CVE-2011-0430
- EPSS 2.96%
- Published 19.02.2011 01:00:03
- Last modified 11.04.2025 00:51:21
Double free vulnerability in the Rx server process in OpenAFS 1.4.14, 1.4.12, 1.4.7, and possibly other versions allows remote attackers to cause a denial of service and execute arbitrary code via unknown vectors.
- EPSS 12.63%
- Published 09.04.2009 00:30:00
- Last modified 09.04.2025 00:30:58
Heap-based buffer overflow in the cache manager in the client in OpenAFS 1.0 through 1.4.8 and 1.5.0 through 1.5.58 on Unix platforms allows remote attackers to cause a denial of service (system crash) or possibly execute arbitrary code via an RX res...
CVE-2009-1250
- EPSS 5.85%
- Published 09.04.2009 00:30:00
- Last modified 09.04.2025 00:30:58
The cache manager in the client in OpenAFS 1.0 through 1.4.8 and 1.5.0 through 1.5.58, and IBM AFS 3.6 before Patch 19, on Linux allows remote attackers to cause a denial of service (system crash) via an RX response with a large error-code value that...
CVE-2007-6599
- EPSS 1.35%
- Published 04.01.2008 02:46:00
- Last modified 09.04.2025 00:30:58
Race condition in fileserver in OpenAFS 1.3.50 through 1.4.5 and 1.5.0 through 1.5.27 allows remote attackers to cause a denial of service (daemon crash) by simultaneously acquiring and giving back file callbacks, which causes the handler for the Giv...
CVE-2007-1507
- EPSS 1.33%
- Published 20.03.2007 10:19:00
- Last modified 09.04.2025 00:30:58
The default configuration in OpenAFS 1.4.x before 1.4.4 and 1.5.x before 1.5.17 supports setuid programs within the local cell, which might allow attackers to gain privileges by spoofing a response to an AFS cache manager FetchStatus request, and set...
CVE-2003-0028
- EPSS 56.05%
- Published 25.03.2003 05:00:00
- Last modified 03.04.2025 01:03:51
Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via ...