Known Vulnerabilities for products from Avahi

Listed below are 14 of the newest known vulnerabilities associated with the vendor "Avahi".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2021-36217 ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-3502. Reason: This candidate is a duplicate of CVE-2021-3... Not Provided 2021-07-07 2023-11-07
CVE-2021-26720 avahi-daemon-check-dns.sh in the Debian avahi package through 0.8-4 is executed as root via /etc/network/if-up.d/avahi-daemon... 7.8 - HIGH 2021-02-17 2022-12-06
CVE-2021-3502 A flaw was found in avahi 0.8-5. A reachable assertion is present in avahi_s_host_name_resolver_start function allowing a loc... 5.5 - MEDIUM 2021-05-07 2023-11-07
CVE-2021-3468 A flaw was found in avahi in versions 0.6 up to 0.8. The event used to signal the termination of the client connection on the... 5.5 - MEDIUM 2021-06-02 2023-06-22
CVE-2017-6519 avahi-daemon in Avahi through 0.6.32 and 0.7 inadvertently responds to IPv6 unicast queries with source addresses that are no... 9.1 - CRITICAL 2017-05-01 2023-11-07
CVE-2011-1002 avahi-core/socket.c in avahi-daemon in Avahi before 0.6.29 allows remote attackers to cause a denial of service (infinite loo... 5 - MEDIUM 2011-02-22 2023-12-22
CVE-2010-2244 The AvahiDnsPacket function in avahi-core/socket.c in avahi-daemon in Avahi 0.6.16 and 0.6.25 allows remote attackers to caus... 4.3 - MEDIUM 2010-07-08 2011-03-07
CVE-2009-0758 The originates_from_local_legacy_unicast_socket function in avahi-core/server.c in avahi-daemon 0.6.23 does not account for t... 7.8 - HIGH 2009-03-03 2010-08-12
CVE-2008-5081 The originates_from_local_legacy_unicast_socket function (avahi-core/server.c) in avahi-daemon in Avahi before 0.6.24 allows ... 5 - MEDIUM 2008-12-17 2017-09-29
CVE-2007-3372 The Avahi daemon in Avahi before 0.6.20 allows attackers to cause a denial of service (exit) via empty TXT data over D-Bus, w... 2.1 - LOW 2007-06-22 2018-10-16
CVE-2006-6870 The consume_labels function in avahi-core/dns.c in Avahi before 0.6.16 allows remote attackers to cause a denial of service (... 5 - MEDIUM 2006-12-31 2011-03-08
CVE-2006-5461 Avahi before 0.6.15 does not verify the sender identity of netlink messages to ensure that they come from the kernel instead ... 2.1 - LOW 2006-11-14 2018-10-03
CVE-2006-2289 Buffer overflow in avahi-core in Avahi before 0.6.10 allows local users to execute arbitrary code via unknown vectors. 2.1 - LOW 2006-05-10 2023-11-07
CVE-2006-2288 Avahi before 0.6.10 allows local users to cause a denial of service (mDNS/DNS-SD service disconnect) via unspecified mDNS nam... 3.6 - LOW 2006-05-10 2023-11-07

Known software with vulnerabilities from Avahi

Type Vendor Product Version
ApplicationAvahiAvahi0.1