Vulnerabilities (CVE)

Filtered by vendor Avahi Subscribe
Filtered by product Avahi
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-38469 2 Avahi, Redhat 2 Avahi, Enterprise Linux 2023-11-09 N/A 5.5 MEDIUM
A vulnerability was found in Avahi, where a reachable assertion exists in avahi_dns_packet_append_record.
CVE-2023-38472 2 Avahi, Redhat 2 Avahi, Enterprise Linux 2023-11-09 N/A 5.5 MEDIUM
A vulnerability was found in Avahi. A reachable assertion exists in the avahi_rdata_parse() function.
CVE-2023-38471 2 Avahi, Redhat 2 Avahi, Enterprise Linux 2023-11-09 N/A 5.5 MEDIUM
A vulnerability was found in Avahi. A reachable assertion exists in the dbus_set_host_name function.
CVE-2023-38470 2 Avahi, Redhat 2 Avahi, Enterprise Linux 2023-11-09 N/A 5.5 MEDIUM
A vulnerability was found in Avahi. A reachable assertion exists in the avahi_escape_label() function.
CVE-2023-38473 2 Avahi, Redhat 2 Avahi, Enterprise Linux 2023-11-09 N/A 5.5 MEDIUM
A vulnerability was found in Avahi. A reachable assertion exists in the avahi_alternative_host_name() function.
CVE-2021-3468 1 Avahi 1 Avahi 2022-06-07 2.1 LOW 5.5 MEDIUM
A flaw was found in avahi in versions 0.6 up to 0.8. The event used to signal the termination of the client connection on the avahi Unix socket is not correctly handled in the client_work function, allowing a local attacker to trigger an infinite loop. The highest threat from this vulnerability is to the availability of the avahi service, which becomes unresponsive after this flaw is triggered.
CVE-2021-3502 1 Avahi 1 Avahi 2021-05-17 2.1 LOW 5.5 MEDIUM
A flaw was found in avahi 0.8-5. A reachable assertion is present in avahi_s_host_name_resolver_start function allowing a local attacker to crash the avahi service by requesting hostname resolutions through the avahi socket or dbus methods for invalid hostnames. The highest threat from this vulnerability is to the service availability.