Nfs-utils
This hub aggregates every CVE we track for Nfs-utils, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
11
CVEs tracked
2
Critical
3
High
0
In CISA KEV
Severity distribution
MEDIUM4HIGH3LOW2CRITICAL2
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
0
0
0
0
2024-082026-07
Latest CVEs
The 11 most recently published vulnerabilities affecting Nfs-utils.
- CVE-2025-12801Nfs-utils: rpc.mountd in the nfs-utils privilege escalation6.5
- CVE-2019-3689nfs-utils: root-owned files stored in insecure /var/lib/nfs directory5.1
- CVE-2011-1749The nfs_addmntent function in support/nfs/nfs_mntent.c in the mount.nsf tool in nfs-utils before 1.2.4 attempts to append to the /etc/mtab file without first checking whether resource limits would ...3.3
- CVE-2011-2500The host_reliable_addrinfo function in support/export/hostname.c in nfs-utils before 1.2.4 does not properly use DNS to verify access to NFS exports, which allows remote attackers to mount filesyst...7.5
- CVE-2013-1923rpc-gssd in nfs-utils before 1.2.8 performs reverse DNS resolution for server names during GSSAPI authentication, which might allow remote attackers to read otherwise-restricted files via DNS spoof...3.2
- CVE-2009-0180Certain Fedora build scripts for nfs-utils before 1.1.2-9.fc9 on Fedora 9, and before 1.1.4-6.fc10 on Fedora 10, omit TCP Wrapper support, which might allow remote attackers to bypass intended acce...7.5
- CVE-2008-4552The good_client function in nfs-utils 1.0.9, and possibly other versions before 1.1.3, invokes the hosts_ctl function with the wrong order of arguments, which causes TCP Wrappers to ignore netgroup...7.5
- CVE-2004-0946rquotad in nfs-utils (rquota_server.c) before 1.0.6-r6 on 64-bit architectures does not properly perform an integer conversion, which leads to a stack-based buffer overflow and allows remote attack...10.0
- CVE-2004-1014statd in nfs-utils 1.257 and earlier does not ignore the SIGPIPE signal, which allows remote attackers to cause a denial of service (server process crash) via a TCP connection that is prematurely t...5.0
- CVE-2004-0154rpc.mountd in nfs-utils after 1.0.3 and before 1.0.6 allows attackers to cause a denial of service (crash) via an NFS mount of a directory from a client whose reverse DNS lookup name is different f...5.0
- CVE-2003-0252Off-by-one error in the xlog function of mountd in the Linux NFS utils package (nfs-utils) before 1.0.4 allows remote attackers to cause a denial of service and possibly execute arbitrary code via ...9.8
Product normalization is registry-driven with AI assist and human review. How it works