Skip to main content

Vendor archive

netatalk CVEs

Beta · best-effort

17 CVEs tagged to vendor netatalk13 Critical, 3 High, 0 Medium, 1 Low, 0 Unrated.

CVE-2024-38441

Published Jun 16, 2024

Netatalk before 3.2.1 has an off-by-one error and resultant heap-based buffer overflow because of setting ibuf[len] to '\0' in FPMapName in afp_mapname in etc/afpd/directory.c. 2.…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-38440

Published Jun 16, 2024

Netatalk before 3.2.1 has an off-by-one error, and resultant heap-based buffer overflow and segmentation violation, because of incorrectly using FPLoginExt in BN_bin2bn in etc/uam…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-38439

Published Jun 16, 2024

Netatalk before 3.2.1 has an off-by-one error and resultant heap-based buffer overflow because of setting ibuf[PASSWDLEN] to '\0' in FPLoginExt in login in etc/uams/uams_pam.c. 2.…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-42464

Published Sep 20, 2023

A Type Confusion vulnerability was found in the Spotlight RPC functions in afpd in Netatalk 3.1.x before 3.1.17. When parsing Spotlight RPC packets, one encoded data structure is…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-43634

Published Mar 29, 2023

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The speci…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-23125

Published Mar 28, 2023

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The speci…

CVSS 9.8 · Critical
evidence mentions
5
Buzz score
27.4
Vendor/product tagsBeta · best-effort

CVE-2022-23124

Published Mar 28, 2023

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. T…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
21.9
Vendor/product tagsBeta · best-effort

CVE-2022-23123

Published Mar 28, 2023

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. T…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
21.9
Vendor/product tagsBeta · best-effort

CVE-2022-23122

Published Mar 28, 2023

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The speci…

CVSS 9.8 · Critical
evidence mentions
5
Buzz score
27.4
Vendor/product tagsBeta · best-effort

CVE-2022-23121

Published Mar 28, 2023

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The speci…

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
25.6
Vendor/product tagsBeta · best-effort

CVE-2022-0194

Published Mar 28, 2023

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The speci…

CVSS 9.8 · Critical
evidence mentions
5
Buzz score
27.4
Vendor/product tagsBeta · best-effort

CVE-2008-5718

Published Dec 26, 2008

The papd daemon in Netatalk before 2.0.4-beta2, when using certain variables in a pipe command for the print file, allows remote attackers to execute arbitrary commands via shell…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-17 of 17 CVEsPage 1 of 1