CVE-2017-18240
- EPSS 0.04%
- Veröffentlicht 19.03.2018 02:29:00
- Zuletzt bearbeitet 21.11.2024 03:19:39
The Gentoo app-admin/collectd package before 5.7.2-r1 sets the ownership of PID file directory to the collectd account, which might allow local users to kill arbitrary processes by leveraging access to this account for PID file modification before a ...
- EPSS 3.34%
- Veröffentlicht 14.11.2017 21:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The csnmp_read_table function in snmp.c in the SNMP plugin in collectd before 5.6.3 is susceptible to a double free in a certain error case, which could lead to a crash (or potentially have other impact).
CVE-2017-7401
- EPSS 0.98%
- Veröffentlicht 03.04.2017 14:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Incorrect interaction of the parse_packet() and parse_part_sign_sha256() functions in network.c in collectd 5.7.1 and earlier allows remote attackers to cause a denial of service (infinite loop) of a collectd instance (configured with "SecurityLevel ...
CVE-2016-6254
- EPSS 13.07%
- Veröffentlicht 19.08.2016 21:59:13
- Zuletzt bearbeitet 12.04.2025 10:46:40
Heap-based buffer overflow in the parse_packet function in network.c in collectd before 5.4.3 and 5.x before 5.5.2 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted network packet.
- EPSS 1.66%
- Veröffentlicht 17.12.2010 19:00:22
- Zuletzt bearbeitet 11.04.2025 00:51:21
The cu_rrd_create_file function (src/utils_rrdcreate.c) in collectd 4.x before 4.9.4 and before 4.10.2 allow remote attackers to cause a denial of service (assertion failure) via a packet with a timestamp whose value is 10 or less, as demonstrated by...