avahi records
25 published records for vendor avahi.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 4%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-617 Reachable Assertion10
- CWE-400 Uncontrolled Resource Consumption2
- CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')2
- CWE-399 Resource Management Errors2
- CWE-59 Improper Link Resolution Before File Access ('Link Following')1
- CWE-346 Origin Validation Error1
The weakness classes this vendor ships most often: where to look.
CWEAll records
25 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
38Monitor | CVE-2008-5081Weaponized | The originates_from_local_legacy_unicast_socket function (avahi-core/server.c) in avahi-daemon in Avahi before 0.6.24 allows remote attackeravahi · avahi · CWE-399 | Medium5.0 | — | 59.2% | Dec 16, 2008 |
37Monitor | CVE-2017-6519No exploit | avahi-daemon in Avahi through 0.6.32 and 0.7 inadvertently responds to IPv6 unicast queries with source addresses that are not on-link, whicavahi · avahi · CWE-346 | Critical9.1 | — | 3.2% | Apr 30, 2017 |
32Monitor | CVE-2009-0758No exploit | The originates_from_local_legacy_unicast_socket function in avahi-core/server.c in avahi-daemon 0.6.23 does not account for the network byteavahi · avahi-daemon · CWE-399 | High7.8 | — | 2.0% | Mar 3, 2009 |
31Monitor | CVE-2021-26720No exploit | avahi-daemon-check-dns.sh in the Debian avahi package through 0.8-4 is executed as root via /etc/network/if-up.d/avahi-daemon, and allows a avahi · avahi · CWE-59 | High7.8 | — | 0.4% | Feb 17, 2021 |
29Monitor | CVE-2011-1002No exploit | avahi-core/socket.c in avahi-daemon in Avahi before 0.6.29 allows remote attackers to cause a denial of service (infinite loop) via an emptyavahi · avahi · CWE-835 | Medium5.0 | — | 29.4% | Feb 22, 2011 |
26Monitor | CVE-2025-68471No exploit | Avahi has a reachable assertion in lookup_startavahi · avahi · CWE-617 | Medium6.5 | — | 0.4% | Jan 12, 2026 |
26Monitor | CVE-2025-68468No exploit | Avahi has a reachable assertion in lookup_multicast_callbackavahi · avahi · CWE-617 | Medium6.5 | — | 0.4% | Jan 12, 2026 |
26Monitor | CVE-2026-24401No exploit | Avahi has Uncontrolled Recursion in lookup_handle_cname functionavahi · avahi · CWE-674 | Medium6.5 | — | 0.3% | Jan 23, 2026 |
22Monitor | CVE-2021-3468No exploit | A flaw was found in avahi in versions 0.6 up to 0.8.avahi · avahi · CWE-835 | Medium5.5 | — | 0.4% | Jun 2, 2021 |
22Monitor | CVE-2023-1981No exploit | A vulnerability was found in the avahi library.avahi · avahi · CWE-400 | Medium5.5 | — | 0.4% | May 26, 2023 |
22Monitor | CVE-2021-3502No exploit | A flaw was found in avahi 0.8-5.avahi · avahi · CWE-617 | Medium5.5 | — | 0.4% | May 7, 2021 |
22Monitor | CVE-2023-38471No exploit | Reachable assertion in dbus_set_host_nameavahi · avahi · CWE-617 | Medium5.5 | — | 0.3% | Nov 2, 2023 |
22Monitor | CVE-2023-38473No exploit | Reachable assertion in avahi_alternative_host_nameavahi · avahi · CWE-617 | Medium5.5 | — | 0.3% | Nov 2, 2023 |
22Monitor | CVE-2023-38469No exploit | Reachable assertion in avahi_dns_packet_append_recordavahi · avahi · CWE-617 | Medium5.5 | — | 0.3% | Nov 2, 2023 |
22Monitor | CVE-2023-38470No exploit | Reachable assertion in avahi_escape_labelavahi · avahi · CWE-617 | Medium5.5 | — | 0.3% | Nov 2, 2023 |
22Monitor | CVE-2023-38472No exploit | Reachable assertion in avahi_rdata_parseavahi · avahi · CWE-617 | Medium5.5 | — | 0.3% | Nov 2, 2023 |
22Monitor | CVE-2025-59529No exploit | simple protocol server ignores accepts unlimited connections and logs failures without limitavahi · avahi · CWE-400 | Medium5.5 | — | 0.2% | Dec 18, 2025 |
22Monitor | CVE-2026-34933No exploit | Avahi: Reachable assertion in `transport_flags_from_domain()` via conflicting publish flags crashes avahi-daemonavahi · avahi · CWE-617 | Medium5.5 | — | 0.2% | Apr 3, 2026 |
22Monitor | CVE-2025-68276No exploit | Avahi has a reachable assertion in avahi_wide_area_scan_cacheavahi · avahi · CWE-617 | Medium5.5 | — | 0.2% | Jan 12, 2026 |
21Monitor | CVE-2006-6870No exploit | The consume_labels function in avahi-core/dns.c in Avahi before 0.6.16 allows remote attackers to cause a denial of service (infinite loop) avahi · avahi | Medium5.0 | — | 2.4% | Dec 31, 2006 |
18Monitor | CVE-2010-2244No exploit | The AvahiDnsPacket function in avahi-core/socket.c in avahi-daemon in Avahi 0.6.16 and 0.6.25 allows remote attackers to cause a denial of savahi · avahi | Medium4.3 | — | 2.3% | Jul 8, 2010 |
14Monitor | CVE-2006-2288No exploit | Avahi before 0.6.10 allows local users to cause a denial of service (mDNS/DNS-SD service disconnect) via unspecified mDNS name conflicts.avahi · avahi | Low3.6 | — | 0.3% | May 9, 2006 |
8Monitor | CVE-2006-2289No exploit | Buffer overflow in avahi-core in Avahi before 0.6.10 allows local users to execute arbitrary code via unknown vectors.avahi · avahi | Low2.1 | — | 0.5% | May 9, 2006 |
8Monitor | CVE-2006-5461No exploit | Avahi before 0.6.15 does not verify the sender identity of netlink messages to ensure that they come from the kernel instead of another procavahi · avahi | Low2.1 | — | 0.4% | Nov 14, 2006 |
8Monitor | CVE-2007-3372No exploit | The Avahi daemon in Avahi before 0.6.20 allows attackers to cause a denial of service (exit) via empty TXT data over D-Bus, which triggers aavahi · avahi | Low2.1 | — | 0.4% | Jun 22, 2007 |
- CVE-2008-508138Monitor
The originates_from_local_legacy_unicast_socket function (avahi-core/server.c) in avahi-daemon in Avahi before 0.6.24 allows remote attacker
MediumCVSS 5.0WeaponizedEPSS 59%avahi · avahiDec 16, 2008
- CVE-2017-651937Monitor
avahi-daemon in Avahi through 0.6.32 and 0.7 inadvertently responds to IPv6 unicast queries with source addresses that are not on-link, whic
CriticalCVSS 9.1No exploitEPSS 3%avahi · avahiApr 30, 2017
- CVE-2009-075832Monitor
The originates_from_local_legacy_unicast_socket function in avahi-core/server.c in avahi-daemon 0.6.23 does not account for the network byte
HighCVSS 7.8No exploitEPSS 2%avahi · avahi-daemonMar 3, 2009
- CVE-2021-2672031Monitor
avahi-daemon-check-dns.sh in the Debian avahi package through 0.8-4 is executed as root via /etc/network/if-up.d/avahi-daemon, and allows a
HighCVSS 7.8No exploitEPSS 0%avahi · avahiFeb 17, 2021
- CVE-2011-100229Monitor
avahi-core/socket.c in avahi-daemon in Avahi before 0.6.29 allows remote attackers to cause a denial of service (infinite loop) via an empty
MediumCVSS 5.0No exploitEPSS 29%avahi · avahiFeb 22, 2011
- CVE-2025-6847126Monitor
Avahi has a reachable assertion in lookup_start
MediumCVSS 6.5No exploitEPSS 0%avahi · avahiJan 12, 2026
- CVE-2025-6846826Monitor
Avahi has a reachable assertion in lookup_multicast_callback
MediumCVSS 6.5No exploitEPSS 0%avahi · avahiJan 12, 2026
- CVE-2026-2440126Monitor
Avahi has Uncontrolled Recursion in lookup_handle_cname function
MediumCVSS 6.5No exploitEPSS 0%avahi · avahiJan 23, 2026
- CVE-2021-346822Monitor
A flaw was found in avahi in versions 0.6 up to 0.8.
MediumCVSS 5.5No exploitEPSS 0%avahi · avahiJun 2, 2021
- CVE-2023-198122Monitor
A vulnerability was found in the avahi library.
MediumCVSS 5.5No exploitEPSS 0%avahi · avahiMay 26, 2023
- CVE-2021-350222Monitor
A flaw was found in avahi 0.8-5.
MediumCVSS 5.5No exploitEPSS 0%avahi · avahiMay 7, 2021
- CVE-2023-3847122Monitor
Reachable assertion in dbus_set_host_name
MediumCVSS 5.5No exploitEPSS 0%avahi · avahiNov 2, 2023
- CVE-2023-3847322Monitor
Reachable assertion in avahi_alternative_host_name
MediumCVSS 5.5No exploitEPSS 0%avahi · avahiNov 2, 2023
- CVE-2023-3846922Monitor
Reachable assertion in avahi_dns_packet_append_record
MediumCVSS 5.5No exploitEPSS 0%avahi · avahiNov 2, 2023
- CVE-2023-3847022Monitor
Reachable assertion in avahi_escape_label
MediumCVSS 5.5No exploitEPSS 0%avahi · avahiNov 2, 2023
- CVE-2023-3847222Monitor
Reachable assertion in avahi_rdata_parse
MediumCVSS 5.5No exploitEPSS 0%avahi · avahiNov 2, 2023
- CVE-2025-5952922Monitor
simple protocol server ignores accepts unlimited connections and logs failures without limit
MediumCVSS 5.5No exploitEPSS 0%avahi · avahiDec 18, 2025
- CVE-2026-3493322Monitor
Avahi: Reachable assertion in `transport_flags_from_domain()` via conflicting publish flags crashes avahi-daemon
MediumCVSS 5.5No exploitEPSS 0%avahi · avahiApr 3, 2026
- CVE-2025-6827622Monitor
Avahi has a reachable assertion in avahi_wide_area_scan_cache
MediumCVSS 5.5No exploitEPSS 0%avahi · avahiJan 12, 2026
- CVE-2006-687021Monitor
The consume_labels function in avahi-core/dns.c in Avahi before 0.6.16 allows remote attackers to cause a denial of service (infinite loop)
MediumCVSS 5.0No exploitEPSS 2%avahi · avahiDec 31, 2006
- CVE-2010-224418Monitor
The AvahiDnsPacket function in avahi-core/socket.c in avahi-daemon in Avahi 0.6.16 and 0.6.25 allows remote attackers to cause a denial of s
MediumCVSS 4.3No exploitEPSS 2%avahi · avahiJul 8, 2010
- CVE-2006-228814Monitor
Avahi before 0.6.10 allows local users to cause a denial of service (mDNS/DNS-SD service disconnect) via unspecified mDNS name conflicts.
LowCVSS 3.6No exploitEPSS 0%avahi · avahiMay 9, 2006
- CVE-2006-22898Monitor
Buffer overflow in avahi-core in Avahi before 0.6.10 allows local users to execute arbitrary code via unknown vectors.
LowCVSS 2.1No exploitEPSS 0%avahi · avahiMay 9, 2006
- CVE-2006-54618Monitor
Avahi before 0.6.15 does not verify the sender identity of netlink messages to ensure that they come from the kernel instead of another proc
LowCVSS 2.1No exploitEPSS 0%avahi · avahiNov 14, 2006
- CVE-2007-33728Monitor
The Avahi daemon in Avahi before 0.6.20 allows attackers to cause a denial of service (exit) via empty TXT data over D-Bus, which triggers a
LowCVSS 2.1No exploitEPSS 0%avahi · avahiJun 22, 2007