The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade freebsd to version 14.3.0-p16, 14.4.0-p7, 15.0.0-p11, 15.1.0-p1 or higher.
Affected versions of this package are vulnerable to Use of Uninitialized Resource in the ktls_ocf_tls_cbc_decrypt process. An attacker can trigger a kernel panic by sending specially crafted TLS 1.2 CBC records that manipulate TCP segmentation so the first mbuf contains only the 5-byte TLS record header, causing the kernel to read from uninitialized memory during HMAC computation. This is only exploitable if the remote peer can control TCP segmentation to isolate the TLS header in the first mbuf.