Nfs Nfs-Utils vulnerabilities

5 known vulnerabilities affecting nfs/nfs-utils.

Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH2MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2009-0180HIGHCVSS 7.5≤ 1.1.2v0.2+20 more2009-01-20
CVE-2009-0180 [HIGH] CVE-2009-0180: Certain Fedora build scripts for nfs-utils before 1.1.2-9.fc9 on Fedora 9, and before 1.1.4-6.fc10 o Certain Fedora build scripts for nfs-utils before 1.1.2-9.fc9 on Fedora 9, and before 1.1.4-6.fc10 on Fedora 10, omit TCP Wrapper support, which might allow remote attackers to bypass intended access restrictions, possibly a related issue to CVE-2008-1376.
nvd
CVE-2008-4552HIGHCVSS 7.5≤ 1.1.2v0.2+17 more2008-10-14
CVE-2008-4552 [HIGH] CWE-264 CVE-2008-4552: The good_client function in nfs-utils 1.0.9, and possibly other versions before 1.1.3, invokes the h The good_client function in nfs-utils 1.0.9, and possibly other versions before 1.1.3, invokes the hosts_ctl function with the wrong order of arguments, which causes TCP Wrappers to ignore netgroups and allows remote attackers to bypass intended access restrictions.
nvd
CVE-2004-0946CRITICALCVSS 10.0v1.0v1.0.1+4 more2005-01-10
CVE-2004-0946 [CRITICAL] CVE-2004-0946: rquotad in nfs-utils (rquota_server.c) before 1.0.6-r6 on 64-bit architectures does not properly per rquotad in nfs-utils (rquota_server.c) before 1.0.6-r6 on 64-bit architectures does not properly perform an integer conversion, which leads to a stack-based buffer overflow and allows remote attackers to execute arbitrary code via a crafted NFS request.
nvd
CVE-2004-1014MEDIUMCVSS 5.0v1.0.62005-01-10
CVE-2004-1014 [MEDIUM] CVE-2004-1014: statd in nfs-utils 1.257 and earlier does not ignore the SIGPIPE signal, which allows remote attacke statd in nfs-utils 1.257 and earlier does not ignore the SIGPIPE signal, which allows remote attackers to cause a denial of service (server process crash) via a TCP connection that is prematurely terminated.
nvd
CVE-2004-0154MEDIUMCVSS 5.0v1.0v1.0.1+3 more2004-06-14
CVE-2004-0154 [MEDIUM] CVE-2004-0154: rpc.mountd in nfs-utils after 1.0.3 and before 1.0.6 allows attackers to cause a denial of service ( rpc.mountd in nfs-utils after 1.0.3 and before 1.0.6 allows attackers to cause a denial of service (crash) via an NFS mount of a directory from a client whose reverse DNS lookup name is different from the forward lookup name.
nvd