Search CVE reports


Toggle filters

431 – 440 of 27411 results

Status is adjusted based on your filters.


CVE-2026-7837

Medium priority
Needs evaluation

A time-of-check time-of-use (TOCTOU) condition in the ad_flush function in Netatalk 3.0.0 through 4.4.2 involves root-privileged file operations, which may allow a remote attacker to cause limited data modification under specific...

1 affected package

netatalk

Package 26.04 LTS
netatalk Needs evaluation
Show less packages

CVE-2026-44075

Medium priority
Needs evaluation

A missing break statement in DSI OpenSession processing in Netatalk 1.5.0 through 4.4.2 causes a DSIOPT_ATTNQUANT switch case to fall through into DSIOPT_SERVQUANT, resulting in unintended session option handling that may allow a...

1 affected package

netatalk

Package 26.04 LTS
netatalk Needs evaluation
Show less packages

CVE-2026-44074

Medium priority
Needs evaluation

Netatalk 2.1.0 through 4.4.2 combines multiple errno values using bitwise OR, resulting in incorrect error codes when multiple error conditions occur simultaneously, which may allow a remote attacker to cause a minor...

1 affected package

netatalk

Package 26.04 LTS
netatalk Needs evaluation
Show less packages

CVE-2026-44071

Medium priority
Needs evaluation

Netatalk 3.1.2 through 4.4.2 is compiled without FORTIFY_SOURCE, which disables built-in buffer overflow detection at runtime, potentially allowing a remote attacker to cause a minor denial of service via memory errors that would...

1 affected package

netatalk

Package 26.04 LTS
netatalk Needs evaluation
Show less packages

CVE-2026-44057

Medium priority
Needs evaluation

A dead bounds check in the Spotlight RPC unmarshaller in Netatalk 3.0.0 through 4.4.2 results in an unreachable code path that provides no effective bounds protection, which may allow a remote authenticated attacker to obtain...

1 affected package

netatalk

Package 26.04 LTS
netatalk Needs evaluation
Show less packages

CVE-2026-7836

Medium priority
Needs evaluation

An incorrect calculation in the hextoint macro in Netatalk 2.0.0 through 4.4.2 due to improper uppercase character handling allows a remote authenticated attacker to cause limited data modification via crafted hexadecimal input.

1 affected package

netatalk

Package 26.04 LTS
netatalk Needs evaluation
Show less packages

CVE-2026-7835

Medium priority
Needs evaluation

A format string argument mismatch in Netatalk 3.0.3 through 4.4.2 allows a remote authenticated attacker to cause a minor denial of service via crafted input that triggers incorrect format string processing.

1 affected package

netatalk

Package 26.04 LTS
netatalk Needs evaluation
Show less packages

CVE-2026-44076

Medium priority
Needs evaluation

Insufficient sanitization of volume paths in Netatalk 3.1.0 through 4.4.2 allows a local privileged user to inject OS commands and execute arbitrary code via a crafted volume path.

1 affected package

netatalk

Package 26.04 LTS
netatalk Needs evaluation
Show less packages

CVE-2026-44073

Medium priority
Needs evaluation

Authentication modules in Netatalk 1.5.0 through 4.4.2 fail to check the return value of seteuid(), which may allow a remote authenticated attacker to retain elevated privileges under error conditions.

1 affected package

netatalk

Package 26.04 LTS
netatalk Needs evaluation
Show less packages

CVE-2026-44072

Medium priority
Needs evaluation

Netatalk 2.2.1 through 4.4.2 calls system() after a failed chdir() without properly handling the error condition, which allows a local privileged user to execute unintended commands or cause a minor service disruption...

1 affected package

netatalk

Package 26.04 LTS
netatalk Needs evaluation
Show less packages