Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
openafs vulnerabilities and exploits
(subscribe to this query)
4
CVSSv2
CVE-2016-2860
The newEntry function in ptserver/ptprocs.c in OpenAFS prior to 1.6.17 allows remote authenticated users from foreign Kerberos realms to bypass intended access restrictions and create arbitrary groups as administrators by leveraging mishandling of the creator ID.
Openafs Openafs
Debian Debian Linux 8.0
5
CVSSv2
CVE-2015-7762
rx/rx.c in OpenAFS prior to 1.6.15 and 1.7.x prior to 1.7.33 does not properly initialize the padding of a data structure when constructing an Rx acknowledgement (ACK) packet, which allows remote malicious users to obtain sensitive information by (1) conducting a replay attack or...
Openafs Openafs 1.7.13
Openafs Openafs 1.7.14
Openafs Openafs 1.7.20
Openafs Openafs 1.7.21
Openafs Openafs 1.7.28
Openafs Openafs 1.7.29
Openafs Openafs
Openafs Openafs 1.7.1
Openafs Openafs 1.7.10
Openafs Openafs 1.7.17
Openafs Openafs 1.7.19
Openafs Openafs 1.7.24
Openafs Openafs 1.7.25
Openafs Openafs 1.7.4
Openafs Openafs 1.7.8
Openafs Openafs 1.7.15
Openafs Openafs 1.7.16
Openafs Openafs 1.7.22
Openafs Openafs 1.7.23
Openafs Openafs 1.7.3
Openafs Openafs 1.7.30
Openafs Openafs 1.7.31
5
CVSSv2
CVE-2015-7763
rx/rx.c in OpenAFS 1.5.75 up to and including 1.5.78, 1.6.x prior to 1.6.15, and 1.7.x prior to 1.7.33 does not properly initialize padding at the end of an Rx acknowledgement (ACK) packet, which allows remote malicious users to obtain sensitive information by (1) conducting a re...
Openafs Openafs 1.6.2
Openafs Openafs 1.6.3
Openafs Openafs 1.6.7
Openafs Openafs 1.6.8
Openafs Openafs 1.6.9
Openafs Openafs 1.7.10
Openafs Openafs 1.7.11
Openafs Openafs 1.7.18
Openafs Openafs 1.7.19
Openafs Openafs 1.7.26
Openafs Openafs 1.7.27
Openafs Openafs 1.7.8
Openafs Openafs 1.5.77
Openafs Openafs 1.5.78
Openafs Openafs 1.6.6
Openafs Openafs 1.6.5.1
Openafs Openafs 1.6.12
Openafs Openafs 1.6.13
Openafs Openafs 1.7.14
Openafs Openafs 1.7.15
Openafs Openafs 1.7.21
Openafs Openafs 1.7.22
4
CVSSv2
CVE-2015-6587
The vlserver in OpenAFS prior to 1.6.13 allows remote authenticated users to cause a denial of service (out-of-bounds read and crash) via a crafted regular expression in a VL_ListAttributesN2 RPC.
Openafs Openafs
Debian Debian Linux 7.0
Debian Debian Linux 8.0
4.6
CVSSv2
CVE-2015-3286
Buffer overflow in the Solaris kernel extension in OpenAFS prior to 1.6.13 allows local users to cause a denial of service (panic or deadlock) or possibly have other unspecified impact via a large group list when joining a PAG.
Openafs Openafs
4.3
CVSSv2
CVE-2015-3282
vos in OpenAFS prior to 1.6.13, when updating VLDB entries, allows remote malicious users to obtain stack data by sniffing the network.
Openafs Openafs
6.8
CVSSv2
CVE-2015-3283
OpenAFS prior to 1.6.13 allows remote malicious users to spoof bos commands via unspecified vectors.
Openafs Openafs
2.1
CVSSv2
CVE-2015-3284
pioctls in OpenAFS 1.6.x prior to 1.6.13 allows local users to read kernel memory via crafted commands.
Openafs Openafs
2.1
CVSSv2
CVE-2015-3285
The pioctl for the OSD FS command in OpenAFS prior to 1.6.13 uses the wrong pointer when writing the results of the RPC, which allows local users to cause a denial of service (memory corruption and kernel panic) via a crafted OSD FS command.
Openafs Openafs
5
CVSSv2
CVE-2014-4044
OpenAFS 1.6.8 does not properly clear the fields in the host structure, which allows remote malicious users to cause a denial of service (uninitialized memory access and crash) via unspecified vectors related to TMAY requests.
Openafs Openafs 1.6.8
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2022-48700
CVE-2022-48689
CVE-2024-27956
CVE-2023-6363
SQL
NULL pointer dereference
CVE-2023-41830
CVE-2015-2051
arbitrary
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
NEXT »