Vulnerabilities > Openafs > Openafs > 1.4.4
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2013-03-14 | CVE-2013-1795 | Numeric Errors vulnerability in Openafs Integer overflow in ptserver in OpenAFS before 1.6.2 allows remote attackers to cause a denial of service (crash) via a large list from the IdToName RPC, which triggers a heap-based buffer overflow. | 5.0 |
2013-03-14 | CVE-2013-1794 | Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Openafs Buffer overflow in certain client utilities in OpenAFS before 1.6.2 allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a long fileserver ACL entry. | 6.5 |
2009-04-09 | CVE-2009-1251 | Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products Heap-based buffer overflow in the cache manager in the client in OpenAFS 1.0 through 1.4.8 and 1.5.0 through 1.5.58 on Unix platforms allows remote attackers to cause a denial of service (system crash) or possibly execute arbitrary code via an RX response containing more data than specified in a request, related to use of XDR arrays. | 10.0 |
2009-04-09 | CVE-2009-1250 | Numeric Errors vulnerability in multiple products The cache manager in the client in OpenAFS 1.0 through 1.4.8 and 1.5.0 through 1.5.58, and IBM AFS 3.6 before Patch 19, on Linux allows remote attackers to cause a denial of service (system crash) via an RX response with a large error-code value that is interpreted as a pointer and dereferenced, related to use of the ERR_PTR macro. | 7.8 |
2008-01-04 | CVE-2007-6599 | Race Condition vulnerability in multiple products Race condition in fileserver in OpenAFS 1.3.50 through 1.4.5 and 1.5.0 through 1.5.27 allows remote attackers to cause a denial of service (daemon crash) by simultaneously acquiring and giving back file callbacks, which causes the handler for the GiveUpAllCallBacks RPC to perform linked-list operations without the host_glock lock. | 4.3 |
2007-03-20 | CVE-2007-1507 | Configuration vulnerability in Openafs The default configuration in OpenAFS 1.4.x before 1.4.4 and 1.5.x before 1.5.17 supports setuid programs within the local cell, which might allow attackers to gain privileges by spoofing a response to an AFS cache manager FetchStatus request, and setting setuid and root ownership for files in the cache. | 7.5 |