NFS (Network File System) utilities represent a narrowly scoped but foundational component for networked file access across Unix and Linux systems, with vulnerabilities concentrated in the nfs-utils package that implements the NFS protocol stack. The observed disclosures reflect the complexity inherent to network protocol parsing and privilege-management functions in a widely embedded utility; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nfs over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-0946HIGH rquotad in nfs-utils (rquota_server.c) before 1.0.6-r6 on 64-bit architectures does not properly perform an integer conversion, which leads to a stack-based buffer overflow and all | Jan 10, 2005 | 10.0 | 35 | NO | NO |
CVE-2008-4552HIGH The good_client function in nfs-utils 1.0.9, and possibly other versions before 1.1.3, invokes the hosts_ctl function with the wrong order of arguments, which causes TCP Wrappers t | Oct 14, 2008 | 7.5 | 21 | NO | NO |
CVE-2009-0180HIGH Certain Fedora build scripts for nfs-utils before 1.1.2-9.fc9 on Fedora 9, and before 1.1.4-6.fc10 on Fedora 10, omit TCP Wrapper support, which might allow remote attackers to byp | Jan 20, 2009 | 7.5 | 19 | NO | NO |
CVE-2004-1014MEDIUM statd in nfs-utils 1.257 and earlier does not ignore the SIGPIPE signal, which allows remote attackers to cause a denial of service (server process crash) via a TCP connection that | Jan 10, 2005 | 5.0 | 19 | NO | NO |
CVE-2004-0154MEDIUM rpc.mountd in nfs-utils after 1.0.3 and before 1.0.6 allows attackers to cause a denial of service (crash) via an NFS mount of a directory from a client whose reverse DNS lookup na | Jun 14, 2004 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nfs.
Media articles that mention a CVE ID that affects a product developed by Nfs — matched by CVE ID, not by vendor name.