Home/Product/netatalk
Product

netatalk

17 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2024-38441
>= 2.0.0 and < 2.4.1
Netatalk before 3.2.1 has an off-by-one error and resultant heap-based buffer overflow because of setting ibuf[len] to '\0' in FPM
9.8CRITICAL
CVE-2024-38440
>= 2.0.0 and < 2.4.1
Netatalk before 3.2.1 has an off-by-one error, and resultant heap-based buffer overflow and segmentation violation, because of inc
7.5HIGH
CVE-2024-38439
>= 2.0.0 and < 2.4.1
Netatalk before 3.2.1 has an off-by-one error and resultant heap-based buffer overflow because of setting ibuf[PASSWDLEN] to '\0'
9.8CRITICAL
CVE-2023-42464
>= 3.1 and < 3.1.17
A Type Confusion vulnerability was found in the Spotlight RPC functions in afpd in Netatalk 3.1.x before 3.1.17. When parsing Spot
9.8CRITICAL
CVE-2022-43634
all versions
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not
9.8CRITICAL
CVE-2022-23125
< 3.1.13
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not
9.8CRITICAL
CVE-2022-23124
< 3.1.13
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Netatalk. Authentication
9.8CRITICAL
CVE-2022-23123
< 3.1.13
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Netatalk. Authentication
9.8CRITICAL
CVE-2022-23122
< 3.1.13
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not
9.8CRITICAL
CVE-2022-23121
< 3.1.13
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not
9.8CRITICAL
CVE-2022-0194
< 3.1.13
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not
9.8CRITICAL
CVE-2022-45188
<= 3.1.13
Netatalk through 3.1.13 has an afp_getappl heap-based buffer overflow resulting in code execution via a crafted .appl file. This p
7.8HIGH
CVE-2022-22995
< 3.1.18
The combination of primitives offered by SMB and AFP in their default configuration allows the arbitrary writing of files. By expl
10.0CRITICAL
CVE-2021-31439
< 3.1.13
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Synology DiskStation M
8.8HIGH
CVE-2018-1160
< 3.1.12
Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_opensess.c. This is due to lack of bounds checking on attack
9.8CRITICAL
CVE-2008-5718
<= 2.0.3
The papd daemon in Netatalk before 2.0.4-beta2, when using certain variables in a pipe command for the print file, allows remote a
CVE-2004-0974
all versions
The netatalk package in Trustix Secure Linux 1.5 through 2.1, and possibly other operating systems, allows local users to overwrit
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin