Memcached records
21 published records for vendor memcached.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 2 · 9.5%
- Pre-auth RCE
- 4
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-190 Integer Overflow or Wraparound4
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer3
- CWE-208 Observable Timing Discrepancy2
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')2
- CWE-400 Uncontrolled Resource Consumption2
- CWE-193 Off-by-one Error1
The weakness classes this vendor ships most often: where to look.
CWEAll records
21 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
56Plan | CVE-2018-1000115Weaponized | Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amplification, CWE-406) vulnerability in the UDPmemcached · memcached · CWE-400 | High7.5 | — | 88.1% | Mar 5, 2018 |
46Plan | CVE-2016-8706Proof of concept | An integer overflow in process_bin_sasl_auth function in Memcached, which is responsible for authentication commands of Memcached binary promemcached · memcached · CWE-190 | High8.1 | — | 45.7% | Jan 6, 2017 |
46Plan | CVE-2016-8704No exploit | An integer overflow in the process_bin_append_prepend function in Memcached, which is responsible for processing multiple commands of Memcacmemcached · memcached · CWE-190 | Critical9.8 | — | 23.2% | Jan 6, 2017 |
45Plan | CVE-2016-8705No exploit | Multiple integer overflows in process_bin_update function in Memcached, which is responsible for processing multiple commands of Memcached bmemcached · memcached · CWE-190 | Critical9.8 | — | 19.9% | Jan 6, 2017 |
39Monitor | CVE-2023-46853No exploit | In Memcached before 1.6.22, an off-by-one error exists when processing proxy requests in proxy mode, if \n is used instead of \r\n.memcached · memcached · CWE-193 | Critical9.8 | — | 0.8% | Oct 27, 2023 |
38Monitor | CVE-2020-10931No exploit | Memcached 1.6.x before 1.6.2 allows remote attackers to cause a denial of service (daemon crash) via a crafted binary protocol header to trymemcached · memcached · CWE-120 | High7.5 | — | 28.1% | Mar 24, 2020 |
32Monitor | CVE-2026-47783No exploit | In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon amemcached · memcached · CWE-208 | High8.1 | — | 1.3% | May 20, 2026 |
32Monitor | CVE-2026-47784No exploit | In memcached before 1.6.42, password data for SASL password database authentication has a timing side channel because memcmp is used by saslmemcached · memcached · CWE-208 | High8.1 | — | 0.6% | May 20, 2026 |
31Monitor | CVE-2017-9951No exploit | The try_read_command function in memcached.c in memcached before 1.4.39 allows remote attackers to cause a denial of service (segmentation fmemcached · memcached | High7.5 | — | 4.2% | Jul 17, 2017 |
31Monitor | CVE-2019-11596No exploit | In memcached before 1.5.14, a NULL pointer dereference was found in the "lru mode" and "lru temp_ttl" commands.memcached · memcached · CWE-476 | High7.5 | — | 3.0% | Apr 29, 2019 |
31Monitor | CVE-2019-15026No exploit | memcached 1.5.16, when UNIX sockets are used, has a stack-based buffer over-read in conn_to_str in memcached.c.memcached · memcached · CWE-125 | High7.5 | — | 2.6% | Aug 30, 2019 |
31Monitor | CVE-2018-1000127No exploit | memcached version prior to 1.4.37 contains an Integer Overflow vulnerability in items.c:item_free() that can result in data corruption and dmemcached · memcached · CWE-190 | High7.5 | — | 2.3% | Mar 13, 2018 |
30Monitor | CVE-2020-22570No exploit | Memcached 1.6.0 before 1.6.3 allows remote attackers to cause a denial of service (daemon crash) via a crafted meta command.memcached · memcached · CWE-77 | High7.5 | — | 1.3% | Aug 22, 2023 |
30Monitor | CVE-2022-48571No exploit | memcached 1.6.7 allows a Denial of Service via multi-packet uploads in UDP.memcached · memcached · CWE-400 | High7.5 | — | 1.1% | Aug 22, 2023 |
30Monitor | CVE-2023-46852No exploit | In Memcached before 1.6.22, a buffer overflow exists when processing multiget requests in proxy mode, if there are many spaces after the "gememcached · memcached · CWE-120 | High7.5 | — | 0.8% | Oct 27, 2023 |
27Monitor | CVE-2011-4971Weaponized | Multiple integer signedness errors in the (1) process_bin_sasl_auth, (2) process_bin_complete_sasl_auth, (3) process_bin_update, and (4) promemcached · memcached · CWE-189 | Medium5.0 | — | 22.3% | Dec 12, 2013 |
22Monitor | CVE-2021-37519No exploit | Buffer Overflow vulnerability in authfile.c memcached 1.6.9 allows attackers to cause a denial of service via crafted authenticattion file.memcached · memcached · CWE-787 | Medium5.5 | — | 0.4% | Feb 3, 2023 |
19Monitor | CVE-2013-7239No exploit | memcached before 1.4.17 allows remote attackers to bypass authentication by sending an invalid request with SASL credentials, then sending amemcached · memcached · CWE-287 | Medium4.8 | — | 1.2% | Jan 13, 2014 |
7Monitor | CVE-2013-0179No exploit | The process_bin_delete function in memcached.c in memcached 1.4.4 and other versions before 1.4.17, when running in verbose mode, allows remmemcached · memcached · CWE-119 | Low1.8 | — | 1.5% | Jan 13, 2014 |
7Monitor | CVE-2013-7291No exploit | memcached before 1.4.17, when running in verbose mode, allows remote attackers to cause a denial of service (crash) via a request that triggmemcached · memcached · CWE-119 | Low1.8 | — | 0.9% | Jan 13, 2014 |
7Monitor | CVE-2013-7290No exploit | The do_item_get function in items.c in memcached 1.4.4 and other versions before 1.4.17, when running in verbose mode, allows remote attackememcached · memcached · CWE-119 | Low1.8 | — | 0.9% | Jan 13, 2014 |
- CVE-2018-100011556Plan
Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amplification, CWE-406) vulnerability in the UDP
HighCVSS 7.5WeaponizedEPSS 88%memcached · memcachedMar 5, 2018
- CVE-2016-870646Plan
An integer overflow in process_bin_sasl_auth function in Memcached, which is responsible for authentication commands of Memcached binary pro
HighCVSS 8.1Proof of conceptEPSS 46%memcached · memcachedJan 6, 2017
- CVE-2016-870446Plan
An integer overflow in the process_bin_append_prepend function in Memcached, which is responsible for processing multiple commands of Memcac
CriticalCVSS 9.8No exploitEPSS 23%memcached · memcachedJan 6, 2017
- CVE-2016-870545Plan
Multiple integer overflows in process_bin_update function in Memcached, which is responsible for processing multiple commands of Memcached b
CriticalCVSS 9.8No exploitEPSS 20%memcached · memcachedJan 6, 2017
- CVE-2023-4685339Monitor
In Memcached before 1.6.22, an off-by-one error exists when processing proxy requests in proxy mode, if \n is used instead of \r\n.
CriticalCVSS 9.8No exploitEPSS 1%memcached · memcachedOct 27, 2023
- CVE-2020-1093138Monitor
Memcached 1.6.x before 1.6.2 allows remote attackers to cause a denial of service (daemon crash) via a crafted binary protocol header to try
HighCVSS 7.5No exploitEPSS 28%memcached · memcachedMar 24, 2020
- CVE-2026-4778332Monitor
In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon a
HighCVSS 8.1No exploitEPSS 1%memcached · memcachedMay 20, 2026
- CVE-2026-4778432Monitor
In memcached before 1.6.42, password data for SASL password database authentication has a timing side channel because memcmp is used by sasl
HighCVSS 8.1No exploitEPSS 1%memcached · memcachedMay 20, 2026
- CVE-2017-995131Monitor
The try_read_command function in memcached.c in memcached before 1.4.39 allows remote attackers to cause a denial of service (segmentation f
HighCVSS 7.5No exploitEPSS 4%memcached · memcachedJul 17, 2017
- CVE-2019-1159631Monitor
In memcached before 1.5.14, a NULL pointer dereference was found in the "lru mode" and "lru temp_ttl" commands.
HighCVSS 7.5No exploitEPSS 3%memcached · memcachedApr 29, 2019
- CVE-2019-1502631Monitor
memcached 1.5.16, when UNIX sockets are used, has a stack-based buffer over-read in conn_to_str in memcached.c.
HighCVSS 7.5No exploitEPSS 3%memcached · memcachedAug 30, 2019
- CVE-2018-100012731Monitor
memcached version prior to 1.4.37 contains an Integer Overflow vulnerability in items.c:item_free() that can result in data corruption and d
HighCVSS 7.5No exploitEPSS 2%memcached · memcachedMar 13, 2018
- CVE-2020-2257030Monitor
Memcached 1.6.0 before 1.6.3 allows remote attackers to cause a denial of service (daemon crash) via a crafted meta command.
HighCVSS 7.5No exploitEPSS 1%memcached · memcachedAug 22, 2023
- CVE-2022-4857130Monitor
memcached 1.6.7 allows a Denial of Service via multi-packet uploads in UDP.
HighCVSS 7.5No exploitEPSS 1%memcached · memcachedAug 22, 2023
- CVE-2023-4685230Monitor
In Memcached before 1.6.22, a buffer overflow exists when processing multiget requests in proxy mode, if there are many spaces after the "ge
HighCVSS 7.5No exploitEPSS 1%memcached · memcachedOct 27, 2023
- CVE-2011-497127Monitor
Multiple integer signedness errors in the (1) process_bin_sasl_auth, (2) process_bin_complete_sasl_auth, (3) process_bin_update, and (4) pro
MediumCVSS 5.0WeaponizedEPSS 22%memcached · memcachedDec 12, 2013
- CVE-2021-3751922Monitor
Buffer Overflow vulnerability in authfile.c memcached 1.6.9 allows attackers to cause a denial of service via crafted authenticattion file.
MediumCVSS 5.5No exploitEPSS 0%memcached · memcachedFeb 3, 2023
- CVE-2013-723919Monitor
memcached before 1.4.17 allows remote attackers to bypass authentication by sending an invalid request with SASL credentials, then sending a
MediumCVSS 4.8No exploitEPSS 1%memcached · memcachedJan 13, 2014
- CVE-2013-01797Monitor
The process_bin_delete function in memcached.c in memcached 1.4.4 and other versions before 1.4.17, when running in verbose mode, allows rem
LowCVSS 1.8No exploitEPSS 1%memcached · memcachedJan 13, 2014
- CVE-2013-72917Monitor
memcached before 1.4.17, when running in verbose mode, allows remote attackers to cause a denial of service (crash) via a request that trigg
LowCVSS 1.8No exploitEPSS 1%memcached · memcachedJan 13, 2014
- CVE-2013-72907Monitor
The do_item_get function in items.c in memcached 1.4.4 and other versions before 1.4.17, when running in verbose mode, allows remote attacke
LowCVSS 1.8No exploitEPSS 1%memcached · memcachedJan 13, 2014