CVE-2024-52616
- EPSS 0.2%
- Veröffentlicht 21.11.2024 21:15:24
- Zuletzt bearbeitet 14.05.2025 00:15:17
A flaw was found in the Avahi-daemon, where it initializes DNS transaction IDs randomly only once at startup, incrementing them sequentially after that. This predictable behavior facilitates DNS spoofing attacks, allowing attackers to guess transacti...
CVE-2024-52615
- EPSS 0.2%
- Veröffentlicht 21.11.2024 21:15:23
- Zuletzt bearbeitet 23.09.2025 10:15:34
A flaw was found in Avahi-daemon, which relies on fixed source ports for wide-area DNS queries. This issue simplifies attacks where malicious DNS responses are injected.
CVE-2023-38473
- EPSS 0.01%
- Veröffentlicht 02.11.2023 16:15:08
- Zuletzt bearbeitet 21.11.2024 08:13:39
A vulnerability was found in Avahi. A reachable assertion exists in the avahi_alternative_host_name() function.
CVE-2023-38472
- EPSS 0.01%
- Veröffentlicht 02.11.2023 15:15:08
- Zuletzt bearbeitet 21.11.2024 08:13:38
A vulnerability was found in Avahi. A reachable assertion exists in the avahi_rdata_parse() function.
CVE-2023-38471
- EPSS 0.01%
- Veröffentlicht 02.11.2023 15:15:08
- Zuletzt bearbeitet 21.11.2024 08:13:38
A vulnerability was found in Avahi. A reachable assertion exists in the dbus_set_host_name function.
CVE-2023-38470
- EPSS 0.01%
- Veröffentlicht 02.11.2023 15:15:08
- Zuletzt bearbeitet 21.11.2024 08:13:38
A vulnerability was found in Avahi. A reachable assertion exists in the avahi_escape_label() function.
CVE-2023-38469
- EPSS 0.01%
- Veröffentlicht 02.11.2023 15:15:08
- Zuletzt bearbeitet 21.11.2024 08:13:38
A vulnerability was found in Avahi, where a reachable assertion exists in avahi_dns_packet_append_record.
CVE-2023-1981
- EPSS 0.02%
- Veröffentlicht 26.05.2023 18:15:11
- Zuletzt bearbeitet 15.01.2025 22:15:25
A vulnerability was found in the avahi library. This flaw allows an unprivileged user to make a dbus call, causing the avahi daemon to crash.
CVE-2021-3468
- EPSS 0.01%
- Veröffentlicht 02.06.2021 16:15:08
- Zuletzt bearbeitet 21.11.2024 06:21:36
A flaw was found in avahi in versions 0.6 up to 0.8. The event used to signal the termination of the client connection on the avahi Unix socket is not correctly handled in the client_work function, allowing a local attacker to trigger an infinite loo...
CVE-2021-3502
- EPSS 0.03%
- Veröffentlicht 07.05.2021 12:15:07
- Zuletzt bearbeitet 21.11.2024 06:21:41
A flaw was found in avahi 0.8-5. A reachable assertion is present in avahi_s_host_name_resolver_start function allowing a local attacker to crash the avahi service by requesting hostname resolutions through the avahi socket or dbus methods for invali...