Netatalk
netatalk
17 CVEs • 2 products
Products (2)
Click to collapseToggle
Products (2)
Click to collapse
CVEs (17)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Netatalk before 3.2.1 has an off-by-one error and resultant heap-based buffer overflow because of setting ibuf[len] to '\0' in FPMapName in afp_mapname in etc/afpd/directory.c. 2.4.1 and 3.1.19 are also fixed versions. |
Netatalk before 3.2.1 has an off-by-one error, and resultant heap-based buffer overflow and segmentation violation, because of incorrectly using FPLoginExt in BN_bin2bn in etc/uams/uams_dhx_pam.c. The original issue 1097...Show more |
Netatalk before 3.2.1 has an off-by-one error and resultant heap-based buffer overflow because of setting ibuf[PASSWDLEN] to '\0' in FPLoginExt in login in etc/uams/uams_pam.c. 2.4.1 and 3.1.19 are also fixed versions. |
2Debian Netatalk2Debian Linux NetatalkJun 17, 2026 Sep 20, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A Type Confusion vulnerability was found in the Spotlight RPC functions in afpd in Netatalk 3.1.x before 3.1.17. When parsing Spotlight RPC packets, one encoded data structure is a key-value style dictionary where the ke...Show more |
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the dsi_writeinit...Show more |
2Debian Netatalk2Debian Linux NetatalkJun 17, 2026 Mar 28, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the copyapplfile f...Show more |
2Debian Netatalk2Debian Linux NetatalkJun 17, 2026 Mar 28, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 This vulnerability allows remote attackers to disclose sensitive information on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the get_fi...Show more |
2Debian Netatalk2Debian Linux NetatalkJun 17, 2026 Mar 28, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 This vulnerability allows remote attackers to disclose sensitive information on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the getdir...Show more |
2Debian Netatalk2Debian Linux NetatalkJun 17, 2026 Mar 28, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the setfilparams f...Show more |
2Debian Netatalk2Debian Linux NetatalkJun 17, 2026 Mar 28, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the parse_entries...Show more |
2Debian Netatalk2Debian Linux NetatalkJun 17, 2026 Mar 28, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the ad_addcomment...Show more |
3Debian FedoraprojectNetatalk3Debian Linux FedoraNetatalkJun 17, 2026 Nov 12, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 Netatalk through 3.1.13 has an afp_getappl heap-based buffer overflow resulting in code execution via a crafted .appl file. This provides remote root access on some platforms such as FreeBSD (used for TrueNAS). |
3Fedoraproject NetatalkWesterndigital13Fedora My Cloud Dl2100 FirmwareMy Cloud Dl4100 Firmware+10 moreJun 17, 2026 Mar 25, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The combination of primitives offered by SMB and AFP in their default configuration allows the arbitrary writing of files. By exploiting these combination of primitives, an attacker can execute arbitrary code. |
3Debian NetatalkSynology3Debian Linux Diskstation ManagerNetatalkJun 17, 2026 May 21, 2021 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Synology DiskStation Manager. Authentication is not required to exploit this vulnerablity. The specific flaw exi...Show more |
3Debian NetatalkSynology6Debian Linux Diskstation ManagerNetatalk+3 moreFeb 13, 2026 Dec 20, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_opensess.c. This is due to lack of bounds checking on attacker controlled data. A remote unauthenticated attacker can leverage this vulnerability to a...Show more |
The papd daemon in Netatalk before 2.0.4-beta2, when using certain variables in a pipe command for the print file, allows remote attackers to execute arbitrary commands via shell metacharacters in a print request, as dem...Show more |
3Mandrakesoft NetatalkRedhat4Fedora Core Mandrake LinuxMandrake Linux Corporate Server+1 moreApr 16, 2026 Feb 9, 2005 N/A· v4 N/A· v3 2.1 LOW· v2 The netatalk package in Trustix Secure Linux 1.5 through 2.1, and possibly other operating systems, allows local users to overwrite files via a symlink attack on temporary files. |