|
2441
|
3.9 |
LOW
Local
|
-
|
-
|
An integer underflow in the volxlate function in Netatalk 3.0.0 through 4.4.2 allows a local privileged user to obtain limited information, modify limited data, or cause a minor service disruption vi…
|
CWE-191
Integer Underflow (Wrap or Wraparound)
|
CVE-2026-44069
|
2026-05-22 00:20 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2442
|
3.1 |
LOW
Network
|
-
|
-
|
An unbounded memory reallocation in the charset conversion code in Netatalk 2.0.0 through 4.4.2 allows a remote authenticated attacker to cause a minor denial of service via crafted character convers…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-44070
|
2026-05-22 00:20 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2443
|
3.0 |
LOW
Local
|
-
|
-
|
Netatalk 2.2.1 through 4.4.2 calls system() after a failed chdir() without properly handling the error condition, which allows a local privileged user to execute unintended commands or cause a minor …
|
CWE-78
OS Command
|
CVE-2026-44072
|
2026-05-22 00:20 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2444
|
5.0 |
MEDIUM
Network
|
-
|
-
|
Authentication modules in Netatalk 1.5.0 through 4.4.2 fail to check the return value of seteuid(), which may allow a remote authenticated attacker to retain elevated privileges under error condition…
|
CWE-273
Improper Check for Dropped Privileges
|
CVE-2026-44073
|
2026-05-22 00:20 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2445
|
6.7 |
MEDIUM
Local
|
-
|
-
|
Insufficient sanitization of volume paths in Netatalk 3.1.0 through 4.4.2 allows a local privileged user to inject OS commands and execute arbitrary code via a crafted volume path.
|
CWE-78
OS Command
|
CVE-2026-44076
|
2026-05-22 00:20 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2446
|
3.1 |
LOW
Network
|
-
|
-
|
A format string argument mismatch in Netatalk 3.0.3 through 4.4.2 allows a remote authenticated attacker to cause a minor denial of service via crafted input that triggers incorrect format string pro…
|
CWE-134
Use of Externally-Controlled Format String
|
CVE-2026-7835
|
2026-05-22 00:20 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2447
|
3.1 |
LOW
Network
|
-
|
-
|
An incorrect calculation in the hextoint macro in Netatalk 2.0.0 through 4.4.2 due to improper uppercase character handling allows a remote authenticated attacker to cause limited data modification v…
|
CWE-682
Incorrect Calculation
|
CVE-2026-7836
|
2026-05-22 00:20 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2448
|
3.1 |
LOW
Network
|
-
|
-
|
A dead bounds check in the Spotlight RPC unmarshaller in Netatalk 3.0.0 through 4.4.2 results in an unreachable code path that provides no effective bounds protection, which may allow a remote authen…
|
CWE-561
Dead Code
|
CVE-2026-44057
|
2026-05-22 00:20 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2449
|
3.7 |
LOW
Network
|
-
|
-
|
Netatalk 3.1.2 through 4.4.2 is compiled without FORTIFY_SOURCE, which disables built-in buffer overflow detection at runtime, potentially allowing a remote attacker to cause a minor denial of servic…
|
CWE-693
Protection Mechanism Failure
|
CVE-2026-44071
|
2026-05-22 00:20 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2450
|
3.7 |
LOW
Network
|
-
|
-
|
Netatalk 2.1.0 through 4.4.2 combines multiple errno values using bitwise OR, resulting in incorrect error codes when multiple error conditions occur simultaneously, which may allow a remote attacker…
|
CWE-682
Incorrect Calculation
|
CVE-2026-44074
|
2026-05-22 00:20 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|