Vulnerability index

Browse CVEs

15 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Openafs HIGH 7.8
CVE-2024-10397

A malicious server can crash the OpenAFS cache manager and other client utilities, and possibly execute arbitrary code.

Fix: 1.6.25 / 1.8.13+
Fix from $1,950 2024-11-14
Openafs HIGH 7.8
CVE-2024-10394

A local user can bypass the OpenAFS PAG (Process Authentication Group) throttling mechanism in Unix clients, allowing the user to create a PAG using …

Fix: 1.6.25 / 1.8.13+
Fix from $1,950 2024-11-14
Openafs MEDIUM 6.5
CVE-2024-10396

An authenticated user can provide a malformed ACL to the fileserver's StoreACL RPC, causing the fileserver to crash, possibly expose uninitialized me…

Fix: 1.6.25 / 1.8.13+
Fix from $1,600 2024-11-14
Openafs HIGH 7.5
CVE-2019-18601

OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to denial of service from unserialized data access because remote attackers can make a series o…

Fix: 1.6.24 / 1.8.5+
Fix from $1,950 2019-10-29
Openafs MEDIUM 5.3
CVE-2016-9772

OpenAFS 1.6.19 and earlier allows remote attackers to obtain sensitive directory information via vectors involving the (1) client cache partition, (2…

Fix: after 1.6.19
Fix from $1,600 2017-02-06
Openafs MEDIUM 5.3
CVE-2016-4536

The client in OpenAFS before 1.6.17 does not properly initialize the (1) AFSStoreStatus, (2) AFSStoreVolumeStatus, (3) VldbListByAttributes, and (4) …

Fix: after 1.6.16
Fix from $1,600 2016-05-13
Openafs MEDIUM 5.0
CVE-2015-7763

rx/rx.c in OpenAFS 1.5.75 through 1.5.78, 1.6.x before 1.6.15, and 1.7.x before 1.7.33 does not properly initialize padding at the end of an Rx ackno…

Mitigation only
Fix from $1,600 2015-11-06
Openafs MEDIUM 6.8
CVE-2015-3283

OpenAFS before 1.6.13 allows remote attackers to spoof bos commands via unspecified vectors.

Fix: after 1.6.12
Fix from $1,600 2015-08-12
Openafs MEDIUM 5.0
CVE-2014-4044

OpenAFS 1.6.8 does not properly clear the fields in the host structure, which allows remote attackers to cause a denial of service (uninitialized mem…

Mitigation only
Fix from $1,600 2014-06-17
Openafs MEDIUM 5.0
CVE-2014-2852

OpenAFS before 1.6.7 delays the listen thread when an RXS_CheckResponse fails, which allows remote attackers to cause a denial of service (performanc…

Fix: after 1.6.6
Fix from $1,600 2014-04-14
Openafs MEDIUM 5.0
CVE-2013-1795

Integer overflow in ptserver in OpenAFS before 1.6.2 allows remote attackers to cause a denial of service (crash) via a large list from the IdToName …

Fix: after 1.6.1
Fix from $1,600 2013-03-14
Openafs MEDIUM 6.5
CVE-2013-1794

Buffer overflow in certain client utilities in OpenAFS before 1.6.2 allows remote authenticated users to cause a denial of service (crash) and possib…

Fix: after 1.6.1
Fix from $1,600 2013-03-14
Openafs HIGH 7.5
CVE-2011-0430

Double free vulnerability in the Rx server process in OpenAFS 1.4.14, 1.4.12, 1.4.7, and possibly other versions allows remote attackers to cause a d…

Mitigation only
Fix from $1,950 2011-02-19
Openafs MEDIUM 5.0
CVE-2011-0431

The afs_linux_lock function in afs/LINUX/osi_vnodeops.c in the kernel module in OpenAFS 1.4.14, 1.4.12, 1.4.7, and possibly other versions does not p…

Mitigation only
Fix from $1,600 2011-02-19
Openafs HIGH 7.5
CVE-2007-1507

The default configuration in OpenAFS 1.4.x before 1.4.4 and 1.5.x before 1.5.17 supports setuid programs within the local cell, which might allow att…

Patch available
Fix from $1,950 2007-03-20