zeromq records
11 published records for vendor zeromq.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 90.9%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-400 Uncontrolled Resource Consumption3
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')2
- CWE-787 Out-of-bounds Write2
- CWE-190 Integer Overflow or Wraparound1
- CWE-20 Improper Input Validation1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
11 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
51Plan | CVE-2019-13132Proof of concept | In ZeroMQ libzmq before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.3.2, a remote, unauthenticated client connecting to a libzmq applicatizeromq · libzmq · CWE-787 | Critical9.8 | — | 41.6% | Jul 10, 2019 |
45Plan | CVE-2021-20235No exploit | There's a flaw in the zeromq server in versions before 4.3.3 in src/decoder_allocators.hpp.zeromq · libzmq · CWE-120 | High8.1 | — | 43.9% | Apr 1, 2021 |
40Plan | CVE-2020-36400No exploit | ZeroMQ libzmq 4.3.3 has a heap-based buffer overflow in zmq::tcp_read, a different vulnerability than CVE-2021-20235.zeromq · libzmq · CWE-787 | Critical9.8 | — | 1.8% | Jun 30, 2021 |
39Monitor | CVE-2021-20236No exploit | A flaw was found in the ZeroMQ server in versions before 4.3.3.zeromq · zeromq · CWE-120 | Critical9.8 | — | 1.6% | May 28, 2021 |
38Monitor | CVE-2019-6250Proof of concept | A pointer overflow, with code execution, was discovered in ZeroMQ libzmq (aka 0MQ) 4.2.x and 4.3.x before 4.3.1.zeromq · libzmq · CWE-190 | High8.8 | — | 9.7% | Jan 13, 2019 |
31Monitor | CVE-2020-15166No exploit | Denial of Service in ZeroMQzeromq · libzmq · CWE-400 | High7.5 | — | 3.4% | Sep 11, 2020 |
31Monitor | CVE-2021-20237No exploit | An uncontrolled resource consumption (memory leak) flaw was found in ZeroMQ's src/xpub.cpp in versions before 4.3.3.zeromq · libzmq · CWE-400 | High7.5 | — | 1.7% | May 28, 2021 |
26Monitor | CVE-2021-20234No exploit | An uncontrolled resource consumption (memory leak) flaw was found in the ZeroMQ client in versions before 4.3.3 in src/pipe.cpp.zeromq · libzmq · CWE-400 | Medium6.5 | — | 1.1% | Apr 1, 2021 |
18Monitor | CVE-2014-9721No exploit | libzmq before 4.0.6 and 4.1.x before 4.1.1 allows remote attackers to conduct downgrade attacks and bypass ZMTP v3 protocol security mechanizeromq · zeromq · CWE-20 | Medium4.3 | — | 2.5% | Jun 3, 2015 |
18Monitor | CVE-2014-7202No exploit | stream_engine.cpp in libzmq (aka ZeroMQ/C++)) 4.0.5 before 4.0.5 allows man-in-the-middle attackers to conduct downgrade attacks via a craftzeromq · zeromq | Medium4.3 | — | 2.0% | Oct 8, 2014 |
18Monitor | CVE-2014-7203No exploit | libzmq (aka ZeroMQ/C++) 4.0.x before 4.0.5 does not ensure that nonces are unique, which allows man-in-the-middle attackers to conduct replazeromq · zeromq | Medium4.3 | — | 1.9% | Oct 8, 2014 |
- CVE-2019-1313251Plan
In ZeroMQ libzmq before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.3.2, a remote, unauthenticated client connecting to a libzmq applicati
CriticalCVSS 9.8Proof of conceptEPSS 42%zeromq · libzmqJul 10, 2019
- CVE-2021-2023545Plan
There's a flaw in the zeromq server in versions before 4.3.3 in src/decoder_allocators.hpp.
HighCVSS 8.1No exploitEPSS 44%zeromq · libzmqApr 1, 2021
- CVE-2020-3640040Plan
ZeroMQ libzmq 4.3.3 has a heap-based buffer overflow in zmq::tcp_read, a different vulnerability than CVE-2021-20235.
CriticalCVSS 9.8No exploitEPSS 2%zeromq · libzmqJun 30, 2021
- CVE-2021-2023639Monitor
A flaw was found in the ZeroMQ server in versions before 4.3.3.
CriticalCVSS 9.8No exploitEPSS 2%zeromq · zeromqMay 28, 2021
- CVE-2019-625038Monitor
A pointer overflow, with code execution, was discovered in ZeroMQ libzmq (aka 0MQ) 4.2.x and 4.3.x before 4.3.1.
HighCVSS 8.8Proof of conceptEPSS 10%zeromq · libzmqJan 13, 2019
- CVE-2020-1516631Monitor
Denial of Service in ZeroMQ
HighCVSS 7.5No exploitEPSS 3%zeromq · libzmqSep 11, 2020
- CVE-2021-2023731Monitor
An uncontrolled resource consumption (memory leak) flaw was found in ZeroMQ's src/xpub.cpp in versions before 4.3.3.
HighCVSS 7.5No exploitEPSS 2%zeromq · libzmqMay 28, 2021
- CVE-2021-2023426Monitor
An uncontrolled resource consumption (memory leak) flaw was found in the ZeroMQ client in versions before 4.3.3 in src/pipe.cpp.
MediumCVSS 6.5No exploitEPSS 1%zeromq · libzmqApr 1, 2021
- CVE-2014-972118Monitor
libzmq before 4.0.6 and 4.1.x before 4.1.1 allows remote attackers to conduct downgrade attacks and bypass ZMTP v3 protocol security mechani
MediumCVSS 4.3No exploitEPSS 3%zeromq · zeromqJun 3, 2015
- CVE-2014-720218Monitor
stream_engine.cpp in libzmq (aka ZeroMQ/C++)) 4.0.5 before 4.0.5 allows man-in-the-middle attackers to conduct downgrade attacks via a craft
MediumCVSS 4.3No exploitEPSS 2%zeromq · zeromqOct 8, 2014
- CVE-2014-720318Monitor
libzmq (aka ZeroMQ/C++) 4.0.x before 4.0.5 does not ensure that nonces are unique, which allows man-in-the-middle attackers to conduct repla
MediumCVSS 4.3No exploitEPSS 2%zeromq · zeromqOct 8, 2014