|
901
|
7.1 |
HIGH
Network
|
-
|
-
|
Multiple heap out-of-bounds reads in the Spotlight RPC unmarshalling code in Netatalk 3.1.0 through 4.4.2 allow a remote authenticated attacker to obtain sensitive information or cause a minor servic…
|
CWE-125
Out-of-bounds Read
|
CVE-2026-44066
|
2026-05-22 00:20 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
902
|
4.2 |
MEDIUM
Network
|
-
|
-
|
A heap over-read in extended attribute (EA) header parsing in Netatalk 2.1.0 through 4.4.2 allows a remote authenticated attacker to obtain limited information or cause a minor service disruption via…
|
CWE-125
Out-of-bounds Read
|
CVE-2026-44067
|
2026-05-22 00:20 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
903
|
7.6 |
HIGH
Network
|
-
|
-
|
Incomplete sanitization of extended attribute (EA) path components in Netatalk 2.1.0 through 4.4.2 allows a remote authenticated attacker to write to files outside the intended metadata namespace via…
|
CWE-22
Path Traversal
|
CVE-2026-44068
|
2026-05-22 00:20 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
904
|
3.9 |
LOW
Local
|
-
|
-
|
An integer underflow in the volxlate function in Netatalk 3.0.0 through 4.4.2 allows a local privileged user to obtain limited information, modify limited data, or cause a minor service disruption vi…
|
CWE-191
Integer Underflow (Wrap or Wraparound)
|
CVE-2026-44069
|
2026-05-22 00:20 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
905
|
3.1 |
LOW
Network
|
-
|
-
|
An unbounded memory reallocation in the charset conversion code in Netatalk 2.0.0 through 4.4.2 allows a remote authenticated attacker to cause a minor denial of service via crafted character convers…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-44070
|
2026-05-22 00:20 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
906
|
3.0 |
LOW
Local
|
-
|
-
|
Netatalk 2.2.1 through 4.4.2 calls system() after a failed chdir() without properly handling the error condition, which allows a local privileged user to execute unintended commands or cause a minor …
|
CWE-78
OS Command
|
CVE-2026-44072
|
2026-05-22 00:20 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
907
|
5.0 |
MEDIUM
Network
|
-
|
-
|
Authentication modules in Netatalk 1.5.0 through 4.4.2 fail to check the return value of seteuid(), which may allow a remote authenticated attacker to retain elevated privileges under error condition…
|
CWE-273
Improper Check for Dropped Privileges
|
CVE-2026-44073
|
2026-05-22 00:20 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
908
|
6.7 |
MEDIUM
Local
|
-
|
-
|
Insufficient sanitization of volume paths in Netatalk 3.1.0 through 4.4.2 allows a local privileged user to inject OS commands and execute arbitrary code via a crafted volume path.
|
CWE-78
OS Command
|
CVE-2026-44076
|
2026-05-22 00:20 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
909
|
3.1 |
LOW
Network
|
-
|
-
|
A format string argument mismatch in Netatalk 3.0.3 through 4.4.2 allows a remote authenticated attacker to cause a minor denial of service via crafted input that triggers incorrect format string pro…
|
CWE-134
Use of Externally-Controlled Format String
|
CVE-2026-7835
|
2026-05-22 00:20 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
910
|
3.1 |
LOW
Network
|
-
|
-
|
An incorrect calculation in the hextoint macro in Netatalk 2.0.0 through 4.4.2 due to improper uppercase character handling allows a remote authenticated attacker to cause limited data modification v…
|
CWE-682
Incorrect Calculation
|
CVE-2026-7836
|
2026-05-22 00:20 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|