keepalived records
6 published records for vendor keepalived.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-59 Improper Link Resolution Before File Access ('Link Following')1
- CWE-787 Out-of-bounds Write1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2018-19115No exploit | keepalived before 2.0.7 has a heap-based buffer overflow when parsing HTTP status codes resulting in DoS or possibly unspecified other impackeepalived · keepalived · CWE-787 | Critical9.8 | — | 3.7% | Nov 8, 2018 |
31Monitor | CVE-2018-19045No exploit | keepalived 2.0.8 used mode 0666 when creating new temporary files upon a call to PrintData or PrintStats, potentially leaking sensitive infokeepalived · keepalived · CWE-200 | High7.5 | — | 2.4% | Nov 8, 2018 |
21Monitor | CVE-2021-44225No exploit | In Keepalived through 2.2.4, the D-Bus policy does not sufficiently restrict the message destination, allowing any user to inspect and manipkeepalived · keepalived | Medium5.4 | — | 1.1% | Nov 25, 2021 |
18Monitor | CVE-2018-19044No exploit | keepalived 2.0.8 didn't check for pathnames with symlinks when writing data to a temporary file upon a call to PrintData or PrintStats.keepalived · keepalived · CWE-59 | Medium4.7 | — | 0.5% | Nov 8, 2018 |
18Monitor | CVE-2018-19046No exploit | keepalived 2.0.8 didn't check for existing plain files when writing data to a temporary file upon a call to PrintData or PrintStats.keepalived · keepalived · CWE-200 | Medium4.7 | — | 0.4% | Nov 8, 2018 |
14Monitor | CVE-2011-1784No exploit | The pidfile_write function in core/pidfile.c in keepalived 1.2.2 and earlier uses 0666 permissions for the (1) keepalived.pid, (2) checkers.keepalived · keepalived · CWE-264 | Low3.6 | — | 0.4% | May 20, 2011 |
- CVE-2018-1911540Plan
keepalived before 2.0.7 has a heap-based buffer overflow when parsing HTTP status codes resulting in DoS or possibly unspecified other impac
CriticalCVSS 9.8No exploitEPSS 4%keepalived · keepalivedNov 8, 2018
- CVE-2018-1904531Monitor
keepalived 2.0.8 used mode 0666 when creating new temporary files upon a call to PrintData or PrintStats, potentially leaking sensitive info
HighCVSS 7.5No exploitEPSS 2%keepalived · keepalivedNov 8, 2018
- CVE-2021-4422521Monitor
In Keepalived through 2.2.4, the D-Bus policy does not sufficiently restrict the message destination, allowing any user to inspect and manip
MediumCVSS 5.4No exploitEPSS 1%keepalived · keepalivedNov 25, 2021
- CVE-2018-1904418Monitor
keepalived 2.0.8 didn't check for pathnames with symlinks when writing data to a temporary file upon a call to PrintData or PrintStats.
MediumCVSS 4.7No exploitEPSS 1%keepalived · keepalivedNov 8, 2018
- CVE-2018-1904618Monitor
keepalived 2.0.8 didn't check for existing plain files when writing data to a temporary file upon a call to PrintData or PrintStats.
MediumCVSS 4.7No exploitEPSS 0%keepalived · keepalivedNov 8, 2018
- CVE-2011-178414Monitor
The pidfile_write function in core/pidfile.c in keepalived 1.2.2 and earlier uses 0666 permissions for the (1) keepalived.pid, (2) checkers.
LowCVSS 3.6No exploitEPSS 0%keepalived · keepalivedMay 20, 2011