CVE-2022-23125
- EPSS 4.35%
- Veröffentlicht 28.03.2023 19:15:10
- Zuletzt bearbeitet 04.11.2025 20:16:03
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the copyapplfile function. When parsing the len ...
CVE-2022-23124
- EPSS 2.84%
- Veröffentlicht 28.03.2023 19:15:10
- Zuletzt bearbeitet 04.11.2025 20:16:03
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the get_finderinfo method. The issue res...
CVE-2022-23123
- EPSS 3.85%
- Veröffentlicht 28.03.2023 19:15:10
- Zuletzt bearbeitet 04.11.2025 20:16:03
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the getdirparams method. The issue resul...
CVE-2022-23122
- EPSS 4.45%
- Veröffentlicht 28.03.2023 19:15:10
- Zuletzt bearbeitet 04.11.2025 20:16:03
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the setfilparams function. The issue results fro...
CVE-2022-23121
- EPSS 8.59%
- Veröffentlicht 28.03.2023 19:15:10
- Zuletzt bearbeitet 04.11.2025 20:16:03
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the parse_entries function. The issue results fr...
CVE-2022-0194
- EPSS 4.45%
- Veröffentlicht 28.03.2023 19:15:09
- Zuletzt bearbeitet 04.11.2025 20:16:03
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the ad_addcomment function. The issue results fr...
CVE-2022-45188
- EPSS 0.58%
- Veröffentlicht 12.11.2022 05:15:12
- Zuletzt bearbeitet 13.02.2026 20:16:14
Netatalk through 3.1.13 has an afp_getappl heap-based buffer overflow resulting in code execution via a crafted .appl file. This provides remote root access on some platforms such as FreeBSD (used for TrueNAS).
CVE-2022-22995
- EPSS 2.76%
- Veröffentlicht 25.03.2022 23:15:08
- Zuletzt bearbeitet 03.11.2025 22:15:55
The combination of primitives offered by SMB and AFP in their default configuration allows the arbitrary writing of files. By exploiting these combination of primitives, an attacker can execute arbitrary code.
CVE-2021-31439
- EPSS 2.33%
- Veröffentlicht 21.05.2021 15:15:07
- Zuletzt bearbeitet 14.01.2025 19:29:55
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Synology DiskStation Manager. Authentication is not required to exploit this vulnerablity. The specific flaw exists within the processing of D...
- EPSS 86.54%
- Veröffentlicht 20.12.2018 21:29:00
- Zuletzt bearbeitet 13.02.2026 20:16:11
Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_opensess.c. This is due to lack of bounds checking on attacker controlled data. A remote unauthenticated attacker can leverage this vulnerability to achieve arbitrary code executio...