rsyslog kayıtları
rsyslog üreticisine ait 20 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 1 · %5
- Pre-auth RCE
- 5
- Düzeltme kaydı olan
- %95
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-772 Missing Release of Resource after Effective Lifetime3
- CWE-125 Out-of-bounds Read2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-189 Numeric Errors2
- CWE-787 Out-of-bounds Write2
- CWE-190 Integer Overflow or Wraparound1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
20 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
42Planlayın | CVE-2018-1000140Kavram kanıtı | rsyslog librelp version 1.2.14 and earlier contains a Buffer Overflow vulnerability in the checking of x509 certificates from a peer that carsyslog · librelp · CWE-787 | Kritik9,8 | — | %9,3 | 23 Mar 2018 |
40Planlayın | CVE-2019-17041Kavram kanıtı | An issue was discovered in Rsyslog v8.1908.0.rsyslog · rsyslog · CWE-787 | Kritik9,8 | — | %4,4 | 7 Eki 2019 |
40Planlayın | CVE-2019-17042İstismar yok | An issue was discovered in Rsyslog v8.1908.0.rsyslog · rsyslog · CWE-20 | Kritik9,8 | — | %3,1 | 7 Eki 2019 |
40Planlayın | CVE-2017-12588İstismar yok | The zmq3 input and output modules in rsyslog before 8.28.0 interpreted description fields as format strings, possibly allowing a format strirsyslog · rsyslog · CWE-134 | Kritik9,8 | — | %2,8 | 6 Ağu 2017 |
40Planlayın | CVE-2019-17040İstismar yok | contrib/pmdb2diag/pmdb2diag.c in Rsyslog v8.1908.0 allows out-of-bounds access because the level length is mishandled.rsyslog · rsyslog · CWE-125 | Kritik9,8 | — | %2,4 | 30 Eyl 2019 |
35İzleyin | CVE-2008-5617İstismar yok | The ACL handling in rsyslog 3.12.1 to 3.20.0, 4.1.0, and 4.1.1 does not follow $AllowedSender directive, which allows remote attackers to byrsyslog · rsyslog · CWE-264 | Yüksek8,5 | — | %2,2 | 16 Ara 2008 |
33İzleyin | CVE-2022-24903Kavram kanıtı | Buffer overflow in TCP syslog server (receiver) components in rsyslogrsyslog · rsyslog · CWE-120 | Yüksek8,1 | — | %3,9 | 5 May 2022 |
32İzleyin | CVE-2014-3634İstismar yok | rsyslog before 7.6.6 and 8.x before 8.4.1 and sysklogd 1.5 and earlier allows remote attackers to cause a denial of service (crash), possiblrsyslog · rsyslog · CWE-119 | Yüksek7,5 | — | %7,5 | 1 Kas 2014 |
31İzleyin | CVE-2018-16881İstismar yok | A denial of service vulnerability was found in rsyslog in the imptcp module.rsyslog · rsyslog · CWE-190 | Yüksek7,5 | — | %2,2 | 25 Oca 2019 |
30İzleyin | CVE-2005-3074İstismar yok | SQL injection vulnerability in rsyslogd in RSyslog before 1.0.1 and before 1.10.1 allows remote attackers to execute arbitrary SQL commands rsyslog · rsyslogd | Yüksek7,5 | — | %1,1 | 27 Eyl 2005 |
30İzleyin | CVE-2026-19654İstismar yok | Rsyslog: a configuration-dependent issue in rsyslog's optional imptcp input module can allow an unauthenticated remote peer to crash rsyslogdrsyslog · rsyslog · CWE-125 | Yüksek7,5 | — | %0,5 | 12 Ağu 2026 |
28İzleyin | CVE-2013-4758İstismar yok | Double free vulnerability in the writeDataError function in the ElasticSearch plugin (omelasticsearch) in rsyslog before 7.4.2 and before 7.rsyslog · rsyslog · CWE-399 | Orta6,8 | — | %2,3 | 4 Eki 2013 |
26İzleyin | CVE-2011-3200Silahlaştırılmış | Stack-based buffer overflow in the parseLegacySyslogMsg function in tools/syslogd.c in rsyslogd in rsyslog 4.6.x before 4.6.8 and 5.2.0 throrsyslog · rsyslog · CWE-119 | Orta5,0 | — | %20,8 | 6 Eyl 2011 |
22İzleyin | CVE-2011-1488İstismar yok | A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages are logged when $RepeatedMsgReduction was enabled.rsyslog · rsyslog · CWE-772 | Orta5,5 | — | %0,5 | 13 Kas 2019 |
22İzleyin | CVE-2011-1489İstismar yok | A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages were logged when multiple rulesets were used and sorsyslog · rsyslog · CWE-772 | Orta5,5 | — | %0,5 | 13 Kas 2019 |
22İzleyin | CVE-2015-3243İstismar yok | rsyslog uses weak permissions for generating log files, which allows local users to obtain sensitive information by reading files in /var/lorsyslog · rsyslog · CWE-532 | Orta5,5 | — | %0,4 | 25 Tem 2017 |
22İzleyin | CVE-2011-1490İstismar yok | A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages are logged when multiple rulesets were used and somrsyslog · rsyslog · CWE-772 | Orta5,5 | — | %0,4 | 13 Kas 2019 |
21İzleyin | CVE-2014-3683İstismar yok | Integer overflow in rsyslog before 7.6.7 and 8.x before 8.4.2 and sysklogd 1.5 and earlier allows remote attackers to cause a denial of servrsyslog · rsyslog · CWE-189 | Orta5,0 | — | %4,6 | 1 Kas 2014 |
20İzleyin | CVE-2008-5618İstismar yok | imudp in rsyslog 4.x before 4.1.2, 3.21 before 3.21.9 beta, and 3.20 before 3.20.2 generates a message even when it is sent by an unauthorizrsyslog · rsyslog | Orta5,0 | — | %1,2 | 16 Ara 2008 |
8İzleyin | CVE-2011-4623İstismar yok | Integer overflow in the rsCStrExtendBuf function in runtime/stringbuf.c in the imfile module in rsyslog 4.x before 4.6.6, 5.x before 5.7.4, rsyslog · rsyslog · CWE-189 | Düşük2,1 | — | %0,4 | 25 Eyl 2012 |
- CVE-2018-100014042Planlayın
rsyslog librelp version 1.2.14 and earlier contains a Buffer Overflow vulnerability in the checking of x509 certificates from a peer that ca
KritikCVSS 9,8Kavram kanıtıEPSS %9rsyslog · librelp23 Mar 2018
- CVE-2019-1704140Planlayın
An issue was discovered in Rsyslog v8.1908.0.
KritikCVSS 9,8Kavram kanıtıEPSS %4rsyslog · rsyslog7 Eki 2019
- CVE-2019-1704240Planlayın
An issue was discovered in Rsyslog v8.1908.0.
KritikCVSS 9,8İstismar yokEPSS %3rsyslog · rsyslog7 Eki 2019
- CVE-2017-1258840Planlayın
The zmq3 input and output modules in rsyslog before 8.28.0 interpreted description fields as format strings, possibly allowing a format stri
KritikCVSS 9,8İstismar yokEPSS %3rsyslog · rsyslog6 Ağu 2017
- CVE-2019-1704040Planlayın
contrib/pmdb2diag/pmdb2diag.c in Rsyslog v8.1908.0 allows out-of-bounds access because the level length is mishandled.
KritikCVSS 9,8İstismar yokEPSS %2rsyslog · rsyslog30 Eyl 2019
- CVE-2008-561735İzleyin
The ACL handling in rsyslog 3.12.1 to 3.20.0, 4.1.0, and 4.1.1 does not follow $AllowedSender directive, which allows remote attackers to by
YüksekCVSS 8,5İstismar yokEPSS %2rsyslog · rsyslog16 Ara 2008
- CVE-2022-2490333İzleyin
Buffer overflow in TCP syslog server (receiver) components in rsyslog
YüksekCVSS 8,1Kavram kanıtıEPSS %4rsyslog · rsyslog5 May 2022
- CVE-2014-363432İzleyin
rsyslog before 7.6.6 and 8.x before 8.4.1 and sysklogd 1.5 and earlier allows remote attackers to cause a denial of service (crash), possibl
YüksekCVSS 7,5İstismar yokEPSS %8rsyslog · rsyslog1 Kas 2014
- CVE-2018-1688131İzleyin
A denial of service vulnerability was found in rsyslog in the imptcp module.
YüksekCVSS 7,5İstismar yokEPSS %2rsyslog · rsyslog25 Oca 2019
- CVE-2005-307430İzleyin
SQL injection vulnerability in rsyslogd in RSyslog before 1.0.1 and before 1.10.1 allows remote attackers to execute arbitrary SQL commands
YüksekCVSS 7,5İstismar yokEPSS %1rsyslog · rsyslogd27 Eyl 2005
- CVE-2026-1965430İzleyin
Rsyslog: a configuration-dependent issue in rsyslog's optional imptcp input module can allow an unauthenticated remote peer to crash rsyslogd
YüksekCVSS 7,5İstismar yokEPSS %0rsyslog · rsyslog12 Ağu 2026
- CVE-2013-475828İzleyin
Double free vulnerability in the writeDataError function in the ElasticSearch plugin (omelasticsearch) in rsyslog before 7.4.2 and before 7.
OrtaCVSS 6,8İstismar yokEPSS %2rsyslog · rsyslog4 Eki 2013
- CVE-2011-320026İzleyin
Stack-based buffer overflow in the parseLegacySyslogMsg function in tools/syslogd.c in rsyslogd in rsyslog 4.6.x before 4.6.8 and 5.2.0 thro
OrtaCVSS 5,0SilahlaştırılmışEPSS %21rsyslog · rsyslog6 Eyl 2011
- CVE-2011-148822İzleyin
A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages are logged when $RepeatedMsgReduction was enabled.
OrtaCVSS 5,5İstismar yokEPSS %0rsyslog · rsyslog13 Kas 2019
- CVE-2011-148922İzleyin
A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages were logged when multiple rulesets were used and so
OrtaCVSS 5,5İstismar yokEPSS %0rsyslog · rsyslog13 Kas 2019
- CVE-2015-324322İzleyin
rsyslog uses weak permissions for generating log files, which allows local users to obtain sensitive information by reading files in /var/lo
OrtaCVSS 5,5İstismar yokEPSS %0rsyslog · rsyslog25 Tem 2017
- CVE-2011-149022İzleyin
A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages are logged when multiple rulesets were used and som
OrtaCVSS 5,5İstismar yokEPSS %0rsyslog · rsyslog13 Kas 2019
- CVE-2014-368321İzleyin
Integer overflow in rsyslog before 7.6.7 and 8.x before 8.4.2 and sysklogd 1.5 and earlier allows remote attackers to cause a denial of serv
OrtaCVSS 5,0İstismar yokEPSS %5rsyslog · rsyslog1 Kas 2014
- CVE-2008-561820İzleyin
imudp in rsyslog 4.x before 4.1.2, 3.21 before 3.21.9 beta, and 3.20 before 3.20.2 generates a message even when it is sent by an unauthoriz
OrtaCVSS 5,0İstismar yokEPSS %1rsyslog · rsyslog16 Ara 2008
- CVE-2011-46238İzleyin
Integer overflow in the rsCStrExtendBuf function in runtime/stringbuf.c in the imfile module in rsyslog 4.x before 4.6.6, 5.x before 5.7.4,
DüşükCVSS 2,1İstismar yokEPSS %0rsyslog · rsyslog25 Eyl 2012