Записи Memcached
21 опубликованных записей вендора memcached.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 2 · 9,5 %
- Pre-auth RCE
- 4
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-190 Integer Overflow or Wraparound4
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer3
- CWE-208 Observable Timing Discrepancy2
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')2
- CWE-400 Uncontrolled Resource Consumption2
- CWE-193 Off-by-one Error1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
21 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
56В плане | CVE-2018-1000115Готовый эксплойт | Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amplification, CWE-406) vulnerability in the UDPmemcached · memcached · CWE-400 | Высокая7,5 | — | 88,1 % | 5 мар. 2018 г. |
46В плане | CVE-2016-8706Proof of concept | An integer overflow in process_bin_sasl_auth function in Memcached, which is responsible for authentication commands of Memcached binary promemcached · memcached · CWE-190 | Высокая8,1 | — | 45,7 % | 6 янв. 2017 г. |
46В плане | CVE-2016-8704Эксплойта нет | An integer overflow in the process_bin_append_prepend function in Memcached, which is responsible for processing multiple commands of Memcacmemcached · memcached · CWE-190 | Критическая9,8 | — | 23,2 % | 6 янв. 2017 г. |
45В плане | CVE-2016-8705Эксплойта нет | Multiple integer overflows in process_bin_update function in Memcached, which is responsible for processing multiple commands of Memcached bmemcached · memcached · CWE-190 | Критическая9,8 | — | 19,9 % | 6 янв. 2017 г. |
39Наблюдать | CVE-2023-46853Эксплойта нет | In Memcached before 1.6.22, an off-by-one error exists when processing proxy requests in proxy mode, if \n is used instead of \r\n.memcached · memcached · CWE-193 | Критическая9,8 | — | 0,8 % | 27 окт. 2023 г. |
38Наблюдать | CVE-2020-10931Эксплойта нет | Memcached 1.6.x before 1.6.2 allows remote attackers to cause a denial of service (daemon crash) via a crafted binary protocol header to trymemcached · memcached · CWE-120 | Высокая7,5 | — | 28,1 % | 24 мар. 2020 г. |
32Наблюдать | CVE-2026-47783Эксплойта нет | In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon amemcached · memcached · CWE-208 | Высокая8,1 | — | 1,3 % | 20 мая 2026 г. |
32Наблюдать | CVE-2026-47784Эксплойта нет | In memcached before 1.6.42, password data for SASL password database authentication has a timing side channel because memcmp is used by saslmemcached · memcached · CWE-208 | Высокая8,1 | — | 0,6 % | 20 мая 2026 г. |
31Наблюдать | CVE-2017-9951Эксплойта нет | The try_read_command function in memcached.c in memcached before 1.4.39 allows remote attackers to cause a denial of service (segmentation fmemcached · memcached | Высокая7,5 | — | 4,2 % | 17 июл. 2017 г. |
31Наблюдать | CVE-2019-11596Эксплойта нет | In memcached before 1.5.14, a NULL pointer dereference was found in the "lru mode" and "lru temp_ttl" commands.memcached · memcached · CWE-476 | Высокая7,5 | — | 3,0 % | 29 апр. 2019 г. |
31Наблюдать | CVE-2019-15026Эксплойта нет | memcached 1.5.16, when UNIX sockets are used, has a stack-based buffer over-read in conn_to_str in memcached.c.memcached · memcached · CWE-125 | Высокая7,5 | — | 2,6 % | 30 авг. 2019 г. |
31Наблюдать | CVE-2018-1000127Эксплойта нет | memcached version prior to 1.4.37 contains an Integer Overflow vulnerability in items.c:item_free() that can result in data corruption and dmemcached · memcached · CWE-190 | Высокая7,5 | — | 2,3 % | 13 мар. 2018 г. |
30Наблюдать | CVE-2020-22570Эксплойта нет | Memcached 1.6.0 before 1.6.3 allows remote attackers to cause a denial of service (daemon crash) via a crafted meta command.memcached · memcached · CWE-77 | Высокая7,5 | — | 1,3 % | 22 авг. 2023 г. |
30Наблюдать | CVE-2022-48571Эксплойта нет | memcached 1.6.7 allows a Denial of Service via multi-packet uploads in UDP.memcached · memcached · CWE-400 | Высокая7,5 | — | 1,1 % | 22 авг. 2023 г. |
30Наблюдать | CVE-2023-46852Эксплойта нет | In Memcached before 1.6.22, a buffer overflow exists when processing multiget requests in proxy mode, if there are many spaces after the "gememcached · memcached · CWE-120 | Высокая7,5 | — | 0,8 % | 27 окт. 2023 г. |
27Наблюдать | CVE-2011-4971Готовый эксплойт | Multiple integer signedness errors in the (1) process_bin_sasl_auth, (2) process_bin_complete_sasl_auth, (3) process_bin_update, and (4) promemcached · memcached · CWE-189 | Средняя5,0 | — | 22,3 % | 12 дек. 2013 г. |
22Наблюдать | CVE-2021-37519Эксплойта нет | Buffer Overflow vulnerability in authfile.c memcached 1.6.9 allows attackers to cause a denial of service via crafted authenticattion file.memcached · memcached · CWE-787 | Средняя5,5 | — | 0,4 % | 3 февр. 2023 г. |
19Наблюдать | CVE-2013-7239Эксплойта нет | memcached before 1.4.17 allows remote attackers to bypass authentication by sending an invalid request with SASL credentials, then sending amemcached · memcached · CWE-287 | Средняя4,8 | — | 1,2 % | 13 янв. 2014 г. |
7Наблюдать | CVE-2013-0179Эксплойта нет | The process_bin_delete function in memcached.c in memcached 1.4.4 and other versions before 1.4.17, when running in verbose mode, allows remmemcached · memcached · CWE-119 | Низкая1,8 | — | 1,5 % | 13 янв. 2014 г. |
7Наблюдать | CVE-2013-7291Эксплойта нет | memcached before 1.4.17, when running in verbose mode, allows remote attackers to cause a denial of service (crash) via a request that triggmemcached · memcached · CWE-119 | Низкая1,8 | — | 0,9 % | 13 янв. 2014 г. |
7Наблюдать | CVE-2013-7290Эксплойта нет | The do_item_get function in items.c in memcached 1.4.4 and other versions before 1.4.17, when running in verbose mode, allows remote attackememcached · memcached · CWE-119 | Низкая1,8 | — | 0,9 % | 13 янв. 2014 г. |
- CVE-2018-100011556В плане
Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amplification, CWE-406) vulnerability in the UDP
ВысокаяCVSS 7,5Готовый эксплойтEPSS 88 %memcached · memcached5 мар. 2018 г.
- CVE-2016-870646В плане
An integer overflow in process_bin_sasl_auth function in Memcached, which is responsible for authentication commands of Memcached binary pro
ВысокаяCVSS 8,1Proof of conceptEPSS 46 %memcached · memcached6 янв. 2017 г.
- CVE-2016-870446В плане
An integer overflow in the process_bin_append_prepend function in Memcached, which is responsible for processing multiple commands of Memcac
КритическаяCVSS 9,8Эксплойта нетEPSS 23 %memcached · memcached6 янв. 2017 г.
- CVE-2016-870545В плане
Multiple integer overflows in process_bin_update function in Memcached, which is responsible for processing multiple commands of Memcached b
КритическаяCVSS 9,8Эксплойта нетEPSS 20 %memcached · memcached6 янв. 2017 г.
- CVE-2023-4685339Наблюдать
In Memcached before 1.6.22, an off-by-one error exists when processing proxy requests in proxy mode, if \n is used instead of \r\n.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %memcached · memcached27 окт. 2023 г.
- CVE-2020-1093138Наблюдать
Memcached 1.6.x before 1.6.2 allows remote attackers to cause a denial of service (daemon crash) via a crafted binary protocol header to try
ВысокаяCVSS 7,5Эксплойта нетEPSS 28 %memcached · memcached24 мар. 2020 г.
- CVE-2026-4778332Наблюдать
In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon a
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %memcached · memcached20 мая 2026 г.
- CVE-2026-4778432Наблюдать
In memcached before 1.6.42, password data for SASL password database authentication has a timing side channel because memcmp is used by sasl
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %memcached · memcached20 мая 2026 г.
- CVE-2017-995131Наблюдать
The try_read_command function in memcached.c in memcached before 1.4.39 allows remote attackers to cause a denial of service (segmentation f
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %memcached · memcached17 июл. 2017 г.
- CVE-2019-1159631Наблюдать
In memcached before 1.5.14, a NULL pointer dereference was found in the "lru mode" and "lru temp_ttl" commands.
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %memcached · memcached29 апр. 2019 г.
- CVE-2019-1502631Наблюдать
memcached 1.5.16, when UNIX sockets are used, has a stack-based buffer over-read in conn_to_str in memcached.c.
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %memcached · memcached30 авг. 2019 г.
- CVE-2018-100012731Наблюдать
memcached version prior to 1.4.37 contains an Integer Overflow vulnerability in items.c:item_free() that can result in data corruption and d
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %memcached · memcached13 мар. 2018 г.
- CVE-2020-2257030Наблюдать
Memcached 1.6.0 before 1.6.3 allows remote attackers to cause a denial of service (daemon crash) via a crafted meta command.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %memcached · memcached22 авг. 2023 г.
- CVE-2022-4857130Наблюдать
memcached 1.6.7 allows a Denial of Service via multi-packet uploads in UDP.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %memcached · memcached22 авг. 2023 г.
- CVE-2023-4685230Наблюдать
In Memcached before 1.6.22, a buffer overflow exists when processing multiget requests in proxy mode, if there are many spaces after the "ge
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %memcached · memcached27 окт. 2023 г.
- CVE-2011-497127Наблюдать
Multiple integer signedness errors in the (1) process_bin_sasl_auth, (2) process_bin_complete_sasl_auth, (3) process_bin_update, and (4) pro
СредняяCVSS 5,0Готовый эксплойтEPSS 22 %memcached · memcached12 дек. 2013 г.
- CVE-2021-3751922Наблюдать
Buffer Overflow vulnerability in authfile.c memcached 1.6.9 allows attackers to cause a denial of service via crafted authenticattion file.
СредняяCVSS 5,5Эксплойта нетEPSS 0 %memcached · memcached3 февр. 2023 г.
- CVE-2013-723919Наблюдать
memcached before 1.4.17 allows remote attackers to bypass authentication by sending an invalid request with SASL credentials, then sending a
СредняяCVSS 4,8Эксплойта нетEPSS 1 %memcached · memcached13 янв. 2014 г.
- CVE-2013-01797Наблюдать
The process_bin_delete function in memcached.c in memcached 1.4.4 and other versions before 1.4.17, when running in verbose mode, allows rem
НизкаяCVSS 1,8Эксплойта нетEPSS 1 %memcached · memcached13 янв. 2014 г.
- CVE-2013-72917Наблюдать
memcached before 1.4.17, when running in verbose mode, allows remote attackers to cause a denial of service (crash) via a request that trigg
НизкаяCVSS 1,8Эксплойта нетEPSS 1 %memcached · memcached13 янв. 2014 г.
- CVE-2013-72907Наблюдать
The do_item_get function in items.c in memcached 1.4.4 and other versions before 1.4.17, when running in verbose mode, allows remote attacke
НизкаяCVSS 1,8Эксплойта нетEPSS 1 %memcached · memcached13 янв. 2014 г.