- EPSS 1.89%
- Published 02.11.2014 00:55:05
- Last modified 12.04.2025 10:46:40
Integer overflow in rsyslog before 7.6.7 and 8.x before 8.4.2 and sysklogd 1.5 and earlier allows remote attackers to cause a denial of service (crash) via a large priority (PRI) value. NOTE: this vulnerability exists because of an incomplete fix fo...
CVE-2014-3634
- EPSS 29.38%
- Published 02.11.2014 00:55:05
- Last modified 12.04.2025 10:46:40
rsyslog before 7.6.6 and 8.x before 8.4.1 and sysklogd 1.5 and earlier allows remote attackers to cause a denial of service (crash), possibly execute arbitrary code, or have other unspecified impact via a crafted priority (PRI) value that triggers an...
CVE-2013-4758
- EPSS 1.22%
- Published 04.10.2013 17:55:09
- Last modified 11.04.2025 00:51:21
Double free vulnerability in the writeDataError function in the ElasticSearch plugin (omelasticsearch) in rsyslog before 7.4.2 and before 7.5.2 devel, when errorfile is set to local logging, allows remote attackers to cause a denial of service (crash...
CVE-2011-4623
- EPSS 0.09%
- Published 25.09.2012 23:55:01
- Last modified 11.04.2025 00:51:21
Integer overflow in the rsCStrExtendBuf function in runtime/stringbuf.c in the imfile module in rsyslog 4.x before 4.6.6, 5.x before 5.7.4, and 6.x before 6.1.4 allows local users to cause a denial of service (daemon hang) via a large file, which tri...
- EPSS 64.78%
- Published 06.09.2011 16:55:10
- Last modified 11.04.2025 00:51:21
Stack-based buffer overflow in the parseLegacySyslogMsg function in tools/syslogd.c in rsyslogd in rsyslog 4.6.x before 4.6.8 and 5.2.0 through 5.8.4 might allow remote attackers to cause a denial of service (application exit) via a long TAG in a leg...
CVE-2008-5617
- EPSS 0.39%
- Published 17.12.2008 02:30:00
- Last modified 09.04.2025 00:30:58
The ACL handling in rsyslog 3.12.1 to 3.20.0, 4.1.0, and 4.1.1 does not follow $AllowedSender directive, which allows remote attackers to bypass intended access restrictions and spoof log messages or create a large number of spurious messages.
- EPSS 0.47%
- Published 17.12.2008 02:30:00
- Last modified 09.04.2025 00:30:58
imudp in rsyslog 4.x before 4.1.2, 3.21 before 3.21.9 beta, and 3.20 before 3.20.2 generates a message even when it is sent by an unauthorized sender, which allows remote attackers to cause a denial of service (disk consumption) via a large number of...