CVE-2026-90698
- EPSS 0.5%
- Veröffentlicht 14.09.2026 08:30:12
- Zuletzt bearbeitet 15.09.2026 16:17:40
A security flaw has been discovered in memcached 1.6.41/1.6.42/1.6.43. This vulnerability affects the function try_read_command_asciiauth of the file proto_text.c of the component mcmc Tokenizer. The manipulation results in out-of-bounds read. It is ...
CVE-2026-47784
- EPSS 0.55%
- Veröffentlicht 20.05.2026 05:45:37
- Zuletzt bearbeitet 24.07.2026 10:10:00
In memcached before 1.6.42, password data for SASL password database authentication has a timing side channel because memcmp is used by sasl_server_userdb_checkpass.
CVE-2026-47783
- EPSS 1.26%
- Veröffentlicht 20.05.2026 05:43:46
- Zuletzt bearbeitet 18.09.2026 13:18:29
In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon as a valid username is found by sasl_server_userdb_checkpass.
CVE-2023-46853
- EPSS 0.76%
- Veröffentlicht 27.10.2023 20:15:09
- Zuletzt bearbeitet 21.11.2024 08:29:25
In Memcached before 1.6.22, an off-by-one error exists when processing proxy requests in proxy mode, if \n is used instead of \r\n.
CVE-2023-46852
- EPSS 0.78%
- Veröffentlicht 27.10.2023 20:15:09
- Zuletzt bearbeitet 21.11.2024 08:29:25
In Memcached before 1.6.22, a buffer overflow exists when processing multiget requests in proxy mode, if there are many spaces after the "get" substring.
CVE-2022-48571
- EPSS 0.91%
- Veröffentlicht 22.08.2023 19:16:32
- Zuletzt bearbeitet 21.11.2024 07:33:31
memcached 1.6.7 allows a Denial of Service via multi-packet uploads in UDP.
CVE-2020-22570
- EPSS 0.98%
- Veröffentlicht 22.08.2023 19:16:19
- Zuletzt bearbeitet 21.11.2024 05:13:18
Memcached 1.6.0 before 1.6.3 allows remote attackers to cause a denial of service (daemon crash) via a crafted meta command.
CVE-2021-37519
- EPSS 0.36%
- Veröffentlicht 03.02.2023 18:15:14
- Zuletzt bearbeitet 26.03.2025 19:15:17
Buffer Overflow vulnerability in authfile.c memcached 1.6.9 allows attackers to cause a denial of service via crafted authenticattion file.
CVE-2020-10931
- EPSS 28.14%
- Veröffentlicht 24.03.2020 15:15:12
- Zuletzt bearbeitet 21.11.2024 04:56:23
Memcached 1.6.x before 1.6.2 allows remote attackers to cause a denial of service (daemon crash) via a crafted binary protocol header to try_read_command_binary in memcached.c.
CVE-2019-15026
- EPSS 2.64%
- Veröffentlicht 30.08.2019 15:15:10
- Zuletzt bearbeitet 21.11.2024 04:27:53
memcached 1.5.16, when UNIX sockets are used, has a stack-based buffer over-read in conn_to_str in memcached.c.