CVE-2019-17040
- EPSS 2.42%
- Veröffentlicht 30.09.2019 14:15:14
- Zuletzt bearbeitet 21.11.2024 04:31:34
contrib/pmdb2diag/pmdb2diag.c in Rsyslog v8.1908.0 allows out-of-bounds access because the level length is mishandled.
CVE-2018-16881
- EPSS 2.24%
- Veröffentlicht 25.01.2019 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:53:31
A denial of service vulnerability was found in rsyslog in the imptcp module. An attacker could send a specially crafted message to the imptcp socket, which would cause rsyslog to crash. Versions before 8.27.0 are vulnerable.
CVE-2017-12588
- EPSS 2.83%
- Veröffentlicht 06.08.2017 14:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The zmq3 input and output modules in rsyslog before 8.28.0 interpreted description fields as format strings, possibly allowing a format string attack with unspecified impact.
CVE-2015-3243
- EPSS 0.45%
- Veröffentlicht 25.07.2017 18:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
rsyslog uses weak permissions for generating log files, which allows local users to obtain sensitive information by reading files in /var/log/cron.
- EPSS 4.59%
- Veröffentlicht 02.11.2014 00:55:05
- Zuletzt bearbeitet 06.05.2026 22:30:45
Integer overflow in rsyslog before 7.6.7 and 8.x before 8.4.2 and sysklogd 1.5 and earlier allows remote attackers to cause a denial of service (crash) via a large priority (PRI) value. NOTE: this vulnerability exists because of an incomplete fix fo...
CVE-2014-3634
- EPSS 7.55%
- Veröffentlicht 02.11.2014 00:55:05
- Zuletzt bearbeitet 06.05.2026 22:30:45
rsyslog before 7.6.6 and 8.x before 8.4.1 and sysklogd 1.5 and earlier allows remote attackers to cause a denial of service (crash), possibly execute arbitrary code, or have other unspecified impact via a crafted priority (PRI) value that triggers an...
CVE-2013-4758
- EPSS 2.33%
- Veröffentlicht 04.10.2013 17:55:09
- Zuletzt bearbeitet 29.04.2026 01:13:23
Double free vulnerability in the writeDataError function in the ElasticSearch plugin (omelasticsearch) in rsyslog before 7.4.2 and before 7.5.2 devel, when errorfile is set to local logging, allows remote attackers to cause a denial of service (crash...
CVE-2011-4623
- EPSS 0.42%
- Veröffentlicht 25.09.2012 23:55:01
- Zuletzt bearbeitet 16.06.2026 23:35:09
Integer overflow in the rsCStrExtendBuf function in runtime/stringbuf.c in the imfile module in rsyslog 4.x before 4.6.6, 5.x before 5.7.4, and 6.x before 6.1.4 allows local users to cause a denial of service (daemon hang) via a large file, which tri...
- EPSS 20.76%
- Veröffentlicht 06.09.2011 16:55:10
- Zuletzt bearbeitet 16.06.2026 23:32:51
Stack-based buffer overflow in the parseLegacySyslogMsg function in tools/syslogd.c in rsyslogd in rsyslog 4.6.x before 4.6.8 and 5.2.0 through 5.8.4 might allow remote attackers to cause a denial of service (application exit) via a long TAG in a leg...
CVE-2008-5617
- EPSS 2.19%
- Veröffentlicht 17.12.2008 02:30:00
- Zuletzt bearbeitet 16.06.2026 23:00:40
The ACL handling in rsyslog 3.12.1 to 3.20.0, 4.1.0, and 4.1.1 does not follow $AllowedSender directive, which allows remote attackers to bypass intended access restrictions and spoof log messages or create a large number of spurious messages.