Vulnerabilities > Bareos > High

DATE CVE VULNERABILITY TITLE RISK
2022-03-15 CVE-2022-24756 Unspecified vulnerability in Bareos
Bareos is open source software for backup, archiving, and recovery of data for operating systems.
network
low complexity
bareos
7.5
2020-07-10 CVE-2020-11061 In Bareos Director less than or equal to 16.2.10, 17.2.9, 18.2.8, and 19.2.7, a heap overflow allows a malicious client to corrupt the director's memory via oversized digest strings sent during initialization of a verify job.
network
low complexity
bareos debian
7.4
2017-09-20 CVE-2017-14610 Improper Initialization vulnerability in Bareos
bareos-dir, bareos-fd, and bareos-sd in bareos-core in Bareos 16.2.6 and earlier create a PID file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for PID file modification before a root script executes a "kill `cat /pathname`" command.
local
low complexity
bareos CWE-665
7.8