CVE-2023-46853
- EPSS 0.15%
- Published 27.10.2023 20:15:09
- Last modified 21.11.2024 08:29:25
In Memcached before 1.6.22, an off-by-one error exists when processing proxy requests in proxy mode, if \n is used instead of \r\n.
CVE-2023-46852
- EPSS 0.13%
- Published 27.10.2023 20:15:09
- Last modified 21.11.2024 08:29:25
In Memcached before 1.6.22, a buffer overflow exists when processing multiget requests in proxy mode, if there are many spaces after the "get" substring.
CVE-2022-48571
- EPSS 0.06%
- Published 22.08.2023 19:16:32
- Last modified 21.11.2024 07:33:31
memcached 1.6.7 allows a Denial of Service via multi-packet uploads in UDP.
CVE-2020-22570
- EPSS 2.07%
- Published 22.08.2023 19:16:19
- Last modified 21.11.2024 05:13:18
Memcached 1.6.0 before 1.6.3 allows remote attackers to cause a denial of service (daemon crash) via a crafted meta command.
CVE-2021-37519
- EPSS 0.02%
- Published 03.02.2023 18:15:14
- Last modified 26.03.2025 19:15:17
Buffer Overflow vulnerability in authfile.c memcached 1.6.9 allows attackers to cause a denial of service via crafted authenticattion file.
CVE-2020-10931
- EPSS 17.29%
- Published 24.03.2020 15:15:12
- Last modified 21.11.2024 04:56:23
Memcached 1.6.x before 1.6.2 allows remote attackers to cause a denial of service (daemon crash) via a crafted binary protocol header to try_read_command_binary in memcached.c.
CVE-2019-15026
- EPSS 0.93%
- Published 30.08.2019 15:15:10
- Last modified 21.11.2024 04:27:53
memcached 1.5.16, when UNIX sockets are used, has a stack-based buffer over-read in conn_to_str in memcached.c.
CVE-2019-11596
- EPSS 1.64%
- Published 29.04.2019 15:29:00
- Last modified 21.11.2024 04:21:24
In memcached before 1.5.14, a NULL pointer dereference was found in the "lru mode" and "lru temp_ttl" commands. This causes a denial of service when parsing crafted lru command messages in process_lru_command in memcached.c.
CVE-2018-1000127
- EPSS 1%
- Published 13.03.2018 21:29:00
- Last modified 21.11.2024 03:39:44
memcached version prior to 1.4.37 contains an Integer Overflow vulnerability in items.c:item_free() that can result in data corruption and deadlocks due to items existing in hash table being reused from free list. This attack appear to be exploitable...
CVE-2018-1000115
- EPSS 79.85%
- Published 05.03.2018 14:29:00
- Last modified 21.11.2024 03:39:40
Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amplification, CWE-406) vulnerability in the UDP support of the memcached server that can result in denial of service via network flood (traffic amplification...