Vulnerabilities > Openafs > Openafs > 1.3.73

DATE CVE VULNERABILITY TITLE RISK
2013-03-14 CVE-2013-1795 Numeric Errors vulnerability in Openafs
Integer overflow in ptserver in OpenAFS before 1.6.2 allows remote attackers to cause a denial of service (crash) via a large list from the IdToName RPC, which triggers a heap-based buffer overflow.
network
low complexity
openafs CWE-189
5.0
2013-03-14 CVE-2013-1794 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Openafs
Buffer overflow in certain client utilities in OpenAFS before 1.6.2 allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a long fileserver ACL entry.
network
low complexity
openafs CWE-119
6.5
2008-01-04 CVE-2007-6599 Race Condition vulnerability in multiple products
Race condition in fileserver in OpenAFS 1.3.50 through 1.4.5 and 1.5.0 through 1.5.27 allows remote attackers to cause a denial of service (daemon crash) by simultaneously acquiring and giving back file callbacks, which causes the handler for the GiveUpAllCallBacks RPC to perform linked-list operations without the host_glock lock.
4.3