VYPR

Rsyslog

by Rsyslog

Source repositories

CVEs (23)

  • CVE-2008-5618Dec 17, 2008
    risk 0.00cvss —epss 0.01

    imudp in rsyslog 4.x before 4.1.2, 3.21 before 3.21.9 beta, and 3.20 before 3.20.2 generates a message even when it is sent by an unauthorized sender, which allows remote attackers to cause a denial of service (disk consumption) via a large number of spurious messages.

  • CVE-2008-5617Dec 17, 2008
    risk 0.00cvss —epss 0.02

    The ACL handling in rsyslog 3.12.1 to 3.20.0, 4.1.0, and 4.1.1 does not follow $AllowedSender directive, which allows remote attackers to bypass intended access restrictions and spoof log messages or create a large number of spurious messages.

  • CVE-2005-3074Sep 27, 2005
    risk 0.00cvss —epss 0.01

    SQL injection vulnerability in rsyslogd in RSyslog before 1.0.1 and before 1.10.1 allows remote attackers to execute arbitrary SQL commands via crafted syslog messages.

Page 2 of 2