freebsd has 3 CVEs on record. 3 were published in the last 90 days. The busiest recent month was August 2026 with 3. The median CVSS is 8.8 (high).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 8.8
- Publish → KEV
- —
- Last 90 days
- 3 prev 0
Worst active — by depth score
CVE-2026-58096High· 8.8LcpDecodeConfig() did not validate the length of received endpoint discriminator options against the minimum required by RFC 171749CVE-2026-58095High· 8.8mp_Enddisc() used incorrect length calculations when formatting endpoint discriminator addresses for display, allowing a received endpoint option to overflow a global result buffer. A malicious PPP peer can crash ppp(8) or potentially e…49CVE-2026-58097High· 7.8mp_SetEnddisc() copied a user-supplied PSN endpoint value without length validation, allowing a buffer overflow via the ppp(8) command interface. A local user with access to the ppp(8) command interface can crash ppp(8) or potentially e…43
freebsd vulnerabilities
CVEs affecting freebsd, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2026-58097High· 7.8mp_SetEnddisc() copied a user-supplied PSN endpoint value without length validation, allowing a buffer overflow via the ppp(8) command interface. A local user with access to the ppp(8) command interface can crash ppp(8) or potentially e…
mp_SetEnddisc() copied a user-supplied PSN endpoint value without length validation, allowing a buffer overflow via the ppp(8) command interface. A local user with access to the ppp(8) command interface can crash ppp(8) or potentially e…
CVE-2026-58096High· 8.8LcpDecodeConfig() did not validate the length of received endpoint discriminator options against the minimum required by RFC 1717
LcpDecodeConfig() did not validate the length of received endpoint discriminator options against the minimum required by RFC 1717. Undersized options would trigger an out-of-bounds write. A malicious PPP peer can exploit CVE-2026-58095…
CVE-2026-58095High· 8.8mp_Enddisc() used incorrect length calculations when formatting endpoint discriminator addresses for display, allowing a received endpoint option to overflow a global result buffer. A malicious PPP peer can crash ppp(8) or potentially e…
mp_Enddisc() used incorrect length calculations when formatting endpoint discriminator addresses for display, allowing a received endpoint option to overflow a global result buffer. A malicious PPP peer can crash ppp(8) or potentially e…