- EPSS 2.87%
- Veröffentlicht 02.11.2014 00:55:05
- Zuletzt bearbeitet 06.05.2026 22:30:45
Integer overflow in rsyslog before 7.6.7 and 8.x before 8.4.2 and sysklogd 1.5 and earlier allows remote attackers to cause a denial of service (crash) via a large priority (PRI) value. NOTE: this vulnerability exists because of an incomplete fix fo...
CVE-2014-3634
- EPSS 29.38%
- Veröffentlicht 02.11.2014 00:55:05
- Zuletzt bearbeitet 06.05.2026 22:30:45
rsyslog before 7.6.6 and 8.x before 8.4.1 and sysklogd 1.5 and earlier allows remote attackers to cause a denial of service (crash), possibly execute arbitrary code, or have other unspecified impact via a crafted priority (PRI) value that triggers an...
CVE-2013-4758
- EPSS 1.22%
- Veröffentlicht 04.10.2013 17:55:09
- Zuletzt bearbeitet 29.04.2026 01:13:23
Double free vulnerability in the writeDataError function in the ElasticSearch plugin (omelasticsearch) in rsyslog before 7.4.2 and before 7.5.2 devel, when errorfile is set to local logging, allows remote attackers to cause a denial of service (crash...
CVE-2011-4623
- EPSS 0.09%
- Veröffentlicht 25.09.2012 23:55:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
Integer overflow in the rsCStrExtendBuf function in runtime/stringbuf.c in the imfile module in rsyslog 4.x before 4.6.6, 5.x before 5.7.4, and 6.x before 6.1.4 allows local users to cause a denial of service (daemon hang) via a large file, which tri...
- EPSS 63.91%
- Veröffentlicht 06.09.2011 16:55:10
- Zuletzt bearbeitet 29.04.2026 01:13:23
Stack-based buffer overflow in the parseLegacySyslogMsg function in tools/syslogd.c in rsyslogd in rsyslog 4.6.x before 4.6.8 and 5.2.0 through 5.8.4 might allow remote attackers to cause a denial of service (application exit) via a long TAG in a leg...
CVE-2008-5617
- EPSS 0.39%
- Veröffentlicht 17.12.2008 02:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
The ACL handling in rsyslog 3.12.1 to 3.20.0, 4.1.0, and 4.1.1 does not follow $AllowedSender directive, which allows remote attackers to bypass intended access restrictions and spoof log messages or create a large number of spurious messages.
- EPSS 0.47%
- Veröffentlicht 17.12.2008 02:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
imudp in rsyslog 4.x before 4.1.2, 3.21 before 3.21.9 beta, and 3.20 before 3.20.2 generates a message even when it is sent by an unauthorized sender, which allows remote attackers to cause a denial of service (disk consumption) via a large number of...