{"schema_version":1,"title":"NetBSD vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 11 vulnerabilities in NetBSD: 0 in the last 7 days and 2 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-57843, was published on 11 September 2026.","url":"https://junglewise.ai/threats/technologies/netbsd","json_url":"https://junglewise.ai/threats/technologies/netbsd.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/netbsd","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":4,"all_time":11,"critical":1,"exploited":0,"last_7_days":0,"last_30_days":2,"last_90_days":2,"last_365_days":3},"latest":[{"cve":"CVE-2026-57843","cvss":5.5,"epss":0.0015,"slug":"cve-2026-57843-netbsd-mm-open-information-disclosure-via-pk-kmem-flag","title":"NetBSD mm_open() information disclosure via PK_KMEM flag","severity":"medium","exploited":false,"published_at":"2026-09-11T14:17:28.067+00:00","url":"https://junglewise.ai/threats/cve-2026-57843-netbsd-mm-open-information-disclosure-via-pk-kmem-flag"},{"cve":"CVE-2026-57842","cvss":7,"epss":0.0014,"slug":"cve-2026-57842-netbsd-use-after-free-and-double-free-in-compat-netbsd32-msg-recv","title":"NetBSD use-after-free and double-free in COMPAT_NETBSD32 msg_recv_copyin","severity":"high","exploited":false,"published_at":"2026-09-11T14:17:27.873+00:00","url":"https://junglewise.ai/threats/cve-2026-57842-netbsd-use-after-free-and-double-free-in-compat-netbsd32-msg-recv"},{"cve":"CVE-2026-32849","cvss":5.5,"slug":"cve-2026-32849-netbsd-signed-integer-overflow-in-cryptodev-op","title":"NetBSD signed integer overflow in cryptodev_op","severity":"medium","exploited":false,"published_at":"2026-05-18T18:17:23.377+00:00","url":"https://junglewise.ai/threats/cve-2026-32849-netbsd-signed-integer-overflow-in-cryptodev-op"},{"cve":"CVE-1999-0323","cvss":10,"slug":"cve-1999-0323-freebsd-and-netbsd-file-integrity-bypass-in-mmap-function","title":"FreeBSD and NetBSD file integrity bypass in mmap function","severity":"critical","exploited":false,"published_at":"1998-02-20T05:00:00+00:00","url":"https://junglewise.ai/threats/cve-1999-0323-freebsd-and-netbsd-file-integrity-bypass-in-mmap-function"},{"cve":"CVE-1999-0304","cvss":7.2,"slug":"cve-1999-0304-bsd-mmap-memory-modification-via-kmem-devices","title":"BSD mmap memory modification via kmem devices","severity":"high","exploited":false,"published_at":"1998-02-01T05:00:00+00:00","url":"https://junglewise.ai/threats/cve-1999-0304-bsd-mmap-memory-modification-via-kmem-devices"},{"cve":"CVE-1999-1214","cvss":2.1,"slug":"cve-1999-1214-bsd-kernel-improper-credential-validation-in-asynchronous-i-o","title":"BSD Kernel Improper Credential Validation in Asynchronous I/O","severity":"low","exploited":false,"published_at":"1997-09-15T04:00:00+00:00","url":"https://junglewise.ai/threats/cve-1999-1214-bsd-kernel-improper-credential-validation-in-asynchronous-i-o"},{"cve":"CVE-1999-1225","cvss":5,"slug":"cve-1999-1225-linux-and-ultrix-information-disclosure-in-rpc-mountd","title":"Linux and Ultrix Information Disclosure in rpc.mountd","severity":"medium","exploited":false,"published_at":"1997-08-24T04:00:00+00:00","url":"https://junglewise.ai/threats/cve-1999-1225-linux-and-ultrix-information-disclosure-in-rpc-mountd"},{"cve":"CVE-1999-0074","cvss":6.4,"slug":"cve-1999-0074-tcp-ip-stack-sequential-port-allocation-allows-spoofing","title":"TCP/IP Stack sequential port allocation allows spoofing","severity":"medium","exploited":false,"published_at":"1997-07-01T04:00:00+00:00","url":"https://junglewise.ai/threats/cve-1999-0074-tcp-ip-stack-sequential-port-allocation-allows-spoofing"},{"cve":"CVE-1999-0628","cvss":5,"slug":"cve-1999-0628-bsd-rwhod-information-disclosure-of-machine-and-user-status","title":"BSD rwhod information disclosure of machine and user status","severity":"medium","exploited":false,"published_at":"1997-07-01T04:00:00+00:00","url":"https://junglewise.ai/threats/cve-1999-0628-bsd-rwhod-information-disclosure-of-machine-and-user-status"},{"cve":"CVE-1999-0297","cvss":7.2,"slug":"cve-1999-0297-vixie-cron-buffer-overflow-in-library","title":"Vixie Cron buffer overflow in library","severity":"high","exploited":false,"published_at":"1996-12-12T05:00:00+00:00","url":"https://junglewise.ai/threats/cve-1999-0297-vixie-cron-buffer-overflow-in-library"},{"cve":"CVE-1999-0085","cvss":7.5,"slug":"cve-1999-0085-ibm-aix-rwhod-buffer-overflow-via-long-hostname","title":"IBM AIX rwhod buffer overflow via long hostname","severity":"high","exploited":false,"published_at":"1996-08-21T04:00:00+00:00","url":"https://junglewise.ai/threats/cve-1999-0085-ibm-aix-rwhod-buffer-overflow-via-long-hostname"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[],"technology":{"hub":true,"name":"NetBSD","slug":"netbsd","vendor":{"name":"Netbsd","slug":"netbsd","url":"https://junglewise.ai/threats/vendors/netbsd"},"aliases":[],"category":"operating-system","homepage":"https://www.netbsd.org/","repo_url":"https://github.com/NetBSD/src","description":"A free, fast, secure, and highly portable Unix-like Open Source operating system.","url":"https://junglewise.ai/threats/technologies/netbsd"},"most_severe":[{"cve":"CVE-1999-0323","cvss":10,"slug":"cve-1999-0323-freebsd-and-netbsd-file-integrity-bypass-in-mmap-function","title":"FreeBSD and NetBSD file integrity bypass in mmap function","severity":"critical","exploited":false,"published_at":"1998-02-20T05:00:00+00:00","url":"https://junglewise.ai/threats/cve-1999-0323-freebsd-and-netbsd-file-integrity-bypass-in-mmap-function"},{"cve":"CVE-1999-0085","cvss":7.5,"slug":"cve-1999-0085-ibm-aix-rwhod-buffer-overflow-via-long-hostname","title":"IBM AIX rwhod buffer overflow via long hostname","severity":"high","exploited":false,"published_at":"1996-08-21T04:00:00+00:00","url":"https://junglewise.ai/threats/cve-1999-0085-ibm-aix-rwhod-buffer-overflow-via-long-hostname"},{"cve":"CVE-1999-0304","cvss":7.2,"slug":"cve-1999-0304-bsd-mmap-memory-modification-via-kmem-devices","title":"BSD mmap memory modification via kmem devices","severity":"high","exploited":false,"published_at":"1998-02-01T05:00:00+00:00","url":"https://junglewise.ai/threats/cve-1999-0304-bsd-mmap-memory-modification-via-kmem-devices"},{"cve":"CVE-1999-0297","cvss":7.2,"slug":"cve-1999-0297-vixie-cron-buffer-overflow-in-library","title":"Vixie Cron buffer overflow in library","severity":"high","exploited":false,"published_at":"1996-12-12T05:00:00+00:00","url":"https://junglewise.ai/threats/cve-1999-0297-vixie-cron-buffer-overflow-in-library"},{"cve":"CVE-2026-57842","cvss":7,"epss":0.0014,"slug":"cve-2026-57842-netbsd-use-after-free-and-double-free-in-compat-netbsd32-msg-recv","title":"NetBSD use-after-free and double-free in COMPAT_NETBSD32 msg_recv_copyin","severity":"high","exploited":false,"published_at":"2026-09-11T14:17:27.873+00:00","url":"https://junglewise.ai/threats/cve-2026-57842-netbsd-use-after-free-and-double-free-in-compat-netbsd32-msg-recv"},{"cve":"CVE-1999-0074","cvss":6.4,"slug":"cve-1999-0074-tcp-ip-stack-sequential-port-allocation-allows-spoofing","title":"TCP/IP Stack sequential port allocation allows spoofing","severity":"medium","exploited":false,"published_at":"1997-07-01T04:00:00+00:00","url":"https://junglewise.ai/threats/cve-1999-0074-tcp-ip-stack-sequential-port-allocation-allows-spoofing"},{"cve":"CVE-2026-57843","cvss":5.5,"epss":0.0015,"slug":"cve-2026-57843-netbsd-mm-open-information-disclosure-via-pk-kmem-flag","title":"NetBSD mm_open() information disclosure via PK_KMEM flag","severity":"medium","exploited":false,"published_at":"2026-09-11T14:17:28.067+00:00","url":"https://junglewise.ai/threats/cve-2026-57843-netbsd-mm-open-information-disclosure-via-pk-kmem-flag"},{"cve":"CVE-2026-32849","cvss":5.5,"slug":"cve-2026-32849-netbsd-signed-integer-overflow-in-cryptodev-op","title":"NetBSD signed integer overflow in cryptodev_op","severity":"medium","exploited":false,"published_at":"2026-05-18T18:17:23.377+00:00","url":"https://junglewise.ai/threats/cve-2026-32849-netbsd-signed-integer-overflow-in-cryptodev-op"},{"cve":"CVE-1999-1225","cvss":5,"slug":"cve-1999-1225-linux-and-ultrix-information-disclosure-in-rpc-mountd","title":"Linux and Ultrix Information Disclosure in rpc.mountd","severity":"medium","exploited":false,"published_at":"1997-08-24T04:00:00+00:00","url":"https://junglewise.ai/threats/cve-1999-1225-linux-and-ultrix-information-disclosure-in-rpc-mountd"},{"cve":"CVE-1999-0628","cvss":5,"slug":"cve-1999-0628-bsd-rwhod-information-disclosure-of-machine-and-user-status","title":"BSD rwhod information disclosure of machine and user status","severity":"medium","exploited":false,"published_at":"1997-07-01T04:00:00+00:00","url":"https://junglewise.ai/threats/cve-1999-0628-bsd-rwhod-information-disclosure-of-machine-and-user-status"}],"generated_at":"2026-09-26T09:11:00.170868+00:00"}