CVE-2026-93302
- EPSS 0.36%
- Veröffentlicht 27.09.2026 09:07:35
- Zuletzt bearbeitet 02.10.2026 18:57:08
MatchTrustedPeer ignores the public key used, leading to forged CA clones passing verification. Affected builds are any that enable the macro WOLFSSL_TRUST_PEER_CERT and load CA certificates with wolfSSL_CTX_trust_peer_cert() or wolfSSL_trust_peer_ce...
CVE-2026-61548
- EPSS 0.59%
- Veröffentlicht 18.09.2026 16:54:28
- Zuletzt bearbeitet 24.09.2026 21:22:19
Rsyslog is a rocket-fast system for log processing. From 7.5.4 until 8.2606.0, the optional mmpstrucdata plugin's parseSD_PARAM function in plugins/mmpstrucdata/mmpstrucdata.c stores RFC5424 parameter values in a fixed pVal[32 * 1024] stack buffer an...
CVE-2026-55556
- EPSS 0.66%
- Veröffentlicht 18.09.2026 16:53:29
- Zuletzt bearbeitet 24.09.2026 21:22:19
Rsyslog is a rocket-fast system for log processing. From 8.2110.0 until 8.2604.0, the optional imhttp module's parse_auth_header function in contrib/imhttp/imhttp.c allocates a zero-byte heap buffer with calloc(0, len) when an HTTP Basic Authorizatio...
CVE-2026-19654
- EPSS 0.4%
- Veröffentlicht 12.08.2026 20:46:31
- Zuletzt bearbeitet 24.09.2026 17:17:04
A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame recovery can cause an invalid internal message length and terminate rsyslogd. No confidentiality or i...
CVE-2022-24903
- EPSS 3.93%
- Veröffentlicht 06.05.2022 00:15:07
- Zuletzt bearbeitet 21.11.2024 06:51:21
Rsyslog is a rocket-fast system for log processing. Modules for TCP syslog reception have a potential heap buffer overflow when octet-counted framing is used. This can result in a segfault or some other malfunction. As of our understanding, this vuln...
CVE-2011-1490
- EPSS 0.38%
- Veröffentlicht 14.11.2019 02:15:10
- Zuletzt bearbeitet 21.11.2024 01:26:25
A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages are logged when multiple rulesets were used and some output batches contained messages belonging to more than one ruleset. A local attacker could cause denial of...
CVE-2011-1489
- EPSS 0.47%
- Veröffentlicht 14.11.2019 02:15:10
- Zuletzt bearbeitet 21.11.2024 01:26:25
A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages were logged when multiple rulesets were used and some output batches contained messages belonging to more than one ruleset. A local attacker could cause denial o...
CVE-2011-1488
- EPSS 0.48%
- Veröffentlicht 14.11.2019 02:15:10
- Zuletzt bearbeitet 21.11.2024 01:26:25
A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages are logged when $RepeatedMsgReduction was enabled. A local attacker could use this flaw to cause a denial of the rsyslogd daemon service by crashing the service ...
CVE-2019-17042
- EPSS 3.07%
- Veröffentlicht 07.10.2019 16:15:11
- Zuletzt bearbeitet 21.11.2024 04:31:35
An issue was discovered in Rsyslog v8.1908.0. contrib/pmcisconames/pmcisconames.c has a heap overflow in the parser for Cisco log messages. The parser tries to locate a log message delimiter (in this case, a space or a colon), but fails to account fo...
CVE-2019-17041
- EPSS 4.57%
- Veröffentlicht 07.10.2019 16:15:11
- Zuletzt bearbeitet 21.11.2024 04:31:34
An issue was discovered in Rsyslog v8.1908.0. contrib/pmaixforwardedfrom/pmaixforwardedfrom.c has a heap overflow in the parser for AIX log messages. The parser tries to locate a log message delimiter (in this case, a space or a colon) but fails to a...