Zeromq

Libzmq

7 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.54%
  • Veröffentlicht 01.07.2021 03:15:07
  • Zuletzt bearbeitet 21.11.2024 05:29:24

ZeroMQ libzmq 4.3.3 has a heap-based buffer overflow in zmq::tcp_read, a different vulnerability than CVE-2021-20235.

  • EPSS 1.33%
  • Veröffentlicht 28.05.2021 11:15:07
  • Zuletzt bearbeitet 21.11.2024 05:46:11

An uncontrolled resource consumption (memory leak) flaw was found in ZeroMQ's src/xpub.cpp in versions before 4.3.3. This flaw allows a remote unauthenticated attacker to send crafted PUB messages that consume excessive memory if the CURVE/ZAP authen...

Exploit
  • EPSS 0.43%
  • Veröffentlicht 01.04.2021 14:15:13
  • Zuletzt bearbeitet 21.11.2024 05:46:11

An uncontrolled resource consumption (memory leak) flaw was found in the ZeroMQ client in versions before 4.3.3 in src/pipe.cpp. This issue causes a client that connects to multiple malicious or compromised servers to crash. The highest threat from t...

  • EPSS 3.09%
  • Veröffentlicht 01.04.2021 14:15:13
  • Zuletzt bearbeitet 21.11.2024 05:46:11

There's a flaw in the zeromq server in versions before 4.3.3 in src/decoder_allocators.hpp. The decoder static allocator could have its sized changed, but the buffer would remain the same as it is a static buffer. A remote, unauthenticated attacker w...

  • EPSS 0.3%
  • Veröffentlicht 11.09.2020 16:15:12
  • Zuletzt bearbeitet 21.11.2024 05:04:59

In ZeroMQ before version 4.3.3, there is a denial-of-service vulnerability. Users with TCP transport public endpoints, even with CURVE/ZAP enabled, are impacted. If a raw TCP socket is opened and connected to an endpoint that is fully configured with...

  • EPSS 23.22%
  • Veröffentlicht 10.07.2019 19:15:10
  • Zuletzt bearbeitet 21.11.2024 04:24:15

In ZeroMQ libzmq before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.3.2, a remote, unauthenticated client connecting to a libzmq application, running with a socket listening with CURVE encryption/authentication enabled, may cause a stack overflow a...

Exploit
  • EPSS 35.04%
  • Veröffentlicht 13.01.2019 15:29:00
  • Zuletzt bearbeitet 21.11.2024 04:46:18

A pointer overflow, with code execution, was discovered in ZeroMQ libzmq (aka 0MQ) 4.2.x and 4.3.x before 4.3.1. A v2_decoder.cpp zmq::v2_decoder_t::size_ready integer overflow allows an authenticated attacker to overwrite an arbitrary amount of byte...