Skip to content
Noroxi

avahi records

25 published records for vendor avahi.

Researcher profile

Entered KEV
0 · 0%
Weaponized
1 · 4%
Pre-auth RCE
0
With a fix record
100%
Median publish → KEV
No record has entered KEV

All records

25 records
  • CVE-2008-5081
    38Monitor

    The originates_from_local_legacy_unicast_socket function (avahi-core/server.c) in avahi-daemon in Avahi before 0.6.24 allows remote attacker

    MediumCVSS 5.0WeaponizedEPSS 59%

    avahi · avahiDec 16, 2008

  • CVE-2017-6519
    37Monitor

    avahi-daemon in Avahi through 0.6.32 and 0.7 inadvertently responds to IPv6 unicast queries with source addresses that are not on-link, whic

    CriticalCVSS 9.1No exploitEPSS 3%

    avahi · avahiApr 30, 2017

  • CVE-2009-0758
    32Monitor

    The originates_from_local_legacy_unicast_socket function in avahi-core/server.c in avahi-daemon 0.6.23 does not account for the network byte

    HighCVSS 7.8No exploitEPSS 2%

    avahi · avahi-daemonMar 3, 2009

  • avahi-daemon-check-dns.sh in the Debian avahi package through 0.8-4 is executed as root via /etc/network/if-up.d/avahi-daemon, and allows a

    HighCVSS 7.8No exploitEPSS 0%

    avahi · avahiFeb 17, 2021

  • CVE-2011-1002
    29Monitor

    avahi-core/socket.c in avahi-daemon in Avahi before 0.6.29 allows remote attackers to cause a denial of service (infinite loop) via an empty

    MediumCVSS 5.0No exploitEPSS 29%

    avahi · avahiFeb 22, 2011

  • Avahi has a reachable assertion in lookup_start

    MediumCVSS 6.5No exploitEPSS 0%

    avahi · avahiJan 12, 2026

  • Avahi has a reachable assertion in lookup_multicast_callback

    MediumCVSS 6.5No exploitEPSS 0%

    avahi · avahiJan 12, 2026

  • Avahi has Uncontrolled Recursion in lookup_handle_cname function

    MediumCVSS 6.5No exploitEPSS 0%

    avahi · avahiJan 23, 2026

  • CVE-2021-3468
    22Monitor

    A flaw was found in avahi in versions 0.6 up to 0.8.

    MediumCVSS 5.5No exploitEPSS 0%

    avahi · avahiJun 2, 2021

  • CVE-2023-1981
    22Monitor

    A vulnerability was found in the avahi library.

    MediumCVSS 5.5No exploitEPSS 0%

    avahi · avahiMay 26, 2023

  • CVE-2021-3502
    22Monitor

    A flaw was found in avahi 0.8-5.

    MediumCVSS 5.5No exploitEPSS 0%

    avahi · avahiMay 7, 2021

  • Reachable assertion in dbus_set_host_name

    MediumCVSS 5.5No exploitEPSS 0%

    avahi · avahiNov 2, 2023

  • Reachable assertion in avahi_alternative_host_name

    MediumCVSS 5.5No exploitEPSS 0%

    avahi · avahiNov 2, 2023

  • Reachable assertion in avahi_dns_packet_append_record

    MediumCVSS 5.5No exploitEPSS 0%

    avahi · avahiNov 2, 2023

  • Reachable assertion in avahi_escape_label

    MediumCVSS 5.5No exploitEPSS 0%

    avahi · avahiNov 2, 2023

  • Reachable assertion in avahi_rdata_parse

    MediumCVSS 5.5No exploitEPSS 0%

    avahi · avahiNov 2, 2023

  • simple protocol server ignores accepts unlimited connections and logs failures without limit

    MediumCVSS 5.5No exploitEPSS 0%

    avahi · avahiDec 18, 2025

  • Avahi: Reachable assertion in `transport_flags_from_domain()` via conflicting publish flags crashes avahi-daemon

    MediumCVSS 5.5No exploitEPSS 0%

    avahi · avahiApr 3, 2026

  • Avahi has a reachable assertion in avahi_wide_area_scan_cache

    MediumCVSS 5.5No exploitEPSS 0%

    avahi · avahiJan 12, 2026

  • CVE-2006-6870
    21Monitor

    The consume_labels function in avahi-core/dns.c in Avahi before 0.6.16 allows remote attackers to cause a denial of service (infinite loop)

    MediumCVSS 5.0No exploitEPSS 2%

    avahi · avahiDec 31, 2006

  • CVE-2010-2244
    18Monitor

    The AvahiDnsPacket function in avahi-core/socket.c in avahi-daemon in Avahi 0.6.16 and 0.6.25 allows remote attackers to cause a denial of s

    MediumCVSS 4.3No exploitEPSS 2%

    avahi · avahiJul 8, 2010

  • CVE-2006-2288
    14Monitor

    Avahi before 0.6.10 allows local users to cause a denial of service (mDNS/DNS-SD service disconnect) via unspecified mDNS name conflicts.

    LowCVSS 3.6No exploitEPSS 0%

    avahi · avahiMay 9, 2006

  • Buffer overflow in avahi-core in Avahi before 0.6.10 allows local users to execute arbitrary code via unknown vectors.

    LowCVSS 2.1No exploitEPSS 0%

    avahi · avahiMay 9, 2006

  • Avahi before 0.6.15 does not verify the sender identity of netlink messages to ensure that they come from the kernel instead of another proc

    LowCVSS 2.1No exploitEPSS 0%

    avahi · avahiNov 14, 2006

  • The Avahi daemon in Avahi before 0.6.20 allows attackers to cause a denial of service (exit) via empty TXT data over D-Bus, which triggers a

    LowCVSS 2.1No exploitEPSS 0%

    avahi · avahiJun 22, 2007