Vulnerabilidades em Netatalk
41 resultadosAnálise Vexday
Netatalk apresenta postura de risco elevada com 41 CVEs catalogadas, sendo 33 divulgadas nos últimos 90 dias, indicando vulnerabilidades recentes e ativas. Apesar de nenhuma estar sob exploração documentada em KEV, 7 falhas críticas (CVSS alto) merecem atenção imediata, com predominância de estouro de buffer (CWE-121) que são vetores tradicionais de comprometimento remoto. A concentração de descobertas recentes sugere exposição contínua do código-base a pesquisadores de segurança.
CVE-2018-1160CRITICALNetatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_opensess.c. This is due to lack of bounds checking on attacker controlEPSS 86.5%CVE-2022-43634CRITICALThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required tEPSS 18.9%CVE-2022-23121CRITICALThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required tEPSS 8.6%CVE-2022-0194CRITICALThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required tEPSS 4.4%CVE-2022-23122CRITICALThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required tEPSS 4.4%CVE-2022-23125CRITICALThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required tEPSS 4.4%CVE-2022-23123MEDIUMThis vulnerability allows remote attackers to disclose sensitive information on affected installations of Netatalk. Authentication is not reEPSS 3.8%CVE-2022-23124MEDIUMThis vulnerability allows remote attackers to disclose sensitive information on affected installations of Netatalk. Authentication is not reEPSS 2.8%CVE-2026-44058MEDIUMAuthentication bypass via admin auth userEPSS 0.5%CVE-2026-44049HIGHOut-of-bounds write in convert_charset() null terminationEPSS 0.5%CVE-2026-44051HIGHArbitrary file read via attacker-controlled symlink creationEPSS 0.5%CVE-2026-44050CRITICALHeap buffer overflow in CNID daemon comm_rcv()EPSS 0.4%CVE-2026-44048HIGHStack buffer overflow via UCS-2 type confusion in convert_charset()EPSS 0.4%CVE-2026-44061MEDIUMDES-ECB auth with timing side channelEPSS 0.4%CVE-2026-44047HIGHSQL injection in MySQL CNID backendEPSS 0.4%CVE-2026-44055HIGHBitwise OR logic bug enables shell injectionEPSS 0.4%CVE-2026-44062HIGHMissing o_len bounds check in pull_charset_flags()EPSS 0.4%CVE-2026-44071LOWFORTIFY_SOURCE disabledEPSS 0.3%CVE-2026-44075LOWMissing break in DSI OpenSessionEPSS 0.3%CVE-2026-44074LOWBitwise OR of errno valuesEPSS 0.3%