Skip to content
Noroxi

openslp records

9 published records for vendor openslp.

Researcher profile

Entered KEV
1 · 11.1%
Weaponized
1 · 11.1%
Pre-auth RCE
0
With a fix record
77.8%
Median publish → KEV
698 days

All records

9 records
  • OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue.

    CriticalCVSS 9.8KEVWeaponizedEPSS 97%

    openslp · openslpDec 6, 2019

  • Buffer overflow in the SLPFoldWhiteSpace function in common/slp_compare.c in OpenSLP 2.0 allows remote attackers to have unspecified impact

    CriticalCVSS 9.8Proof of conceptEPSS 12%

    openslp · openslpJan 23, 2017

  • OpenSLP releases in the 1.0.2 and 1.1.0 code streams have a heap-related memory corruption issue which may manifest itself as a denial-of-se

    CriticalCVSS 9.8No exploitEPSS 4%

    openslp · openslpApr 23, 2018

  • CVE-2012-4428
    33Monitor

    openslp: SLPIntersectStringList()' Function has a DoS vulnerability

    HighCVSS 7.5No exploitEPSS 10%

    openslp · openslpDec 2, 2019

  • CVE-2015-5177
    32Monitor

    Double free vulnerability in the SLPDKnownDAAdd function in slpd/slpd_knownda.c in OpenSLP 1.2.1 allows remote attackers to cause a denial o

    HighCVSS 7.5No exploitEPSS 6%

    openslp · openslpOct 22, 2017

  • CVE-2016-4912
    32Monitor

    The _xrealloc function in xlsp_xmalloc.c in OpenSLP 2.0.0 allows remote attackers to cause a denial of service (NULL pointer dereference and

    HighCVSS 7.5No exploitEPSS 5%

    openslp · openslpMar 27, 2017

  • CVE-2005-0769
    31Monitor

    Multiple buffer overflows in OpenSLP before 1.1.5 allow remote attackers to have an unknown impact via malformed SLP packets.

    HighCVSS 7.5No exploitEPSS 3%

    openslp · openslpMay 2, 2005

  • CVE-2010-3609
    25Monitor

    The extension parser in slp_v2message.c in OpenSLP 1.2.1, and other versions before SVN revision 1647, as used in Service Location Protocol

    MediumCVSS 5.0Proof of conceptEPSS 17%

    openslp · openslpMar 11, 2011

  • Symbolic link vulnerability in the slpd script slpd.all_init for OpenSLP before 1.0.11 allows local users to overwrite arbitrary files via t

    LowCVSS 2.1No exploitEPSS 0%

    openslp · openslpNov 17, 2003