memcached kayıtları
memcached üreticisine ait 21 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 2 · %9,5
- Pre-auth RCE
- 4
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-190 Integer Overflow or Wraparound4
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer3
- CWE-208 Observable Timing Discrepancy2
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')2
- CWE-400 Uncontrolled Resource Consumption2
- CWE-193 Off-by-one Error1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
21 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
56Planlayın | CVE-2018-1000115Silahlaştırılmış | Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amplification, CWE-406) vulnerability in the UDPmemcached · memcached · CWE-400 | Yüksek7,5 | — | %88,1 | 5 Mar 2018 |
46Planlayın | CVE-2016-8706Kavram kanıtı | An integer overflow in process_bin_sasl_auth function in Memcached, which is responsible for authentication commands of Memcached binary promemcached · memcached · CWE-190 | Yüksek8,1 | — | %45,7 | 6 Oca 2017 |
46Planlayın | CVE-2016-8704İstismar yok | An integer overflow in the process_bin_append_prepend function in Memcached, which is responsible for processing multiple commands of Memcacmemcached · memcached · CWE-190 | Kritik9,8 | — | %23,2 | 6 Oca 2017 |
45Planlayın | CVE-2016-8705İstismar yok | Multiple integer overflows in process_bin_update function in Memcached, which is responsible for processing multiple commands of Memcached bmemcached · memcached · CWE-190 | Kritik9,8 | — | %19,9 | 6 Oca 2017 |
39İzleyin | CVE-2023-46853İstismar yok | In Memcached before 1.6.22, an off-by-one error exists when processing proxy requests in proxy mode, if \n is used instead of \r\n.memcached · memcached · CWE-193 | Kritik9,8 | — | %0,8 | 27 Eki 2023 |
38İzleyin | CVE-2020-10931İstismar yok | Memcached 1.6.x before 1.6.2 allows remote attackers to cause a denial of service (daemon crash) via a crafted binary protocol header to trymemcached · memcached · CWE-120 | Yüksek7,5 | — | %28,1 | 24 Mar 2020 |
32İzleyin | CVE-2026-47783İstismar yok | In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon amemcached · memcached · CWE-208 | Yüksek8,1 | — | %1,3 | 20 May 2026 |
32İzleyin | CVE-2026-47784İstismar yok | In memcached before 1.6.42, password data for SASL password database authentication has a timing side channel because memcmp is used by saslmemcached · memcached · CWE-208 | Yüksek8,1 | — | %0,6 | 20 May 2026 |
31İzleyin | CVE-2017-9951İstismar yok | The try_read_command function in memcached.c in memcached before 1.4.39 allows remote attackers to cause a denial of service (segmentation fmemcached · memcached | Yüksek7,5 | — | %4,2 | 17 Tem 2017 |
31İzleyin | CVE-2019-11596İstismar yok | In memcached before 1.5.14, a NULL pointer dereference was found in the "lru mode" and "lru temp_ttl" commands.memcached · memcached · CWE-476 | Yüksek7,5 | — | %3,0 | 29 Nis 2019 |
31İzleyin | CVE-2019-15026İstismar yok | memcached 1.5.16, when UNIX sockets are used, has a stack-based buffer over-read in conn_to_str in memcached.c.memcached · memcached · CWE-125 | Yüksek7,5 | — | %2,6 | 30 Ağu 2019 |
31İzleyin | CVE-2018-1000127İstismar yok | memcached version prior to 1.4.37 contains an Integer Overflow vulnerability in items.c:item_free() that can result in data corruption and dmemcached · memcached · CWE-190 | Yüksek7,5 | — | %2,3 | 13 Mar 2018 |
30İzleyin | CVE-2020-22570İstismar yok | Memcached 1.6.0 before 1.6.3 allows remote attackers to cause a denial of service (daemon crash) via a crafted meta command.memcached · memcached · CWE-77 | Yüksek7,5 | — | %1,3 | 22 Ağu 2023 |
30İzleyin | CVE-2022-48571İstismar yok | memcached 1.6.7 allows a Denial of Service via multi-packet uploads in UDP.memcached · memcached · CWE-400 | Yüksek7,5 | — | %1,1 | 22 Ağu 2023 |
30İzleyin | CVE-2023-46852İstismar yok | In Memcached before 1.6.22, a buffer overflow exists when processing multiget requests in proxy mode, if there are many spaces after the "gememcached · memcached · CWE-120 | Yüksek7,5 | — | %0,8 | 27 Eki 2023 |
27İzleyin | CVE-2011-4971Silahlaştırılmış | Multiple integer signedness errors in the (1) process_bin_sasl_auth, (2) process_bin_complete_sasl_auth, (3) process_bin_update, and (4) promemcached · memcached · CWE-189 | Orta5,0 | — | %22,3 | 12 Ara 2013 |
22İzleyin | CVE-2021-37519İstismar yok | Buffer Overflow vulnerability in authfile.c memcached 1.6.9 allows attackers to cause a denial of service via crafted authenticattion file.memcached · memcached · CWE-787 | Orta5,5 | — | %0,4 | 3 Şub 2023 |
19İzleyin | CVE-2013-7239İstismar yok | memcached before 1.4.17 allows remote attackers to bypass authentication by sending an invalid request with SASL credentials, then sending amemcached · memcached · CWE-287 | Orta4,8 | — | %1,2 | 13 Oca 2014 |
7İzleyin | CVE-2013-0179İstismar yok | The process_bin_delete function in memcached.c in memcached 1.4.4 and other versions before 1.4.17, when running in verbose mode, allows remmemcached · memcached · CWE-119 | Düşük1,8 | — | %1,5 | 13 Oca 2014 |
7İzleyin | CVE-2013-7291İstismar yok | memcached before 1.4.17, when running in verbose mode, allows remote attackers to cause a denial of service (crash) via a request that triggmemcached · memcached · CWE-119 | Düşük1,8 | — | %0,9 | 13 Oca 2014 |
7İzleyin | CVE-2013-7290İstismar yok | The do_item_get function in items.c in memcached 1.4.4 and other versions before 1.4.17, when running in verbose mode, allows remote attackememcached · memcached · CWE-119 | Düşük1,8 | — | %0,9 | 13 Oca 2014 |
- CVE-2018-100011556Planlayın
Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amplification, CWE-406) vulnerability in the UDP
YüksekCVSS 7,5SilahlaştırılmışEPSS %88memcached · memcached5 Mar 2018
- CVE-2016-870646Planlayın
An integer overflow in process_bin_sasl_auth function in Memcached, which is responsible for authentication commands of Memcached binary pro
YüksekCVSS 8,1Kavram kanıtıEPSS %46memcached · memcached6 Oca 2017
- CVE-2016-870446Planlayın
An integer overflow in the process_bin_append_prepend function in Memcached, which is responsible for processing multiple commands of Memcac
KritikCVSS 9,8İstismar yokEPSS %23memcached · memcached6 Oca 2017
- CVE-2016-870545Planlayın
Multiple integer overflows in process_bin_update function in Memcached, which is responsible for processing multiple commands of Memcached b
KritikCVSS 9,8İstismar yokEPSS %20memcached · memcached6 Oca 2017
- CVE-2023-4685339İzleyin
In Memcached before 1.6.22, an off-by-one error exists when processing proxy requests in proxy mode, if \n is used instead of \r\n.
KritikCVSS 9,8İstismar yokEPSS %1memcached · memcached27 Eki 2023
- CVE-2020-1093138İzleyin
Memcached 1.6.x before 1.6.2 allows remote attackers to cause a denial of service (daemon crash) via a crafted binary protocol header to try
YüksekCVSS 7,5İstismar yokEPSS %28memcached · memcached24 Mar 2020
- CVE-2026-4778332İzleyin
In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon a
YüksekCVSS 8,1İstismar yokEPSS %1memcached · memcached20 May 2026
- CVE-2026-4778432İzleyin
In memcached before 1.6.42, password data for SASL password database authentication has a timing side channel because memcmp is used by sasl
YüksekCVSS 8,1İstismar yokEPSS %1memcached · memcached20 May 2026
- CVE-2017-995131İzleyin
The try_read_command function in memcached.c in memcached before 1.4.39 allows remote attackers to cause a denial of service (segmentation f
YüksekCVSS 7,5İstismar yokEPSS %4memcached · memcached17 Tem 2017
- CVE-2019-1159631İzleyin
In memcached before 1.5.14, a NULL pointer dereference was found in the "lru mode" and "lru temp_ttl" commands.
YüksekCVSS 7,5İstismar yokEPSS %3memcached · memcached29 Nis 2019
- CVE-2019-1502631İzleyin
memcached 1.5.16, when UNIX sockets are used, has a stack-based buffer over-read in conn_to_str in memcached.c.
YüksekCVSS 7,5İstismar yokEPSS %3memcached · memcached30 Ağu 2019
- CVE-2018-100012731İzleyin
memcached version prior to 1.4.37 contains an Integer Overflow vulnerability in items.c:item_free() that can result in data corruption and d
YüksekCVSS 7,5İstismar yokEPSS %2memcached · memcached13 Mar 2018
- CVE-2020-2257030İzleyin
Memcached 1.6.0 before 1.6.3 allows remote attackers to cause a denial of service (daemon crash) via a crafted meta command.
YüksekCVSS 7,5İstismar yokEPSS %1memcached · memcached22 Ağu 2023
- CVE-2022-4857130İzleyin
memcached 1.6.7 allows a Denial of Service via multi-packet uploads in UDP.
YüksekCVSS 7,5İstismar yokEPSS %1memcached · memcached22 Ağu 2023
- CVE-2023-4685230İzleyin
In Memcached before 1.6.22, a buffer overflow exists when processing multiget requests in proxy mode, if there are many spaces after the "ge
YüksekCVSS 7,5İstismar yokEPSS %1memcached · memcached27 Eki 2023
- CVE-2011-497127İzleyin
Multiple integer signedness errors in the (1) process_bin_sasl_auth, (2) process_bin_complete_sasl_auth, (3) process_bin_update, and (4) pro
OrtaCVSS 5,0SilahlaştırılmışEPSS %22memcached · memcached12 Ara 2013
- CVE-2021-3751922İzleyin
Buffer Overflow vulnerability in authfile.c memcached 1.6.9 allows attackers to cause a denial of service via crafted authenticattion file.
OrtaCVSS 5,5İstismar yokEPSS %0memcached · memcached3 Şub 2023
- CVE-2013-723919İzleyin
memcached before 1.4.17 allows remote attackers to bypass authentication by sending an invalid request with SASL credentials, then sending a
OrtaCVSS 4,8İstismar yokEPSS %1memcached · memcached13 Oca 2014
- CVE-2013-01797İzleyin
The process_bin_delete function in memcached.c in memcached 1.4.4 and other versions before 1.4.17, when running in verbose mode, allows rem
DüşükCVSS 1,8İstismar yokEPSS %1memcached · memcached13 Oca 2014
- CVE-2013-72917İzleyin
memcached before 1.4.17, when running in verbose mode, allows remote attackers to cause a denial of service (crash) via a request that trigg
DüşükCVSS 1,8İstismar yokEPSS %1memcached · memcached13 Oca 2014
- CVE-2013-72907İzleyin
The do_item_get function in items.c in memcached 1.4.4 and other versions before 1.4.17, when running in verbose mode, allows remote attacke
DüşükCVSS 1,8İstismar yokEPSS %1memcached · memcached13 Oca 2014