Skip to main content

Vendor archive

rsyslog CVEs

Beta · best-effort

19 CVEs tagged to vendor rsyslog5 Critical, 5 High, 8 Medium, 1 Low, 0 Unrated.

CVE-2019-17040

Published Sep 30, 2019

contrib/pmdb2diag/pmdb2diag.c in Rsyslog v8.1908.0 allows out-of-bounds access because the level length is mishandled.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-1000140

Published Mar 23, 2018

rsyslog librelp version 1.2.14 and earlier contains a Buffer Overflow vulnerability in the checking of x509 certificates from a peer that can result in Remote code execution. This…

CVSS 9.8 · Critical

CVE-2017-12588

Published Aug 6, 2017

The zmq3 input and output modules in rsyslog before 8.28.0 interpreted description fields as format strings, possibly allowing a format string attack with unspecified impact.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-3243

Published Jul 25, 2017

rsyslog uses weak permissions for generating log files, which allows local users to obtain sensitive information by reading files in /var/log/cron.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3683

Published Nov 2, 2014

Integer overflow in rsyslog before 7.6.7 and 8.x before 8.4.2 and sysklogd 1.5 and earlier allows remote attackers to cause a denial of service (crash) via a large priority (PRI)…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3634

Published Nov 2, 2014

rsyslog before 7.6.6 and 8.x before 8.4.1 and sysklogd 1.5 and earlier allows remote attackers to cause a denial of service (crash), possibly execute arbitrary code, or have other…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2013-4758

Published Oct 4, 2013

Double free vulnerability in the writeDataError function in the ElasticSearch plugin (omelasticsearch) in rsyslog before 7.4.2 and before 7.5.2 devel, when errorfile is set to loc…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4623

Published Sep 25, 2012

Integer overflow in the rsCStrExtendBuf function in runtime/stringbuf.c in the imfile module in rsyslog 4.x before 4.6.6, 5.x before 5.7.4, and 6.x before 6.1.4 allows local users…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2011-3200

Published Sep 6, 2011

Stack-based buffer overflow in the parseLegacySyslogMsg function in tools/syslogd.c in rsyslogd in rsyslog 4.6.x before 4.6.8 and 5.2.0 through 5.8.4 might allow remote attackers…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5618

Published Dec 17, 2008

imudp in rsyslog 4.x before 4.1.2, 3.21 before 3.21.9 beta, and 3.20 before 3.20.2 generates a message even when it is sent by an unauthorized sender, which allows remote attacker…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5617

Published Dec 17, 2008

The ACL handling in rsyslog 3.12.1 to 3.20.0, 4.1.0, and 4.1.1 does not follow $AllowedSender directive, which allows remote attackers to bypass intended access restrictions and s…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-3074

Published Sep 27, 2005

SQL injection vulnerability in rsyslogd in RSyslog before 1.0.1 and before 1.10.1 allows remote attackers to execute arbitrary SQL commands via crafted syslog messages.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-19 of 19 CVEsPage 1 of 1