowing the process to read private data belonging to other p…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-29626">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-25584 – In FreeBSD 13.0-STABLE before n245118, 12.2-STABLE before r369552, 11.4-STABLE b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-25584</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-25584</guid>
    <pubDate>Wed, 07 Apr 2021 15:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-25584</strong></p>
  <p>In FreeBSD 13.0-STABLE before n245118, 12.2-STABLE before r369552, 11.4-STABLE before r369560, 13.0-RC5 before p1, 12.2-RELEASE before p6, and 11.4-RELEASE before p9, a superuser inside a FreeBSD jail configured with the non-default allow.mount permission could cause a race condition between the lookup of ".." and remounting a filesystem, allowing access to filesystem hierarchy outside of the jai…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-25584">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-25583 – In FreeBSD 12.2-STABLE before r368250, 11.4-STABLE before r368253, 12.2-RELEASE ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-25583</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-25583</guid>
    <pubDate>Mon, 29 Mar 2021 20:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-25583</strong></p>
  <p>In FreeBSD 12.2-STABLE before r368250, 11.4-STABLE before r368253, 12.2-RELEASE before p1, 12.1-RELEASE before p11 and 11.4-RELEASE before p5 when processing a DNSSL option, rtsold(8) decodes domain name labels per an encoding specified in RFC 1035 in which the first octet of each label contains the label's length. rtsold(8) did not validate label lengths correctly and could overflow the destinat…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-25583">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-25577 – In FreeBSD 12.2-STABLE before r368250, 11.4-STABLE before r368253, 12.2-RELEASE ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-25577</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-25577</guid>
    <pubDate>Mon, 29 Mar 2021 20:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-25577</strong></p>
  <p>In FreeBSD 12.2-STABLE before r368250, 11.4-STABLE before r368253, 12.2-RELEASE before p1, 12.1-RELEASE before p11 and 11.4-RELEASE before p5 rtsold(8) does not verify that the RDNSS option does not extend past the end of the received packet before processing its contents. While the kernel currently ignores such malformed packets, it passes them to userspace programs. Any programs expecting the k…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-25577">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-7468 – In FreeBSD 12.2-STABLE before r365772, 11.4-STABLE before r365773, 12.1-RELEASE ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7468</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7468</guid>
    <pubDate>Fri, 26 Mar 2021 21:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-7468</strong></p>
  <p>In FreeBSD 12.2-STABLE before r365772, 11.4-STABLE before r365773, 12.1-RELEASE before p10, 11.4-RELEASE before p4 and 11.3-RELEASE before p14 a ftpd(8) bug in the implementation of the file system sandbox, combined with capabilities available to an authenticated FTP user, can be used to escape the file system restriction configured in ftpchroot(5). Moreover, the bug allows a malicious client to…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7468">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-7467 – In FreeBSD 12.2-STABLE before r365767, 11.4-STABLE before r365769, 12.1-RELEASE ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7467</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7467</guid>
    <pubDate>Fri, 26 Mar 2021 21:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-7467</strong></p>
  <p>In FreeBSD 12.2-STABLE before r365767, 11.4-STABLE before r365769, 12.1-RELEASE before p10, 11.4-RELEASE before p4 and 11.3-RELEASE before p14 a number of AMD virtualization instructions operate on host physical addresses, are not subject to nested page table translation, and guest use of these instructions was not trapped.</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7467">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-7464 – In FreeBSD 12.2-STABLE before r365730, 11.4-STABLE before r365738, 12.1-RELEASE ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7464</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7464</guid>
    <pubDate>Fri, 26 Mar 2021 21:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-7464</strong></p>
  <p>In FreeBSD 12.2-STABLE before r365730, 11.4-STABLE before r365738, 12.1-RELEASE before p10, 11.4-RELEASE before p4, and 11.3-RELEASE before p14, a programming error in the ure(4) device driver caused some Realtek USB Ethernet interfaces to incorrectly report packets with more than 2048 bytes in a single USB transfer as having a length of only 2048 bytes. An adversary can exploit this to cause the…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7464">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-7463 – In FreeBSD 12.1-STABLE before r364644, 11.4-STABLE before r364651, 12.1-RELEASE ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7463</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7463</guid>
    <pubDate>Fri, 26 Mar 2021 21:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-7463</strong></p>
  <p>In FreeBSD 12.1-STABLE before r364644, 11.4-STABLE before r364651, 12.1-RELEASE before p9, 11.4-RELEASE before p3, and 11.3-RELEASE before p13, improper handling in the kernel causes a use-after-free bug by sending large user messages from multiple threads on the same SCTP socket. The use-after-free situation may result in unintended kernel behaviour including a kernel panic.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7463">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-7461 – In FreeBSD 12.1-STABLE before r365010, 11.4-STABLE before r365011, 12.1-RELEASE ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7461</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7461</guid>
    <pubDate>Fri, 26 Mar 2021 21:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-7461</strong></p>
  <p>In FreeBSD 12.1-STABLE before r365010, 11.4-STABLE before r365011, 12.1-RELEASE before p9, 11.4-RELEASE before p3, and 11.3-RELEASE before p13, dhclient(8) fails to handle certain malformed input related to handling of DHCP option 119 resulting a heap overflow. The heap overflow could in principle be exploited to achieve remote code execution. The affected process runs with reduced privileges in…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7461">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-25582 – In FreeBSD 12.2-STABLE before r369334, 11.4-STABLE before r369335, 12.2-RELEASE ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-25582</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-25582</guid>
    <pubDate>Fri, 26 Mar 2021 21:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-25582</strong></p>
  <p>In FreeBSD 12.2-STABLE before r369334, 11.4-STABLE before r369335, 12.2-RELEASE before p4 and 11.4-RELEASE before p8 when a process, such as jexec(8) or killall(1), calls jail_attach(2) to enter a jail, the jailed root can attach to it using ptrace(2) before the current working directory is changed.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-25582">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-25581 – In FreeBSD 12.2-STABLE before r369312, 11.4-STABLE before r369313, 12.2-RELEASE ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-25581</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-25581</guid>
    <pubDate>Fri, 26 Mar 2021 21:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-25581</strong></p>
  <p>In FreeBSD 12.2-STABLE before r369312, 11.4-STABLE before r369313, 12.2-RELEASE before p4 and 11.4-RELEASE before p8 due to a race condition in the jail_remove(2) implementation, it may fail to kill some of the processes.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-25581">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-25580 – In FreeBSD 12.2-STABLE before r369346, 11.4-STABLE before r369345, 12.2-RELEASE ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-25580</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-25580</guid>
    <pubDate>Fri, 26 Mar 2021 21:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-25580</strong></p>
  <p>In FreeBSD 12.2-STABLE before r369346, 11.4-STABLE before r369345, 12.2-RELEASE before p4 and 11.4-RELEASE before p8 a regression in the login.access(5) rule processor has the effect of causing rules to fail to match even when they should not. This means that rules denying access may be ignored.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-697</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-25580">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-25579 – In FreeBSD 12.2-STABLE before r368969, 11.4-STABLE before r369047, 12.2-RELEASE ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-25579</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-25579</guid>
    <pubDate>Fri, 26 Mar 2021 21:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-25579</strong></p>
  <p>In FreeBSD 12.2-STABLE before r368969, 11.4-STABLE before r369047, 12.2-RELEASE before p3, 12.1-RELEASE before p13 and 11.4-RELEASE before p7 msdosfs(5) was failing to zero-fill a pair of padding fields in the dirent structure, resulting in a leak of three uninitialized bytes.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-909</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-25579">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-25578 – In FreeBSD 12.2-STABLE before r368969, 11.4-STABLE before r369047, 12.2-RELEASE ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-25578</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-25578</guid>
    <pubDate>Fri, 26 Mar 2021 21:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-25578</strong></p>
  <p>In FreeBSD 12.2-STABLE before r368969, 11.4-STABLE before r369047, 12.2-RELEASE before p3, 12.1-RELEASE before p13 and 11.4-RELEASE before p7 several file systems were not properly initializing the d_off field of the dirent structures returned by VOP_READDIR. In particular, tmpfs(5), smbfs(5), autofs(5) and mqueuefs(5) were failing to do so. As a result, eight uninitialized kernel stack bytes may…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-665</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-25578">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-29568 – An issue was discovered in Xen through 4.14.x. Some OSes (such as Linux, FreeBSD...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-29568</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-29568</guid>
    <pubDate>Tue, 15 Dec 2020 17:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-29568</strong></p>
  <p>An issue was discovered in Xen through 4.14.x. Some OSes (such as Linux, FreeBSD, and NetBSD) are processing watch events using a single thread. If the events are received faster than the thread is able to handle, they will get queued. As the queue is unbounded, a guest may be able to trigger an OOM in the backend. All systems with a FreeBSD, Linux, or NetBSD (any version) dom0 are vulnerable.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-29568">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-24718 – bhyve, as used in FreeBSD through 12.1 and illumos (e.g., OmniOS CE through r151...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-24718</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-24718</guid>
    <pubDate>Fri, 25 Sep 2020 04:23:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-24718</strong></p>
  <p>bhyve, as used in FreeBSD through 12.1 and illumos (e.g., OmniOS CE through r151034 and OpenIndiana through Hipster 2020.04), does not properly restrict VMCS and VMCB read/write operations, as demonstrated by a root user in a container on an Intel system, who can gain privileges by modifying VMCS_HOST_RIP.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-24718">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-24045 – A sandbox escape issue was discovered in TitanHQ SpamTitan Gateway 7.07. It limi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-24045</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-24045</guid>
    <pubDate>Thu, 17 Sep 2020 17:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-24045</strong></p>
  <p>A sandbox escape issue was discovered in TitanHQ SpamTitan Gateway 7.07. It limits the admin user to a restricted shell, allowing execution of a small number of tools of the operating system. The restricted shell can be bypassed by presenting a fake vmware-tools ISO image to the guest virtual machine running SpamTitan Gateway. This ISO image should contain a valid Perl script at the vmware-freebs…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-345</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-24045">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-24863 – A memory corruption vulnerability was found in the kernel function kern_getfssta...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-24863</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-24863</guid>
    <pubDate>Thu, 03 Sep 2020 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-24863</strong></p>
  <p>A memory corruption vulnerability was found in the kernel function kern_getfsstat in MidnightBSD before 1.2.7 and 1.3 through 2020-08-19, and FreeBSD through 11.4, that allows an attacker to trigger an invalid free and crash the system via a crafted size value in conjunction with an invalid mode.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-24863">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-24385 – In MidnightBSD before 1.2.6 and 1.3 before August 2020, and FreeBSD before 7, a ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-24385</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-24385</guid>
    <pubDate>Thu, 03 Sep 2020 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-24385</strong></p>
  <p>In MidnightBSD before 1.2.6 and 1.3 before August 2020, and FreeBSD before 7, a NULL pointer dereference was found in the Linux emulation layer that allows attackers to crash the running kernel. During binary interaction, td->td_emuldata in sys/compat/linux/linux_emul.h is not getting initialized and returns NULL from em_find().</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-24385">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-24717 – OpenZFS before 2.0.0-rc1, when used on FreeBSD, misinterprets group permissions ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-24717</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-24717</guid>
    <pubDate>Thu, 27 Aug 2020 19:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-24717</strong></p>
  <p>OpenZFS before 2.0.0-rc1, when used on FreeBSD, misinterprets group permissions as user permissions, as demonstrated by mode 0770 being equivalent to mode 0777.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-24717">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-24716 – OpenZFS before 2.0.0-rc1, when used on FreeBSD, allows execute permissions for a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-24716</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-24716</guid>
    <pubDate>Thu, 27 Aug 2020 19:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-24716</strong></p>
  <p>OpenZFS before 2.0.0-rc1, when used on FreeBSD, allows execute permissions for all directories.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-24716">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-7460 – In FreeBSD 12.1-STABLE before r363918, 12.1-RELEASE before p8, 11.4-STABLE befor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7460</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7460</guid>
    <pubDate>Thu, 06 Aug 2020 17:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-7460</strong></p>
  <p>In FreeBSD 12.1-STABLE before r363918, 12.1-RELEASE before p8, 11.4-STABLE before r363919, 11.4-RELEASE before p2, and 11.3-RELEASE before p12, the sendmsg system call in the compat32 subsystem on 64-bit platforms has a time-of-check to time-of-use vulnerability allowing a mailcious userspace program to modify control message headers after they were validation.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7460">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-7459 – In FreeBSD 12.1-STABLE before r362166, 12.1-RELEASE before p8, 11.4-STABLE befor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7459</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7459</guid>
    <pubDate>Thu, 06 Aug 2020 17:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-7459</strong></p>
  <p>In FreeBSD 12.1-STABLE before r362166, 12.1-RELEASE before p8, 11.4-STABLE before r362167, 11.4-RELEASE before p2, and 11.3-RELEASE before p12, missing length validation code common to mulitple USB network drivers allows a malicious USB device to write beyond the end of an allocated network packet buffer.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7459">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-7458 – In FreeBSD 12.1-STABLE before r362281, 11.4-STABLE before r362281, and 11.4-RELE...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7458</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7458</guid>
    <pubDate>Thu, 09 Jul 2020 14:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-7458</strong></p>
  <p>In FreeBSD 12.1-STABLE before r362281, 11.4-STABLE before r362281, and 11.4-RELEASE before p1, long values in the user-controlled PATH environment variable cause posix_spawnp to write beyond the end of the heap allocated stack possibly leading to arbitrary code execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7458">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-7457 – In FreeBSD 12.1-STABLE before r359565, 12.1-RELEASE before p7, 11.4-STABLE befor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7457</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7457</guid>
    <pubDate>Thu, 09 Jul 2020 14:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-7457</strong></p>
  <p>In FreeBSD 12.1-STABLE before r359565, 12.1-RELEASE before p7, 11.4-STABLE before r362975, 11.4-RELEASE before p1, and 11.3-RELEASE before p11, missing synchronization in the IPV6_2292PKTOPTIONS socket option set handler contained a race condition allowing a malicious application to modify memory after being freed, possibly resulting in code execution.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7457">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-7456 – In FreeBSD 12.1-STABLE before r361918, 12.1-RELEASE before p6, 11.4-STABLE befor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7456</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7456</guid>
    <pubDate>Tue, 09 Jun 2020 19:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-7456</strong></p>
  <p>In FreeBSD 12.1-STABLE before r361918, 12.1-RELEASE before p6, 11.4-STABLE before r361919, 11.3-RELEASE before p10, and 11.4-RC2 before p1, an invalid memory location may be used for HID items if the push/pop level is not restored within the processing of that HID item allowing an attacker with physical access to a USB port to be able to use a specially crafted USB device to gain kernel or user-s…</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7456">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-13160 – AnyDesk before 5.5.3 on Linux and FreeBSD has a format string vulnerability that...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-13160</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-13160</guid>
    <pubDate>Tue, 09 Jun 2020 17:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-13160</strong></p>
  <p>AnyDesk before 5.5.3 on Linux and FreeBSD has a format string vulnerability that can be exploited for remote code execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-134</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-13160">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-7455 – In FreeBSD 12.1-STABLE before r360973, 12.1-RELEASE before p5, 11.4-STABLE befor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7455</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7455</guid>
    <pubDate>Wed, 13 May 2020 16:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-7455</strong></p>
  <p>In FreeBSD 12.1-STABLE before r360973, 12.1-RELEASE before p5, 11.4-STABLE before r360973, 11.4-BETA1 before p1 and 11.3-RELEASE before p9, the FTP packet handler in libalias incorrectly calculates some packet length allowing disclosure of small amounts of kernel (for kernel NAT) or natd process space (for userspace natd).</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-772</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7455">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-7454 – In FreeBSD 12.1-STABLE before r360971, 12.1-RELEASE before p5, 11.4-STABLE befor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7454</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7454</guid>
    <pubDate>Wed, 13 May 2020 16:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-7454</strong></p>
  <p>In FreeBSD 12.1-STABLE before r360971, 12.1-RELEASE before p5, 11.4-STABLE before r360971, 11.4-BETA1 before p1 and 11.3-RELEASE before p9, libalias does not properly validate packet length resulting in modules causing an out of bounds read/write condition if no checking was built into the module.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7454">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-15880 – In FreeBSD 12.1-STABLE before r356911, and 12.1-RELEASE before p5, insufficient ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-15880</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-15880</guid>
    <pubDate>Wed, 13 May 2020 16:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-15880</strong></p>
  <p>In FreeBSD 12.1-STABLE before r356911, and 12.1-RELEASE before p5, insufficient checking in the cryptodev module allocated the size of a kernel buffer based on a user-supplied length allowing an unprivileged process to trigger a kernel panic.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-15880">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-15879 – In FreeBSD 12.1-STABLE before r356908, 12.1-RELEASE before p5, 11.3-STABLE befor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-15879</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-15879</guid>
    <pubDate>Wed, 13 May 2020 16:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-15879</strong></p>
  <p>In FreeBSD 12.1-STABLE before r356908, 12.1-RELEASE before p5, 11.3-STABLE before r356908, and 11.3-RELEASE before p9, a race condition in the cryptodev module permitted a data structure in the kernel to be used after it was freed, allowing an unprivileged process can overwrite arbitrary kernel memory.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-15879">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-15878 – In FreeBSD 12.1-STABLE before r352509, 11.3-STABLE before r352509, and 11.3-RELE...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-15878</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-15878</guid>
    <pubDate>Wed, 13 May 2020 16:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-15878</strong></p>
  <p>In FreeBSD 12.1-STABLE before r352509, 11.3-STABLE before r352509, and 11.3-RELEASE before p9, an unprivileged local user can trigger a use-after-free situation due to improper checking in SCTP when an application tries to update an SCTP-AUTH shared key.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-15878">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-7453 – In FreeBSD 12.1-STABLE before r359021, 12.1-RELEASE before 12.1-RELEASE-p3, 11.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7453</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7453</guid>
    <pubDate>Wed, 29 Apr 2020 00:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-7453</strong></p>
  <p>In FreeBSD 12.1-STABLE before r359021, 12.1-RELEASE before 12.1-RELEASE-p3, 11.3-STABLE before r359020, and 11.3-RELEASE before 11.3-RELEASE-p7, a missing null termination check in the jail_set configuration option "osrelease" may return more bytes with a subsequent jail_get system call allowing a malicious jail superuser with permission to create nested jails to read kernel memory.</p>
  <p><strong>CVSS:</strong> 6.0 · <strong>CWE:</strong> CWE-754</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7453">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-7452 – In FreeBSD 12.1-STABLE before r357490, 12.1-RELEASE before 12.1-RELEASE-p3, 11.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7452</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7452</guid>
    <pubDate>Wed, 29 Apr 2020 00:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-7452</strong></p>
  <p>In FreeBSD 12.1-STABLE before r357490, 12.1-RELEASE before 12.1-RELEASE-p3, 11.3-STABLE before r357489, and 11.3-RELEASE before 11.3-RELEASE-p7, incorrect use of a user-controlled pointer in the epair virtual network module allowed vnet jailed privileged users to panic the host system and potentially execute arbitrary code in the kernel.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7452">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-5614 – In FreeBSD 12.1-STABLE before r356035, 12.1-RELEASE before 12.1-RELEASE-p4, 11.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5614</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5614</guid>
    <pubDate>Wed, 29 Apr 2020 00:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-5614</strong></p>
  <p>In FreeBSD 12.1-STABLE before r356035, 12.1-RELEASE before 12.1-RELEASE-p4, 11.3-STABLE before r356036, and 11.3-RELEASE before 11.3-RELEASE-p8, incomplete packet data validation may result in accessing out-of-bounds memory leading to a kernel panic or other unpredictable results.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5614">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-15874 – In FreeBSD 12.1-STABLE before r356035, 12.1-RELEASE before 12.1-RELEASE-p4, 11.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-15874</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-15874</guid>
    <pubDate>Wed, 29 Apr 2020 00:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-15874</strong></p>
  <p>In FreeBSD 12.1-STABLE before r356035, 12.1-RELEASE before 12.1-RELEASE-p4, 11.3-STABLE before r356036, and 11.3-RELEASE before 11.3-RELEASE-p8, incomplete packet data validation may result in memory access after it has been freed leading to a kernel panic or other unpredictable results.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-15874">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-7451 – In FreeBSD 12.1-STABLE before r358739, 12.1-RELEASE before 12.1-RELEASE-p3, 11.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7451</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7451</guid>
    <pubDate>Tue, 28 Apr 2020 20:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-7451</strong></p>
  <p>In FreeBSD 12.1-STABLE before r358739, 12.1-RELEASE before 12.1-RELEASE-p3, 11.3-STABLE before r358740, and 11.3-RELEASE before 11.3-RELEASE-p7, a TCP SYN-ACK or challenge TCP-ACK segment over IPv6 that is transmitted or retransmitted does not properly initialize the Traffic Class field disclosing one byte of kernel memory over the network.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7451">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-15877 – In FreeBSD 12.1-STABLE before r356606 and 12.1-RELEASE before 12.1-RELEASE-p3, d...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-15877</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-15877</guid>
    <pubDate>Tue, 28 Apr 2020 20:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-15877</strong></p>
  <p>In FreeBSD 12.1-STABLE before r356606 and 12.1-RELEASE before 12.1-RELEASE-p3, driver specific ioctl command handlers in the ixl network driver failed to check whether the caller has sufficient privileges allowing unprivileged users to trigger updates to the device's non-volatile memory.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-15877">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-15876 – In FreeBSD 12.1-STABLE before r356089, 12.1-RELEASE before 12.1-RELEASE-p3, 11.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-15876</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-15876</guid>
    <pubDate>Tue, 28 Apr 2020 20:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-15876</strong></p>
  <p>In FreeBSD 12.1-STABLE before r356089, 12.1-RELEASE before 12.1-RELEASE-p3, 11.3-STABLE before r356090, and 11.3-RELEASE before 11.3-RELEASE-p7, driver specific ioctl command handlers in the oce network driver failed to check whether the caller has sufficient privileges allowing unprivileged users to send passthrough commands to the device firmware.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-15876">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-10566 – grub2-bhyve, as used in FreeBSD bhyve before revision 525916 2020-02-12, mishand...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-10566</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-10566</guid>
    <pubDate>Sat, 14 Mar 2020 01:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-10566</strong></p>
  <p>grub2-bhyve, as used in FreeBSD bhyve before revision 525916 2020-02-12, mishandles font loading by a guest through a grub2.cfg file, leading to a buffer overflow.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-10566">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-10565 – grub2-bhyve, as used in FreeBSD bhyve before revision 525916 2020-02-12, does no...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-10565</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-10565</guid>
    <pubDate>Sat, 14 Mar 2020 01:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-10565</strong></p>
  <p>grub2-bhyve, as used in FreeBSD bhyve before revision 525916 2020-02-12, does not validate the address provided as part of a memrw command (read_* or write_*) by a guest through a grub2.cfg file. This allows an untrusted guest to perform arbitrary read or write operations in the context of the grub-bhyve process, resulting in code execution as root on the host OS.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-10565">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2012-5365 – The IPv6 implementation in FreeBSD and NetBSD (unknown versions, year 2012 and e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-5365</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-5365</guid>
    <pubDate>Thu, 20 Feb 2020 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2012-5365</strong></p>
  <p>The IPv6 implementation in FreeBSD and NetBSD (unknown versions, year 2012 and earlier) allows remote attackers to cause a denial of service via a flood of ICMPv6 Router Advertisement packets containing multiple Routing entries.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-5365">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2012-5363 – The IPv6 implementation in FreeBSD and NetBSD (unknown versions, year 2012 and e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-5363</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-5363</guid>
    <pubDate>Thu, 20 Feb 2020 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2012-5363</strong></p>
  <p>The IPv6 implementation in FreeBSD and NetBSD (unknown versions, year 2012 and earlier) allows remote attackers to cause a denial of service via a flood of ICMPv6 Neighbor Solicitation messages, a different vulnerability than CVE-2011-2393.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-5363">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2015-2923 – The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in FreeBSD...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-2923</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-2923</guid>
    <pubDate>Thu, 20 Feb 2020 04:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2015-2923</strong></p>
  <p>The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in FreeBSD through 10.1 allows remote attackers to reconfigure a hop-limit setting via a small hop_limit value in a Router Advertisement (RA) message.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-2923">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-7450 – In FreeBSD 12.1-STABLE before r357213, 12.1-RELEASE before 12.1-RELEASE-p2, 12.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7450</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7450</guid>
    <pubDate>Tue, 18 Feb 2020 16:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-7450</strong></p>
  <p>In FreeBSD 12.1-STABLE before r357213, 12.1-RELEASE before 12.1-RELEASE-p2, 12.0-RELEASE before 12.0-RELEASE-p13, 11.3-STABLE before r357214, and 11.3-RELEASE before 11.3-RELEASE-p6, URL handling in libfetch with URLs containing username and/or password components is vulnerable to a heap buffer overflow allowing program misbehavior or malicious code execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7450">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-5613 – In FreeBSD 12.0-RELEASE before 12.0-RELEASE-p13, a missing check in the ipsec pa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5613</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5613</guid>
    <pubDate>Tue, 18 Feb 2020 16:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-5613</strong></p>
  <p>In FreeBSD 12.0-RELEASE before 12.0-RELEASE-p13, a missing check in the ipsec packet processor allows reinjection of an old packet to be accepted by the ipsec endpoint. Depending on the higher-level protocol in use over ipsec, this could allow an action to be repeated.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-345</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5613">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2019-15875 – In FreeBSD 12.1-STABLE before r354734, 12.1-RELEASE before 12.1-RELEASE-p2, 12.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-15875</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-15875</guid>
    <pubDate>Tue, 18 Feb 2020 16:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2019-15875</strong></p>
  <p>In FreeBSD 12.1-STABLE before r354734, 12.1-RELEASE before 12.1-RELEASE-p2, 12.0-RELEASE before 12.0-RELEASE-p13, 11.3-STABLE before r354735, and 11.3-RELEASE before 11.3-RELEASE-p6, due to incorrect initialization of a stack data structure, core dump files may contain up to 20 bytes of kernel data previously stored on the stack.</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-665</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-15875">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-14899 – A vulnerability was discovered in Linux, FreeBSD, OpenBSD, MacOS, iOS, and Andro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-14899</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-14899</guid>
    <pubDate>Wed, 11 Dec 2019 15:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-14899</strong></p>
  <p>A vulnerability was discovered in Linux, FreeBSD, OpenBSD, MacOS, iOS, and Android that allows a malicious access point, or an adjacent user, to determine if a connected user is using a VPN, make positive inferences about the websites they are visiting, and determine the correct sequence and acknowledgement numbers in use, allowing the bad actor to inject data into the TCP stream. This provides e…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-300</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-14899">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2012-4576 – FreeBSD: Input Validation Flaw allows local users to gain elevated privileges</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-4576</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-4576</guid>
    <pubDate>Mon, 02 Dec 2019 18:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2012-4576</strong></p>
  <p>FreeBSD: Input Validation Flaw allows local users to gain elevated privileges</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-4576">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2011-2480 – Information Disclosure vulnerability in the 802.11 stack, as used in FreeBSD bef...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-2480</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-2480</guid>
    <pubDate>Wed, 27 Nov 2019 19:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2011-2480</strong></p>
  <p>Information Disclosure vulnerability in the 802.11 stack, as used in FreeBSD before 8.2 and NetBSD when using certain non-x86 architectures. A signedness error in the IEEE80211_IOC_CHANINFO ioctl allows a local unprivileged user to cause the kernel to copy large amounts of kernel memory back to the user, disclosing potentially sensitive information.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-2480">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-18667 – /usr/local/www/freeradius_view_config.php in the freeradius3 package before 0.15...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-18667</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-18667</guid>
    <pubDate>Sat, 02 Nov 2019 16:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-18667</strong></p>
  <p>/usr/local/www/freeradius_view_config.php in the freeradius3 package before 0.15.7_3 for pfSense on FreeBSD allows a user with an XSS payload as password or username to execute arbitrary javascript code on a victim browser.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-18667">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2012-2979 – FreeBSD NSD before 3.2.13 allows remote attackers to crash a NSD child server pr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-2979</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-2979</guid>
    <pubDate>Fri, 01 Nov 2019 15:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2012-2979</strong></p>
  <p>FreeBSD NSD before 3.2.13 allows remote attackers to crash a NSD child server process (SIGSEGV) and cause a denial of service in the NSD server.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-669</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-2979">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-0061 – The management daemon (MGD) is responsible for all configuration and management ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-0061</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-0061</guid>
    <pubDate>Wed, 09 Oct 2019 20:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-0061</strong></p>
  <p>The management daemon (MGD) is responsible for all configuration and management operations in Junos OS. The Junos CLI communicates with MGD over an internal unix-domain socket and is granted special permission to open this protected mode socket. Due to a misconfiguration of the internal socket, a local, authenticated user may be able to exploit this vulnerability to gain administrative privileges…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-657</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-0061">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-5612 – In FreeBSD 12.0-STABLE before r351264, 12.0-RELEASE before 12.0-RELEASE-p10, 11...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5612</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5612</guid>
    <pubDate>Fri, 30 Aug 2019 09:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-5612</strong></p>
  <p>In FreeBSD 12.0-STABLE before r351264, 12.0-RELEASE before 12.0-RELEASE-p10, 11.3-STABLE before r351265, 11.3-RELEASE before 11.3-RELEASE-p3, and 11.2-RELEASE before 11.2-RELEASE-p14, the kernel driver for /dev/midistat implements a read handler that is not thread-safe. A multi-threaded program can exploit races in the handler to copy out kernel memory outside the boundaries of midistat's data bu…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5612">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-5611 – In FreeBSD 12.0-STABLE before r350828, 12.0-RELEASE before 12.0-RELEASE-p10, 11...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5611</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5611</guid>
    <pubDate>Fri, 30 Aug 2019 09:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-5611</strong></p>
  <p>In FreeBSD 12.0-STABLE before r350828, 12.0-RELEASE before 12.0-RELEASE-p10, 11.3-STABLE before r350829, 11.3-RELEASE before 11.3-RELEASE-p3, and 11.2-RELEASE before 11.2-RELEASE-p14, a missing check in the function to arrange data in a chain of mbufs could cause data returned not to be contiguous. Extra checks in the IPv6 stack could catch the error condition and trigger a kernel panic, leading…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5611">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-5610 – In FreeBSD 12.0-STABLE before r350637, 12.0-RELEASE before 12.0-RELEASE-p9, 11.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5610</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5610</guid>
    <pubDate>Fri, 30 Aug 2019 09:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-5610</strong></p>
  <p>In FreeBSD 12.0-STABLE before r350637, 12.0-RELEASE before 12.0-RELEASE-p9, 11.3-STABLE before r350638, 11.3-RELEASE before 11.3-RELEASE-p2, and 11.2-RELEASE before 11.2-RELEASE-p13, the bsnmp library is not properly validating the submitted length from a type-length-value encoding. A remote user could cause an out-of-bounds read or trigger a crash of the software such as bsnmpd resulting in a de…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5610">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-5609 – In FreeBSD 12.0-STABLE before r350619, 12.0-RELEASE before 12.0-RELEASE-p9, 11.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5609</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5609</guid>
    <pubDate>Fri, 30 Aug 2019 09:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-5609</strong></p>
  <p>In FreeBSD 12.0-STABLE before r350619, 12.0-RELEASE before 12.0-RELEASE-p9, 11.3-STABLE before r350619, 11.3-RELEASE before 11.3-RELEASE-p2, and 11.2-RELEASE before 11.2-RELEASE-p13, the bhyve e1000 device emulation used a guest-provided value to determine the size of the on-stack buffer without validation when TCP segmentation offload is requested for a transmitted packet. A misbehaving bhyve gu…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5609">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-5608 – In FreeBSD 12.0-STABLE before r350648, 12.0-RELEASE before 12.0-RELEASE-p9, 11.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5608</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5608</guid>
    <pubDate>Fri, 30 Aug 2019 09:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-5608</strong></p>
  <p>In FreeBSD 12.0-STABLE before r350648, 12.0-RELEASE before 12.0-RELEASE-p9, 11.3-STABLE before r350650, 11.3-RELEASE before 11.3-RELEASE-p2, and 11.2-RELEASE before 11.2-RELEASE-p13, the ICMPv6 input path incorrectly handles cases where an MLDv2 listener query packet is internally fragmented across multiple mbufs. A remote attacker may be able to cause an out-of-bounds read or write that may caus…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5608">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-5607 – In FreeBSD 12.0-STABLE before r350222, 12.0-RELEASE before 12.0-RELEASE-p8, 11.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5607</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5607</guid>
    <pubDate>Fri, 26 Jul 2019 01:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-5607</strong></p>
  <p>In FreeBSD 12.0-STABLE before r350222, 12.0-RELEASE before 12.0-RELEASE-p8, 11.3-STABLE before r350223, 11.3-RELEASE before 11.3-RELEASE-p1, and 11.2-RELEASE before 11.2-RELEASE-p12, rights transmitted over a domain socket did not properly release a reference on transmission error allowing a malicious user to cause the reference counter to wrap, forcing a free event. This could allow a malicious…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-404</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5607">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-5606 – In FreeBSD 12.0-STABLE before r349805, 12.0-RELEASE before 12.0-RELEASE-p8, 11.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5606</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5606</guid>
    <pubDate>Fri, 26 Jul 2019 01:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-5606</strong></p>
  <p>In FreeBSD 12.0-STABLE before r349805, 12.0-RELEASE before 12.0-RELEASE-p8, 11.3-STABLE before r349806, 11.3-RELEASE before 11.3-RELEASE-p1, and 11.2-RELEASE before 11.2-RELEASE-p12, code which handles close of a descriptor created by posix_openpt fails to undo a signal configuration. This causes an incorrect signal to be raised leading to a write after free of kernel memory allowing a malicious…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5606">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-5605 – In FreeBSD 11.3-STABLE before r350217, 11.3-RELEASE before 11.3-RELEASE-p1, and ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5605</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5605</guid>
    <pubDate>Fri, 26 Jul 2019 01:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-5605</strong></p>
  <p>In FreeBSD 11.3-STABLE before r350217, 11.3-RELEASE before 11.3-RELEASE-p1, and 11.2-RELEASE before 11.2-RELEASE-p12, due to insufficient initialization of memory copied to userland in the freebsd32_ioctl interface, small amounts of kernel memory may be disclosed to userland processes. This may allow an attacker to leverage this information to obtain elevated privileges either directly or indirec…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-665</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5605">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-5604 – In FreeBSD 12.0-STABLE before r350246, 12.0-RELEASE before 12.0-RELEASE-p8, 11.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5604</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5604</guid>
    <pubDate>Fri, 26 Jul 2019 01:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-5604</strong></p>
  <p>In FreeBSD 12.0-STABLE before r350246, 12.0-RELEASE before 12.0-RELEASE-p8, 11.3-STABLE before r350247, 11.3-RELEASE before 11.3-RELEASE-p1, and 11.2-RELEASE before 11.2-RELEASE-p12, the emulated XHCI device included with the bhyve hypervisor did not properly validate data provided by the guest, allowing an out-of-bounds read. This provides a malicious guest the possibility to crash the system or…</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5604">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-5603 – In FreeBSD 12.0-STABLE before r350261, 12.0-RELEASE before 12.0-RELEASE-p8, 11.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5603</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5603</guid>
    <pubDate>Fri, 26 Jul 2019 01:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-5603</strong></p>
  <p>In FreeBSD 12.0-STABLE before r350261, 12.0-RELEASE before 12.0-RELEASE-p8, 11.3-STABLE before r350263, 11.3-RELEASE before 11.3-RELEASE-p1, and 11.2-RELEASE before 11.2-RELEASE-p12, system calls operating on file descriptors as part of mqueuefs did not properly release the reference allowing a malicious user to overflow the counter allowing access to files, directories, and sockets opened by pro…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-404</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5603">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-5602 – In FreeBSD 12.0-STABLE before r349628, 12.0-RELEASE before 12.0-RELEASE-p7, 11.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5602</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5602</guid>
    <pubDate>Wed, 03 Jul 2019 19:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-5602</strong></p>
  <p>In FreeBSD 12.0-STABLE before r349628, 12.0-RELEASE before 12.0-RELEASE-p7, 11.3-PRERELEASE before r349629, 11.3-RC3 before 11.3-RC3-p1, and 11.2-RELEASE before 11.2-RELEASE-p11, a bug in the cdrom driver allows users with read access to the cdrom device to arbitrarily overwrite kernel memory when media is present thereby allowing a malicious user in the operator group to gain root privileges.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5602">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-5601 – In FreeBSD 12.0-STABLE before r347474, 12.0-RELEASE before 12.0-RELEASE-p7, 11.2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5601</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5601</guid>
    <pubDate>Wed, 03 Jul 2019 19:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-5601</strong></p>
  <p>In FreeBSD 12.0-STABLE before r347474, 12.0-RELEASE before 12.0-RELEASE-p7, 11.2-STABLE before r347475, and 11.2-RELEASE before 11.2-RELEASE-p11, a bug in the FFS implementation causes up to three bytes of kernel stack memory to be written to disk as uninitialized directory entry padding.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5601">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-5600 – In FreeBSD 12.0-STABLE before r349622, 12.0-RELEASE before 12.0-RELEASE-p7, 11.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5600</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5600</guid>
    <pubDate>Wed, 03 Jul 2019 19:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-5600</strong></p>
  <p>In FreeBSD 12.0-STABLE before r349622, 12.0-RELEASE before 12.0-RELEASE-p7, 11.3-PRERELEASE before r349624, 11.3-RC3 before 11.3-RC3-p1, and 11.2-RELEASE before 11.2-RELEASE-p11, a bug in iconv implementation may allow an attacker to write past the end of an output buffer. Depending on the implementation, an attacker may be able to create a denial of service, provoke incorrect program behavior, o…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5600">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-5599 – In FreeBSD 12.0-STABLE before r349197 and 12.0-RELEASE before 12.0-RELEASE-p6, a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5599</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5599</guid>
    <pubDate>Tue, 02 Jul 2019 21:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-5599</strong></p>
  <p>In FreeBSD 12.0-STABLE before r349197 and 12.0-RELEASE before 12.0-RELEASE-p6, a bug in the non-default RACK TCP stack can allow an attacker to cause several linked lists to grow unbounded and cause an expensive list traversal on every packet being processed, leading to resource exhaustion and a denial of service.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5599">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
