- EPSS 1.89%
- Veröffentlicht 02.11.2014 00:55:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
Integer overflow in rsyslog before 7.6.7 and 8.x before 8.4.2 and sysklogd 1.5 and earlier allows remote attackers to cause a denial of service (crash) via a large priority (PRI) value. NOTE: this vulnerability exists because of an incomplete fix fo...
CVE-2014-3634
- EPSS 29.38%
- Veröffentlicht 02.11.2014 00:55:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
rsyslog before 7.6.6 and 8.x before 8.4.1 and sysklogd 1.5 and earlier allows remote attackers to cause a denial of service (crash), possibly execute arbitrary code, or have other unspecified impact via a crafted priority (PRI) value that triggers an...
CVE-2013-4758
- EPSS 1.22%
- Veröffentlicht 04.10.2013 17:55:09
- Zuletzt bearbeitet 11.04.2025 00:51:21
Double free vulnerability in the writeDataError function in the ElasticSearch plugin (omelasticsearch) in rsyslog before 7.4.2 and before 7.5.2 devel, when errorfile is set to local logging, allows remote attackers to cause a denial of service (crash...
CVE-2011-4623
- EPSS 0.09%
- Veröffentlicht 25.09.2012 23:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Integer overflow in the rsCStrExtendBuf function in runtime/stringbuf.c in the imfile module in rsyslog 4.x before 4.6.6, 5.x before 5.7.4, and 6.x before 6.1.4 allows local users to cause a denial of service (daemon hang) via a large file, which tri...
- EPSS 64.78%
- Veröffentlicht 06.09.2011 16:55:10
- Zuletzt bearbeitet 11.04.2025 00:51:21
Stack-based buffer overflow in the parseLegacySyslogMsg function in tools/syslogd.c in rsyslogd in rsyslog 4.6.x before 4.6.8 and 5.2.0 through 5.8.4 might allow remote attackers to cause a denial of service (application exit) via a long TAG in a leg...
CVE-2008-5617
- EPSS 0.39%
- Veröffentlicht 17.12.2008 02:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The ACL handling in rsyslog 3.12.1 to 3.20.0, 4.1.0, and 4.1.1 does not follow $AllowedSender directive, which allows remote attackers to bypass intended access restrictions and spoof log messages or create a large number of spurious messages.
- EPSS 0.47%
- Veröffentlicht 17.12.2008 02:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
imudp in rsyslog 4.x before 4.1.2, 3.21 before 3.21.9 beta, and 3.20 before 3.20.2 generates a message even when it is sent by an unauthorized sender, which allows remote attackers to cause a denial of service (disk consumption) via a large number of...