Show filters
36 Total Results
Displaying 11-20 of 36
Sort by:
Attacker Value
Unknown

CVE-2016-9772

Disclosure Date: February 06, 2017 (last updated November 26, 2024)
OpenAFS 1.6.19 and earlier allows remote attackers to obtain sensitive directory information via vectors involving the (1) client cache partition, (2) fileserver vice partition, or (3) certain RPC responses.
0
Attacker Value
Unknown

CVE-2016-4536

Disclosure Date: May 13, 2016 (last updated November 25, 2024)
The client in OpenAFS before 1.6.17 does not properly initialize the (1) AFSStoreStatus, (2) AFSStoreVolumeStatus, (3) VldbListByAttributes, and (4) ListAddrByAttributes structures, which might allow remote attackers to obtain sensitive memory information by leveraging access to RPC call traffic.
0
Attacker Value
Unknown

CVE-2016-2860

Disclosure Date: May 13, 2016 (last updated November 08, 2023)
The newEntry function in ptserver/ptprocs.c in OpenAFS before 1.6.17 allows remote authenticated users from foreign Kerberos realms to bypass intended access restrictions and create arbitrary groups as administrators by leveraging mishandling of the creator ID.
0
Attacker Value
Unknown

CVE-2015-8312

Disclosure Date: May 13, 2016 (last updated November 08, 2023)
Off-by-one error in afs_pioctl.c in OpenAFS before 1.6.16 might allow local users to cause a denial of service (memory overwrite and system crash) via a pioctl with an input buffer size of 4096 bytes.
0
Attacker Value
Unknown

CVE-2015-7762

Disclosure Date: November 06, 2015 (last updated October 05, 2023)
rx/rx.c in OpenAFS before 1.6.15 and 1.7.x before 1.7.33 does not properly initialize the padding of a data structure when constructing an Rx acknowledgement (ACK) packet, which allows remote attackers to obtain sensitive information by (1) conducting a replay attack or (2) sniffing the network.
0
Attacker Value
Unknown

CVE-2015-7763

Disclosure Date: November 06, 2015 (last updated October 05, 2023)
rx/rx.c in OpenAFS 1.5.75 through 1.5.78, 1.6.x before 1.6.15, and 1.7.x before 1.7.33 does not properly initialize padding at the end of an Rx acknowledgement (ACK) packet, which allows remote attackers to obtain sensitive information by (1) conducting a replay attack or (2) sniffing the network.
0
Attacker Value
Unknown

CVE-2015-6587

Disclosure Date: September 02, 2015 (last updated October 05, 2023)
The vlserver in OpenAFS before 1.6.13 allows remote authenticated users to cause a denial of service (out-of-bounds read and crash) via a crafted regular expression in a VL_ListAttributesN2 RPC.
0
Attacker Value
Unknown

CVE-2015-3284

Disclosure Date: August 12, 2015 (last updated October 05, 2023)
pioctls in OpenAFS 1.6.x before 1.6.13 allows local users to read kernel memory via crafted commands.
0
Attacker Value
Unknown

CVE-2015-3282

Disclosure Date: August 12, 2015 (last updated October 05, 2023)
vos in OpenAFS before 1.6.13, when updating VLDB entries, allows remote attackers to obtain stack data by sniffing the network.
0
Attacker Value
Unknown

CVE-2015-3286

Disclosure Date: August 12, 2015 (last updated October 05, 2023)
Buffer overflow in the Solaris kernel extension in OpenAFS before 1.6.13 allows local users to cause a denial of service (panic or deadlock) or possibly have other unspecified impact via a large group list when joining a PAG.
0