Записи openafs
36 опубликованных записей вендора openafs.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 6
- С записью об исправлении
- 97,2 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer7
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor7
- CWE-189 Numeric Errors3
- CWE-908 Use of Uninitialized Resource2
- CWE-20 Improper Input Validation2
- CWE-310 Cryptographic Issues2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
36 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
42В плане | CVE-2009-1251Эксплойта нет | Heap-based buffer overflow in the cache manager in the client in OpenAFS 1.0 through 1.4.8 and 1.5.0 through 1.5.58 on Unix platforms allowsunix · unix · CWE-119 | Критическая10,0 | — | 6,4 % | 8 апр. 2009 г. |
40В плане | CVE-2018-16947Эксплойта нет | An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2.openafs · openafs · CWE-287 | Критическая9,8 | — | 2,6 % | 11 сент. 2018 г. |
35Наблюдать | CVE-2003-0028Эксплойта нет | Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived frgnu · glibc | Высокая7,5 | — | 15,0 % | 25 мар. 2003 г. |
33Наблюдать | CVE-2024-10394Эксплойта нет | Theft of credentials in Unix client PAGsopenafs · openafs · CWE-305 | Высокая8,4 | — | 0,2 % | 14 нояб. 2024 г. |
32Наблюдать | CVE-2009-1250Эксплойта нет | The cache manager in the client in OpenAFS 1.0 through 1.4.8 and 1.5.0 through 1.5.58, and IBM AFS 3.6 before Patch 19, on Linux allows remoibm · afs · CWE-189 | Высокая7,8 | — | 4,0 % | 8 апр. 2009 г. |
31Наблюдать | CVE-2018-16949Эксплойта нет | An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2.openafs · openafs · CWE-400 | Высокая7,5 | — | 3,1 % | 11 сент. 2018 г. |
31Наблюдать | CVE-2017-17432Эксплойта нет | OpenAFS 1.x before 1.6.22 does not properly validate Rx ack packets, which allows remote attackers to cause a denial of service (system crasopenafs · openafs · CWE-617 | Высокая7,5 | — | 3,1 % | 5 дек. 2017 г. |
31Наблюдать | CVE-2011-0430Эксплойта нет | Double free vulnerability in the Rx server process in OpenAFS 1.4.14, 1.4.12, 1.4.7, and possibly other versions allows remote attackers to openafs · openafs · CWE-399 | Высокая7,5 | — | 3,0 % | 18 февр. 2011 г. |
31Наблюдать | CVE-2007-1507Эксплойта нет | The default configuration in OpenAFS 1.4.x before 1.4.4 and 1.5.x before 1.5.17 supports setuid programs within the local cell, which might openafs · openafs · CWE-16 | Высокая7,5 | — | 2,5 % | 20 мар. 2007 г. |
31Наблюдать | CVE-2018-16948Эксплойта нет | An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2.openafs · openafs · CWE-200 | Высокая7,5 | — | 2,0 % | 11 сент. 2018 г. |
31Наблюдать | CVE-2015-8312Эксплойта нет | Off-by-one error in afs_pioctl.c in OpenAFS before 1.6.16 might allow local users to cause a denial of service (memory overwrite and system openafs · openafs · CWE-189 | Высокая7,8 | — | 0,4 % | 13 мая 2016 г. |
30Наблюдать | CVE-2019-18602Эксплойта нет | OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to an information disclosure vulnerability because uninitialized scalars are sent overopenafs · openafs · CWE-908 | Высокая7,5 | — | 1,5 % | 29 окт. 2019 г. |
30Наблюдать | CVE-2019-18601Эксплойта нет | OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to denial of service from unserialized data access because remote attackers can make aopenafs · openafs · CWE-502 | Высокая7,5 | — | 1,4 % | 29 окт. 2019 г. |
30Наблюдать | CVE-2024-10397Эксплойта нет | Preallocated buffer overflows in XDR responsesopenafs · openafs · CWE-787 | Высокая7,7 | — | 0,4 % | 14 нояб. 2024 г. |
28Наблюдать | CVE-2015-3283Эксплойта нет | OpenAFS before 1.6.13 allows remote attackers to spoof bos commands via unspecified vectors.openafs · openafs · CWE-264 | Средняя6,8 | — | 2,1 % | 12 авг. 2015 г. |
27Наблюдать | CVE-2013-1794Эксплойта нет | Buffer overflow in certain client utilities in OpenAFS before 1.6.2 allows remote authenticated users to cause a denial of service (crash) aopenafs · openafs · CWE-119 | Средняя6,5 | — | 3,4 % | 13 мар. 2013 г. |
26Наблюдать | CVE-2016-2860Эксплойта нет | The newEntry function in ptserver/ptprocs.c in OpenAFS before 1.6.17 allows remote authenticated users from foreign Kerberos realms to bypasopenafs · openafs · CWE-284 | Средняя6,5 | — | 1,5 % | 13 мая 2016 г. |
26Наблюдать | CVE-2024-10396Эксплойта нет | Fileserver crash and possible information leak on StoreACL/FetchACLopenafs · openafs · CWE-772 | Средняя6,5 | — | 0,6 % | 14 нояб. 2024 г. |
23Наблюдать | CVE-2019-18603Эксплойта нет | OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to information leakage upon certain error conditions because uninitialized RPC output openafs · openafs · CWE-908 | Средняя5,9 | — | 1,2 % | 29 окт. 2019 г. |
22Наблюдать | CVE-2016-9772Эксплойта нет | OpenAFS 1.6.19 and earlier allows remote attackers to obtain sensitive directory information via vectors involving the (1) client cache partopenafs · openafs · CWE-200 | Средняя5,3 | — | 1,7 % | 6 февр. 2017 г. |
21Наблюдать | CVE-2013-1795Эксплойта нет | Integer overflow in ptserver in OpenAFS before 1.6.2 allows remote attackers to cause a denial of service (crash) via a large list from the openafs · openafs · CWE-189 | Средняя5,0 | — | 3,3 % | 13 мар. 2013 г. |
21Наблюдать | CVE-2014-0159Эксплойта нет | Buffer overflow in the GetStatistics64 remote procedure call (RPC) in OpenAFS 1.4.8 before 1.6.7 allows remote attackers to cause a denial oopenafs · openafs · CWE-119 | Средняя5,0 | — | 2,2 % | 14 апр. 2014 г. |
21Наблюдать | CVE-2015-7763Эксплойта нет | rx/rx.c in OpenAFS 1.5.75 through 1.5.78, 1.6.x before 1.6.15, and 1.7.x before 1.7.33 does not properly initialize padding at the end of anopenafs · openafs · CWE-200 | Средняя5,0 | — | 2,1 % | 6 нояб. 2015 г. |
21Наблюдать | CVE-2015-7762Эксплойта нет | rx/rx.c in OpenAFS before 1.6.15 and 1.7.x before 1.7.33 does not properly initialize the padding of a data structure when constructing an Ropenafs · openafs · CWE-200 | Средняя5,0 | — | 2,1 % | 6 нояб. 2015 г. |
21Наблюдать | CVE-2011-0431Эксплойта нет | The afs_linux_lock function in afs/LINUX/osi_vnodeops.c in the kernel module in OpenAFS 1.4.14, 1.4.12, 1.4.7, and possibly other versions dopenafs · openafs · CWE-20 | Средняя5,0 | — | 2,0 % | 18 февр. 2011 г. |
- CVE-2009-125142В плане
Heap-based buffer overflow in the cache manager in the client in OpenAFS 1.0 through 1.4.8 and 1.5.0 through 1.5.58 on Unix platforms allows
КритическаяCVSS 10,0Эксплойта нетEPSS 6 %unix · unix8 апр. 2009 г.
- CVE-2018-1694740В плане
An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %openafs · openafs11 сент. 2018 г.
- CVE-2003-002835Наблюдать
Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived fr
ВысокаяCVSS 7,5Эксплойта нетEPSS 15 %gnu · glibc25 мар. 2003 г.
- CVE-2024-1039433Наблюдать
Theft of credentials in Unix client PAGs
ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %openafs · openafs14 нояб. 2024 г.
- CVE-2009-125032Наблюдать
The cache manager in the client in OpenAFS 1.0 through 1.4.8 and 1.5.0 through 1.5.58, and IBM AFS 3.6 before Patch 19, on Linux allows remo
ВысокаяCVSS 7,8Эксплойта нетEPSS 4 %ibm · afs8 апр. 2009 г.
- CVE-2018-1694931Наблюдать
An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2.
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %openafs · openafs11 сент. 2018 г.
- CVE-2017-1743231Наблюдать
OpenAFS 1.x before 1.6.22 does not properly validate Rx ack packets, which allows remote attackers to cause a denial of service (system cras
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %openafs · openafs5 дек. 2017 г.
- CVE-2011-043031Наблюдать
Double free vulnerability in the Rx server process in OpenAFS 1.4.14, 1.4.12, 1.4.7, and possibly other versions allows remote attackers to
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %openafs · openafs18 февр. 2011 г.
- CVE-2007-150731Наблюдать
The default configuration in OpenAFS 1.4.x before 1.4.4 and 1.5.x before 1.5.17 supports setuid programs within the local cell, which might
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %openafs · openafs20 мар. 2007 г.
- CVE-2018-1694831Наблюдать
An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %openafs · openafs11 сент. 2018 г.
- CVE-2015-831231Наблюдать
Off-by-one error in afs_pioctl.c in OpenAFS before 1.6.16 might allow local users to cause a denial of service (memory overwrite and system
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %openafs · openafs13 мая 2016 г.
- CVE-2019-1860230Наблюдать
OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to an information disclosure vulnerability because uninitialized scalars are sent over
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %openafs · openafs29 окт. 2019 г.
- CVE-2019-1860130Наблюдать
OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to denial of service from unserialized data access because remote attackers can make a
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %openafs · openafs29 окт. 2019 г.
- CVE-2024-1039730Наблюдать
Preallocated buffer overflows in XDR responses
ВысокаяCVSS 7,7Эксплойта нетEPSS 0 %openafs · openafs14 нояб. 2024 г.
- CVE-2015-328328Наблюдать
OpenAFS before 1.6.13 allows remote attackers to spoof bos commands via unspecified vectors.
СредняяCVSS 6,8Эксплойта нетEPSS 2 %openafs · openafs12 авг. 2015 г.
- CVE-2013-179427Наблюдать
Buffer overflow in certain client utilities in OpenAFS before 1.6.2 allows remote authenticated users to cause a denial of service (crash) a
СредняяCVSS 6,5Эксплойта нетEPSS 3 %openafs · openafs13 мар. 2013 г.
- CVE-2016-286026Наблюдать
The newEntry function in ptserver/ptprocs.c in OpenAFS before 1.6.17 allows remote authenticated users from foreign Kerberos realms to bypas
СредняяCVSS 6,5Эксплойта нетEPSS 2 %openafs · openafs13 мая 2016 г.
- CVE-2024-1039626Наблюдать
Fileserver crash and possible information leak on StoreACL/FetchACL
СредняяCVSS 6,5Эксплойта нетEPSS 1 %openafs · openafs14 нояб. 2024 г.
- CVE-2019-1860323Наблюдать
OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to information leakage upon certain error conditions because uninitialized RPC output
СредняяCVSS 5,9Эксплойта нетEPSS 1 %openafs · openafs29 окт. 2019 г.
- CVE-2016-977222Наблюдать
OpenAFS 1.6.19 and earlier allows remote attackers to obtain sensitive directory information via vectors involving the (1) client cache part
СредняяCVSS 5,3Эксплойта нетEPSS 2 %openafs · openafs6 февр. 2017 г.
- CVE-2013-179521Наблюдать
Integer overflow in ptserver in OpenAFS before 1.6.2 allows remote attackers to cause a denial of service (crash) via a large list from the
СредняяCVSS 5,0Эксплойта нетEPSS 3 %openafs · openafs13 мар. 2013 г.
- CVE-2014-015921Наблюдать
Buffer overflow in the GetStatistics64 remote procedure call (RPC) in OpenAFS 1.4.8 before 1.6.7 allows remote attackers to cause a denial o
СредняяCVSS 5,0Эксплойта нетEPSS 2 %openafs · openafs14 апр. 2014 г.
- CVE-2015-776321Наблюдать
rx/rx.c in OpenAFS 1.5.75 through 1.5.78, 1.6.x before 1.6.15, and 1.7.x before 1.7.33 does not properly initialize padding at the end of an
СредняяCVSS 5,0Эксплойта нетEPSS 2 %openafs · openafs6 нояб. 2015 г.
- CVE-2015-776221Наблюдать
rx/rx.c in OpenAFS before 1.6.15 and 1.7.x before 1.7.33 does not properly initialize the padding of a data structure when constructing an R
СредняяCVSS 5,0Эксплойта нетEPSS 2 %openafs · openafs6 нояб. 2015 г.
- CVE-2011-043121Наблюдать
The afs_linux_lock function in afs/LINUX/osi_vnodeops.c in the kernel module in OpenAFS 1.4.14, 1.4.12, 1.4.7, and possibly other versions d
СредняяCVSS 5,0Эксплойта нетEPSS 2 %openafs · openafs18 февр. 2011 г.