Skip to content
Noroxi

keepalived records

6 published records for vendor keepalived.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
100%
Median publish → KEV
No record has entered KEV

All records

6 records
  • keepalived before 2.0.7 has a heap-based buffer overflow when parsing HTTP status codes resulting in DoS or possibly unspecified other impac

    CriticalCVSS 9.8No exploitEPSS 4%

    keepalived · keepalivedNov 8, 2018

  • keepalived 2.0.8 used mode 0666 when creating new temporary files upon a call to PrintData or PrintStats, potentially leaking sensitive info

    HighCVSS 7.5No exploitEPSS 2%

    keepalived · keepalivedNov 8, 2018

  • In Keepalived through 2.2.4, the D-Bus policy does not sufficiently restrict the message destination, allowing any user to inspect and manip

    MediumCVSS 5.4No exploitEPSS 1%

    keepalived · keepalivedNov 25, 2021

  • keepalived 2.0.8 didn't check for pathnames with symlinks when writing data to a temporary file upon a call to PrintData or PrintStats.

    MediumCVSS 4.7No exploitEPSS 1%

    keepalived · keepalivedNov 8, 2018

  • keepalived 2.0.8 didn't check for existing plain files when writing data to a temporary file upon a call to PrintData or PrintStats.

    MediumCVSS 4.7No exploitEPSS 0%

    keepalived · keepalivedNov 8, 2018

  • CVE-2011-1784
    14Monitor

    The pidfile_write function in core/pidfile.c in keepalived 1.2.2 and earlier uses 0666 permissions for the (1) keepalived.pid, (2) checkers.

    LowCVSS 3.6No exploitEPSS 0%

    keepalived · keepalivedMay 20, 2011