OpenZFS
Products
2- 5 CVEs
- 2 CVEs
Recent CVEs
5| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2013-20001 | Hig | 0.49 | 7.5 | 0.02 | Feb 12, 2021 | An issue was discovered in OpenZFS through 2.0.3. When an NFS share is exported to IPv6 addresses via the sharenfs feature, there is a silent failure to parse the IPv6 address data, and access is allowed to everyone. IPv6 restrictions from the configuration are not applied. | ||
| CVE-2020-37022 | Med | 0.42 | 6.4 | 0.00 | Jan 30, 2026 | OpenZ ERP 3.6.60 contains a persistent cross-site scripting vulnerability in the Employee module's name and description parameters. Attackers can inject malicious scripts through POST requests to , enabling session hijacking and manipulation of application modules. | ||
| CVE-2023-49298 | Hig | 0.00 | 7.5 | 0.01 | Nov 24, 2023 | OpenZFS through 2.1.13 and 2.2.x through 2.2.1, in certain scenarios involving applications that try to rely on efficient copying of file data, can replace file contents with zero-valued bytes and thus potentially disable security mechanisms. NOTE: this issue is not always… | ||
| CVE-2020-24717 | Hig | 0.00 | 7.8 | 0.00 | Aug 27, 2020 | OpenZFS before 2.0.0-rc1, when used on FreeBSD, misinterprets group permissions as user permissions, as demonstrated by mode 0770 being equivalent to mode 0777. | ||
| CVE-2020-24716 | Hig | 0.00 | 7.8 | 0.00 | Aug 27, 2020 | OpenZFS before 2.0.0-rc1, when used on FreeBSD, allows execute permissions for all directories. |
- risk 0.49cvss 7.5epss 0.02
An issue was discovered in OpenZFS through 2.0.3. When an NFS share is exported to IPv6 addresses via the sharenfs feature, there is a silent failure to parse the IPv6 address data, and access is allowed to everyone. IPv6 restrictions from the configuration are not applied.
- risk 0.42cvss 6.4epss 0.00
OpenZ ERP 3.6.60 contains a persistent cross-site scripting vulnerability in the Employee module's name and description parameters. Attackers can inject malicious scripts through POST requests to , enabling session hijacking and manipulation of application modules.
- risk 0.00cvss 7.5epss 0.01
OpenZFS through 2.1.13 and 2.2.x through 2.2.1, in certain scenarios involving applications that try to rely on efficient copying of file data, can replace file contents with zero-valued bytes and thus potentially disable security mechanisms. NOTE: this issue is not always…
- risk 0.00cvss 7.8epss 0.00
OpenZFS before 2.0.0-rc1, when used on FreeBSD, misinterprets group permissions as user permissions, as demonstrated by mode 0770 being equivalent to mode 0777.
- risk 0.00cvss 7.8epss 0.00
OpenZFS before 2.0.0-rc1, when used on FreeBSD, allows execute permissions for all directories.