linux-nfs records
6 published records for vendor linux-nfs.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-193 Off-by-one Error1
- CWE-20 Improper Input Validation1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-276 Incorrect Default Permissions1
- CWE-279 Incorrect Execution-Assigned Permissions1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
44Plan | CVE-2003-0252No exploit | Off-by-one error in the xlog function of mountd in the Linux NFS utils package (nfs-utils) before 1.0.4 allows remote attackers to cause a dlinux-nfs · nfs-utils · CWE-193 | Critical9.8 | — | 15.8% | Aug 18, 2003 |
39Monitor | CVE-2019-3689No exploit | nfs-utils: root-owned files stored in insecure /var/lib/nfs directorysuse · linux enterprise server · CWE-276 | Critical9.8 | — | 1.5% | Sep 19, 2019 |
31Monitor | CVE-2011-2500No exploit | The host_reliable_addrinfo function in support/export/hostname.c in nfs-utils before 1.2.4 does not properly use DNS to verify access to NFSlinux-nfs · nfs-utils · CWE-264 | High7.5 | — | 2.6% | Feb 15, 2014 |
26Monitor | CVE-2025-12801No exploit | Nfs-utils: rpc.mountd in the nfs-utils privilege escalationredhat · openshift container platform · CWE-279 | Medium6.5 | — | 0.5% | Mar 4, 2026 |
13Monitor | CVE-2011-1749No exploit | The nfs_addmntent function in support/nfs/nfs_mntent.c in the mount.nsf tool in nfs-utils before 1.2.4 attempts to append to the /etc/mtab flinux-nfs · nfs-utils · CWE-20 | Low3.3 | — | 0.3% | Feb 26, 2014 |
12Monitor | CVE-2013-1923No exploit | rpc-gssd in nfs-utils before 1.2.8 performs reverse DNS resolution for server names during GSSAPI authentication, which might allow remote alinux-nfs · nfs-utils · CWE-200 | Low3.2 | — | 1.0% | Jan 21, 2014 |
- CVE-2003-025244Plan
Off-by-one error in the xlog function of mountd in the Linux NFS utils package (nfs-utils) before 1.0.4 allows remote attackers to cause a d
CriticalCVSS 9.8No exploitEPSS 16%linux-nfs · nfs-utilsAug 18, 2003
- CVE-2019-368939Monitor
nfs-utils: root-owned files stored in insecure /var/lib/nfs directory
CriticalCVSS 9.8No exploitEPSS 2%suse · linux enterprise serverSep 19, 2019
- CVE-2011-250031Monitor
The host_reliable_addrinfo function in support/export/hostname.c in nfs-utils before 1.2.4 does not properly use DNS to verify access to NFS
HighCVSS 7.5No exploitEPSS 3%linux-nfs · nfs-utilsFeb 15, 2014
- CVE-2025-1280126Monitor
Nfs-utils: rpc.mountd in the nfs-utils privilege escalation
MediumCVSS 6.5No exploitEPSS 0%redhat · openshift container platformMar 4, 2026
- CVE-2011-174913Monitor
The nfs_addmntent function in support/nfs/nfs_mntent.c in the mount.nsf tool in nfs-utils before 1.2.4 attempts to append to the /etc/mtab f
LowCVSS 3.3No exploitEPSS 0%linux-nfs · nfs-utilsFeb 26, 2014
- CVE-2013-192312Monitor
rpc-gssd in nfs-utils before 1.2.8 performs reverse DNS resolution for server names during GSSAPI authentication, which might allow remote a
LowCVSS 3.2No exploitEPSS 1%linux-nfs · nfs-utilsJan 21, 2014