Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Openafs

First CVE: Mar 25, 2003Active for: 23 yearsTotal CVEs: 36
25.2
VTI Score
Low

OpenAFS is a distributed file system that enables shared storage and data access across networked systems, occupying a specialized but strategically important role in research and enterprise infrastructure environments. The vendor's vulnerability profile concentrates in the single OpenAFS product and recurs through weakness classes reflecting the complexity of network protocols, buffer management, and authentication enforcement: exposure of sensitive information, buffer boundary violations, improper input validation, uninitialized resource use, and authentication bypass. These issues arise from the intersection of legacy codebase constraints and the stringent demands of a kernel-level distributed system operating across untrusted networks. Defenders deploying OpenAFS should prioritize inventory and network isolation of file servers, since the product's privileged role and long deployment lifecycles make patch cycles critical; live severity and exploitation figures are shown alongside this summary.

FAUCET AI Generated
36
Total CVEs
More Total CVEs than 98% of tracked vendors
2.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
6.1
Avg CVSS Score
Higher Avg CVSS Score than 30% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Openafs over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 25, 2003
23 years ago
Most Recent CVE
Nov 14, 2024
617 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (36 CVEs).

36 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-16947CRITICAL
An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2. The backup tape controller (butc) process accepts incoming RPCs but does not require (or allow for) authent
Sep 12, 20189.832NONO
CVE-2003-0028HIGH
Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc
Mar 25, 20037.528NONO
CVE-2009-1251HIGH
Heap-based buffer overflow in the cache manager in the client in OpenAFS 1.0 through 1.4.8 and 1.5.0 through 1.5.58 on Unix platforms allows remote attackers to cause a denial of s
Apr 9, 200910.027NONO
CVE-2018-16949HIGH
An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2. Several data types used as RPC input variables were implemented as unbounded array types, limited only by t
Sep 12, 20187.526NONO
CVE-2017-17432HIGH
OpenAFS 1.x before 1.6.22 does not properly validate Rx ack packets, which allows remote attackers to cause a denial of service (system crash or application crash) via crafted fiel
Dec 6, 20177.526NONO
CVE-2019-18602HIGH
OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to an information disclosure vulnerability because uninitialized scalars are sent over the network to a peer.
Oct 29, 20197.525NONO
CVE-2019-18601HIGH
OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to denial of service from unserialized data access because remote attackers can make a series of VOTE_Debug RPC calls to crash
Oct 29, 20197.524NONO
CVE-2011-0430HIGH
Double free vulnerability in the Rx server process in OpenAFS 1.4.14, 1.4.12, 1.4.7, and possibly other versions allows remote attackers to cause a denial of service and execute ar
Feb 19, 20117.524NONO
CVE-2018-16948HIGH
An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2. Several RPC server routines did not fully initialize their output variables before returning, leaking memor
Sep 12, 20187.523NONO
CVE-2024-10397HIGH
A malicious server can crash the OpenAFS cache manager and other client utilities, and possibly execute arbitrary code.
Nov 14, 20247.822NONO
View all 36 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products36 CVEs
56%
36%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local3 (8.3%)
Network11 (30.6%)
Unknown22 (61.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low13 (36.1%)
High1 (2.8%)
Unknown22 (61.1%)
User Interaction
None14 (38.9%)
Unknown22 (61.1%)
Required0 (0.0%)
Privileges Required
Low5 (13.9%)
High0 (0.0%)
None9 (25.0%)
Unknown22 (61.1%)

Exploit Exposure

Signals from CVEs in this vendor scope (36 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Openafs.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Openafs — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Openafs's Products

View all 4 CNAs →

Top CWEs