Vulnerability index

Browse CVEs

9 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Rsyslog CRITICAL 9.8
CVE-2019-17040

contrib/pmdb2diag/pmdb2diag.c in Rsyslog v8.1908.0 allows out-of-bounds access because the level length is mishandled.

Patch available
Fix from $2,300 2019-09-30
Rsyslog CRITICAL 9.8
CVE-2017-12588

The zmq3 input and output modules in rsyslog before 8.28.0 interpreted description fields as format strings, possibly allowing a format string attack…

Fix: after 8.27.0
Fix from $2,300 2017-08-06
Rsyslog MEDIUM 5.5
CVE-2015-3243

rsyslog uses weak permissions for generating log files, which allows local users to obtain sensitive information by reading files in /var/log/cron.

Mitigation only
Fix from $1,600 2017-07-25
Rsyslog MEDIUM 5.0
CVE-2014-3683

Integer overflow in rsyslog before 7.6.7 and 8.x before 8.4.2 and sysklogd 1.5 and earlier allows remote attackers to cause a denial of service (cras…

Fix: after 7.6.6
Fix from $1,600 2014-11-02
Rsyslog MEDIUM 6.8
CVE-2013-4758

Double free vulnerability in the writeDataError function in the ElasticSearch plugin (omelasticsearch) in rsyslog before 7.4.2 and before 7.5.2 devel…

Fix: after 7.5.1
Fix from $1,600 2013-10-04
Rsyslog MEDIUM 5.0
CVE-2011-3200EPSS 21%

Stack-based buffer overflow in the parseLegacySyslogMsg function in tools/syslogd.c in rsyslogd in rsyslog 4.6.x before 4.6.8 and 5.2.0 through 5.8.4…

Patch available
Fix from $1,600 2011-09-06
Rsyslog HIGH 8.5
CVE-2008-5617

The ACL handling in rsyslog 3.12.1 to 3.20.0, 4.1.0, and 4.1.1 does not follow $AllowedSender directive, which allows remote attackers to bypass inte…

Patch available
Fix from $1,950 2008-12-17
Rsyslog MEDIUM 5.0
CVE-2008-5618

imudp in rsyslog 4.x before 4.1.2, 3.21 before 3.21.9 beta, and 3.20 before 3.20.2 generates a message even when it is sent by an unauthorized sender…

Mitigation only
Fix from $1,600 2008-12-17
Rsyslogd HIGH 7.5
CVE-2005-3074

SQL injection vulnerability in rsyslogd in RSyslog before 1.0.1 and before 1.10.1 allows remote attackers to execute arbitrary SQL commands via craft…

Fix: after 1.10.1_development
Fix from $1,950 2005-09-27