Debian Avahi vulnerabilities
24 known vulnerabilities affecting debian/avahi.
Total CVEs
24
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM16LOW7
Vulnerabilities
Page 2 of 2
CVE-2006-2289P4MEDIUMCVSS 2.1fixed in avahi 0.6.10-1 (bookworm)2006
CVE-2006-2289 [LOW] CVE-2006-2289: avahi - Buffer overflow in avahi-core in Avahi before 0.6.10 allows local users to execu...
Buffer overflow in avahi-core in Avahi before 0.6.10 allows local users to execute arbitrary code via unknown vectors.
Scope: local
bookworm: resolved (fixed in 0.6.10-1)
bullseye: resolved (fixed in 0.6.10-1)
forky: resolved (fixed in 0.6.10-1)
sid: resolved (fixed in 0.6.10-1)
trixie: resolved (fixed in 0.6.10-1)
debian
CVE-2007-3372P4LOWCVSS 2.1fixed in avahi 0.6.20-2 (bookworm)2007
CVE-2007-3372 [LOW] CVE-2007-3372: avahi - The Avahi daemon in Avahi before 0.6.20 allows attackers to cause a denial of se...
The Avahi daemon in Avahi before 0.6.20 allows attackers to cause a denial of service (exit) via empty TXT data over D-Bus, which triggers an assert error.
Scope: local
bookworm: resolved (fixed in 0.6.20-2)
bullseye: resolved (fixed in 0.6.20-2)
forky: resolved (fixed in 0.6.20-2)
sid: resolved (fixed in 0.6.20-2)
trixie: resolved (fixed in 0.6.20-2)
debian
CVE-2006-2288P4LOWCVSS 3.6fixed in avahi 0.6.10-1 (bookworm)2006
CVE-2006-2288 [LOW] CVE-2006-2288: avahi - Avahi before 0.6.10 allows local users to cause a denial of service (mDNS/DNS-SD...
Avahi before 0.6.10 allows local users to cause a denial of service (mDNS/DNS-SD service disconnect) via unspecified mDNS name conflicts.
Scope: local
bookworm: resolved (fixed in 0.6.10-1)
bullseye: resolved (fixed in 0.6.10-1)
forky: resolved (fixed in 0.6.10-1)
sid: resolved (fixed in 0.6.10-1)
trixie: resolved (fixed in 0.6.10-1)
debian
CVE-2006-5461P4LOWCVSS 2.1fixed in avahi 0.6.15-1 (bookworm)2006
CVE-2006-5461 [LOW] CVE-2006-5461: avahi - Avahi before 0.6.15 does not verify the sender identity of netlink messages to e...
Avahi before 0.6.15 does not verify the sender identity of netlink messages to ensure that they come from the kernel instead of another process, which allows local users to spoof network changes to Avahi.
Scope: local
bookworm: resolved (fixed in 0.6.15-1)
bullseye: resolved (fixed in 0.6.15-1)
forky: resolved (fixed in 0.6.15-1)
sid: resolved (fixed in 0.6.15-1)
trixie:
debian
← Previous2 / 2