openafs kayıtları
openafs üreticisine ait 36 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 6
- Düzeltme kaydı olan
- %97,2
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer7
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor7
- CWE-189 Numeric Errors3
- CWE-908 Use of Uninitialized Resource2
- CWE-20 Improper Input Validation2
- CWE-310 Cryptographic Issues2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
36 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
42Planlayın | CVE-2009-1251İstismar yok | Heap-based buffer overflow in the cache manager in the client in OpenAFS 1.0 through 1.4.8 and 1.5.0 through 1.5.58 on Unix platforms allowsunix · unix · CWE-119 | Kritik10,0 | — | %6,4 | 8 Nis 2009 |
40Planlayın | CVE-2018-16947İstismar yok | An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2.openafs · openafs · CWE-287 | Kritik9,8 | — | %2,6 | 11 Eyl 2018 |
35İzleyin | CVE-2003-0028İstismar yok | Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived frgnu · glibc | Yüksek7,5 | — | %15,0 | 25 Mar 2003 |
33İzleyin | CVE-2024-10394İstismar yok | Theft of credentials in Unix client PAGsopenafs · openafs · CWE-305 | Yüksek8,4 | — | %0,2 | 14 Kas 2024 |
32İzleyin | CVE-2009-1250İstismar yok | The cache manager in the client in OpenAFS 1.0 through 1.4.8 and 1.5.0 through 1.5.58, and IBM AFS 3.6 before Patch 19, on Linux allows remoibm · afs · CWE-189 | Yüksek7,8 | — | %4,0 | 8 Nis 2009 |
31İzleyin | CVE-2018-16949İstismar yok | An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2.openafs · openafs · CWE-400 | Yüksek7,5 | — | %3,1 | 11 Eyl 2018 |
31İzleyin | CVE-2017-17432İstismar yok | OpenAFS 1.x before 1.6.22 does not properly validate Rx ack packets, which allows remote attackers to cause a denial of service (system crasopenafs · openafs · CWE-617 | Yüksek7,5 | — | %3,1 | 5 Ara 2017 |
31İzleyin | CVE-2011-0430İstismar yok | Double free vulnerability in the Rx server process in OpenAFS 1.4.14, 1.4.12, 1.4.7, and possibly other versions allows remote attackers to openafs · openafs · CWE-399 | Yüksek7,5 | — | %3,0 | 18 Şub 2011 |
31İzleyin | CVE-2007-1507İstismar yok | The default configuration in OpenAFS 1.4.x before 1.4.4 and 1.5.x before 1.5.17 supports setuid programs within the local cell, which might openafs · openafs · CWE-16 | Yüksek7,5 | — | %2,5 | 20 Mar 2007 |
31İzleyin | CVE-2018-16948İstismar yok | An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2.openafs · openafs · CWE-200 | Yüksek7,5 | — | %2,0 | 11 Eyl 2018 |
31İzleyin | CVE-2015-8312İstismar yok | Off-by-one error in afs_pioctl.c in OpenAFS before 1.6.16 might allow local users to cause a denial of service (memory overwrite and system openafs · openafs · CWE-189 | Yüksek7,8 | — | %0,4 | 13 May 2016 |
30İzleyin | CVE-2019-18602İstismar yok | OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to an information disclosure vulnerability because uninitialized scalars are sent overopenafs · openafs · CWE-908 | Yüksek7,5 | — | %1,5 | 29 Eki 2019 |
30İzleyin | CVE-2019-18601İstismar yok | OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to denial of service from unserialized data access because remote attackers can make aopenafs · openafs · CWE-502 | Yüksek7,5 | — | %1,4 | 29 Eki 2019 |
30İzleyin | CVE-2024-10397İstismar yok | Preallocated buffer overflows in XDR responsesopenafs · openafs · CWE-787 | Yüksek7,7 | — | %0,4 | 14 Kas 2024 |
28İzleyin | CVE-2015-3283İstismar yok | OpenAFS before 1.6.13 allows remote attackers to spoof bos commands via unspecified vectors.openafs · openafs · CWE-264 | Orta6,8 | — | %2,1 | 12 Ağu 2015 |
27İzleyin | CVE-2013-1794İstismar yok | Buffer overflow in certain client utilities in OpenAFS before 1.6.2 allows remote authenticated users to cause a denial of service (crash) aopenafs · openafs · CWE-119 | Orta6,5 | — | %3,4 | 13 Mar 2013 |
26İzleyin | CVE-2016-2860İstismar yok | The newEntry function in ptserver/ptprocs.c in OpenAFS before 1.6.17 allows remote authenticated users from foreign Kerberos realms to bypasopenafs · openafs · CWE-284 | Orta6,5 | — | %1,5 | 13 May 2016 |
26İzleyin | CVE-2024-10396İstismar yok | Fileserver crash and possible information leak on StoreACL/FetchACLopenafs · openafs · CWE-772 | Orta6,5 | — | %0,6 | 14 Kas 2024 |
23İzleyin | CVE-2019-18603İstismar yok | OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to information leakage upon certain error conditions because uninitialized RPC output openafs · openafs · CWE-908 | Orta5,9 | — | %1,2 | 29 Eki 2019 |
22İzleyin | CVE-2016-9772İstismar yok | OpenAFS 1.6.19 and earlier allows remote attackers to obtain sensitive directory information via vectors involving the (1) client cache partopenafs · openafs · CWE-200 | Orta5,3 | — | %1,7 | 6 Şub 2017 |
21İzleyin | CVE-2013-1795İstismar yok | Integer overflow in ptserver in OpenAFS before 1.6.2 allows remote attackers to cause a denial of service (crash) via a large list from the openafs · openafs · CWE-189 | Orta5,0 | — | %3,3 | 13 Mar 2013 |
21İzleyin | CVE-2014-0159İstismar yok | Buffer overflow in the GetStatistics64 remote procedure call (RPC) in OpenAFS 1.4.8 before 1.6.7 allows remote attackers to cause a denial oopenafs · openafs · CWE-119 | Orta5,0 | — | %2,2 | 14 Nis 2014 |
21İzleyin | CVE-2015-7763İstismar yok | rx/rx.c in OpenAFS 1.5.75 through 1.5.78, 1.6.x before 1.6.15, and 1.7.x before 1.7.33 does not properly initialize padding at the end of anopenafs · openafs · CWE-200 | Orta5,0 | — | %2,1 | 6 Kas 2015 |
21İzleyin | CVE-2015-7762İstismar yok | rx/rx.c in OpenAFS before 1.6.15 and 1.7.x before 1.7.33 does not properly initialize the padding of a data structure when constructing an Ropenafs · openafs · CWE-200 | Orta5,0 | — | %2,1 | 6 Kas 2015 |
21İzleyin | CVE-2011-0431İstismar yok | The afs_linux_lock function in afs/LINUX/osi_vnodeops.c in the kernel module in OpenAFS 1.4.14, 1.4.12, 1.4.7, and possibly other versions dopenafs · openafs · CWE-20 | Orta5,0 | — | %2,0 | 18 Şub 2011 |
- CVE-2009-125142Planlayın
Heap-based buffer overflow in the cache manager in the client in OpenAFS 1.0 through 1.4.8 and 1.5.0 through 1.5.58 on Unix platforms allows
KritikCVSS 10,0İstismar yokEPSS %6unix · unix8 Nis 2009
- CVE-2018-1694740Planlayın
An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2.
KritikCVSS 9,8İstismar yokEPSS %3openafs · openafs11 Eyl 2018
- CVE-2003-002835İzleyin
Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived fr
YüksekCVSS 7,5İstismar yokEPSS %15gnu · glibc25 Mar 2003
- CVE-2024-1039433İzleyin
Theft of credentials in Unix client PAGs
YüksekCVSS 8,4İstismar yokEPSS %0openafs · openafs14 Kas 2024
- CVE-2009-125032İzleyin
The cache manager in the client in OpenAFS 1.0 through 1.4.8 and 1.5.0 through 1.5.58, and IBM AFS 3.6 before Patch 19, on Linux allows remo
YüksekCVSS 7,8İstismar yokEPSS %4ibm · afs8 Nis 2009
- CVE-2018-1694931İzleyin
An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2.
YüksekCVSS 7,5İstismar yokEPSS %3openafs · openafs11 Eyl 2018
- CVE-2017-1743231İzleyin
OpenAFS 1.x before 1.6.22 does not properly validate Rx ack packets, which allows remote attackers to cause a denial of service (system cras
YüksekCVSS 7,5İstismar yokEPSS %3openafs · openafs5 Ara 2017
- CVE-2011-043031İzleyin
Double free vulnerability in the Rx server process in OpenAFS 1.4.14, 1.4.12, 1.4.7, and possibly other versions allows remote attackers to
YüksekCVSS 7,5İstismar yokEPSS %3openafs · openafs18 Şub 2011
- CVE-2007-150731İzleyin
The default configuration in OpenAFS 1.4.x before 1.4.4 and 1.5.x before 1.5.17 supports setuid programs within the local cell, which might
YüksekCVSS 7,5İstismar yokEPSS %3openafs · openafs20 Mar 2007
- CVE-2018-1694831İzleyin
An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2.
YüksekCVSS 7,5İstismar yokEPSS %2openafs · openafs11 Eyl 2018
- CVE-2015-831231İzleyin
Off-by-one error in afs_pioctl.c in OpenAFS before 1.6.16 might allow local users to cause a denial of service (memory overwrite and system
YüksekCVSS 7,8İstismar yokEPSS %0openafs · openafs13 May 2016
- CVE-2019-1860230İzleyin
OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to an information disclosure vulnerability because uninitialized scalars are sent over
YüksekCVSS 7,5İstismar yokEPSS %2openafs · openafs29 Eki 2019
- CVE-2019-1860130İzleyin
OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to denial of service from unserialized data access because remote attackers can make a
YüksekCVSS 7,5İstismar yokEPSS %1openafs · openafs29 Eki 2019
- CVE-2024-1039730İzleyin
Preallocated buffer overflows in XDR responses
YüksekCVSS 7,7İstismar yokEPSS %0openafs · openafs14 Kas 2024
- CVE-2015-328328İzleyin
OpenAFS before 1.6.13 allows remote attackers to spoof bos commands via unspecified vectors.
OrtaCVSS 6,8İstismar yokEPSS %2openafs · openafs12 Ağu 2015
- CVE-2013-179427İzleyin
Buffer overflow in certain client utilities in OpenAFS before 1.6.2 allows remote authenticated users to cause a denial of service (crash) a
OrtaCVSS 6,5İstismar yokEPSS %3openafs · openafs13 Mar 2013
- CVE-2016-286026İzleyin
The newEntry function in ptserver/ptprocs.c in OpenAFS before 1.6.17 allows remote authenticated users from foreign Kerberos realms to bypas
OrtaCVSS 6,5İstismar yokEPSS %2openafs · openafs13 May 2016
- CVE-2024-1039626İzleyin
Fileserver crash and possible information leak on StoreACL/FetchACL
OrtaCVSS 6,5İstismar yokEPSS %1openafs · openafs14 Kas 2024
- CVE-2019-1860323İzleyin
OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to information leakage upon certain error conditions because uninitialized RPC output
OrtaCVSS 5,9İstismar yokEPSS %1openafs · openafs29 Eki 2019
- CVE-2016-977222İzleyin
OpenAFS 1.6.19 and earlier allows remote attackers to obtain sensitive directory information via vectors involving the (1) client cache part
OrtaCVSS 5,3İstismar yokEPSS %2openafs · openafs6 Şub 2017
- CVE-2013-179521İzleyin
Integer overflow in ptserver in OpenAFS before 1.6.2 allows remote attackers to cause a denial of service (crash) via a large list from the
OrtaCVSS 5,0İstismar yokEPSS %3openafs · openafs13 Mar 2013
- CVE-2014-015921İzleyin
Buffer overflow in the GetStatistics64 remote procedure call (RPC) in OpenAFS 1.4.8 before 1.6.7 allows remote attackers to cause a denial o
OrtaCVSS 5,0İstismar yokEPSS %2openafs · openafs14 Nis 2014
- CVE-2015-776321İzleyin
rx/rx.c in OpenAFS 1.5.75 through 1.5.78, 1.6.x before 1.6.15, and 1.7.x before 1.7.33 does not properly initialize padding at the end of an
OrtaCVSS 5,0İstismar yokEPSS %2openafs · openafs6 Kas 2015
- CVE-2015-776221İzleyin
rx/rx.c in OpenAFS before 1.6.15 and 1.7.x before 1.7.33 does not properly initialize the padding of a data structure when constructing an R
OrtaCVSS 5,0İstismar yokEPSS %2openafs · openafs6 Kas 2015
- CVE-2011-043121İzleyin
The afs_linux_lock function in afs/LINUX/osi_vnodeops.c in the kernel module in OpenAFS 1.4.14, 1.4.12, 1.4.7, and possibly other versions d
OrtaCVSS 5,0İstismar yokEPSS %2openafs · openafs18 Şub 2011