Gluster / Glusterfs
27 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2023-26253 | glusterfs: stack-based buffer overflow in notify() in fuse-bridge.c | HIGH | 7.5 | Feb 21, 2023 |
| CVE-2022-48340 | glusterfs: heap use-after-free in dht_setxattr_mds_cbk() in dht-common.c | HIGH | 7.5 | Feb 21, 2023 |
| CVE-2018-14660 | glusterfs: Repeat use of "GF_META_LOCK_KEY" xattr allows for memory exhaustion | MEDIUM | 6.5 | Nov 1, 2018 |
| CVE-2018-14651 | glusterfs: glusterfs server exploitable via symlinks to relative paths | HIGH | 8.8 | Oct 31, 2018 |
| CVE-2018-14661 | glusterfs: features/locks translator passes an user-controlled string to snprintf without a proper format string resulting in a denial of service | MEDIUM | 6.5 | Oct 31, 2018 |
| CVE-2018-14659 | glusterfs: Unlimited file creation via "GF_XATTR_IOSTATS_DUMP_KEY" xattr allows for denial of service | MEDIUM | 6.5 | Oct 31, 2018 |
| CVE-2018-14654 | glusterfs: "features/index" translator can create arbitrary, empty files | MEDIUM | 6.5 | Oct 31, 2018 |
| CVE-2018-14653 | glusterfs: Heap-based buffer overflow via "gf_getspec_req" RPC message | HIGH | 8.8 | Oct 31, 2018 |
| CVE-2018-14652 | glusterfs: Buffer overflow in "features/locks" translator allows for denial of service | MEDIUM | 6.5 | Oct 31, 2018 |
| CVE-2018-10930 | glusterfs: Files can be renamed outside volume | MEDIUM | 6.5 | Sep 4, 2018 |
| CVE-2018-10929 | glusterfs: Arbitrary file creation on storage server allows for execution of arbitrary code | HIGH | 8.8 | Sep 4, 2018 |
| CVE-2018-10928 | glusterfs: Improper resolution of symlinks allows for privilege escalation | HIGH | 8.8 | Sep 4, 2018 |
| CVE-2018-10927 | glusterfs: File status information leak and denial of service | HIGH | 8.1 | Sep 4, 2018 |
| CVE-2018-10926 | glusterfs: Device files can be created in arbitrary locations | HIGH | 8.8 | Sep 4, 2018 |
| CVE-2018-10924 | glusterfs: Denial-of-service via fsync(2) in Gluster FUSE client | MEDIUM | 6.5 | Sep 4, 2018 |
| CVE-2018-10923 | glusterfs: I/O to arbitrary devices on storage server | HIGH | 8.1 | Sep 4, 2018 |
| CVE-2018-10914 | glusterfs: remote denial of service of gluster volumes via posix_get_file_contents function in posix-helpers.c | MEDIUM | 6.5 | Sep 4, 2018 |
| CVE-2018-10913 | glusterfs: Information Exposure in posix_get_file_contents function in posix-helpers.c | MEDIUM | 6.5 | Sep 4, 2018 |
| CVE-2018-10911 | glusterfs: Improper deserialization in dict.c:dict_unserialize() can allow attackers to read arbitrary memory | HIGH | 7.5 | Sep 4, 2018 |
| CVE-2018-10907 | glusterfs: Stack-based buffer overflow in server-rpc-fops.c allows remote attackers to execute arbitrary code | HIGH | 8.8 | Sep 4, 2018 |
| CVE-2018-10904 | glusterfs: Unsanitized file names in debug/io-stats translator can allow remote attackers to execute arbitrary code | HIGH | 8.8 | Sep 4, 2018 |
| CVE-2018-10841 | glusterfs: access trusted peer group via remote-host command | HIGH | 8.8 | Jun 20, 2018 |
| CVE-2018-1112 | glusterfs: auth.allow allows unauthenticated clients to mount gluster volumes (CVE-2018-1088 regression) | HIGH | 8.8 | Apr 25, 2018 |
| CVE-2017-15096 | glusterfs: Null pointer dereference in send_brick_req function in glusterfsd/src/gf_attach.c | LOW | 3.3 | Oct 26, 2017 |
| CVE-2014-3619 | glusterfs: fragment header infinite loop DoS | MEDIUM | 5.0 | Mar 27, 2015 |
Showing 1 to 25 of 27 CVEs