Show filters
30 Total Results
Displaying 21-30 of 30
Sort by:
Attacker Value
Unknown

CVE-2013-7290

Disclosure Date: January 13, 2014 (last updated October 05, 2023)
The do_item_get function in items.c in memcached 1.4.4 and other versions before 1.4.17, when running in verbose mode, allows remote attackers to cause a denial of service (segmentation fault) via a request to delete a key, which does not account for the lack of a null terminator in the key and triggers a buffer over-read when printing to stderr, a different vulnerability than CVE-2013-0179.
0
Attacker Value
Unknown

CVE-2013-0179

Disclosure Date: January 13, 2014 (last updated October 05, 2023)
The process_bin_delete function in memcached.c in memcached 1.4.4 and other versions before 1.4.17, when running in verbose mode, allows remote attackers to cause a denial of service (segmentation fault) via a request to delete a key, which does not account for the lack of a null terminator in the key and triggers a buffer over-read when printing to stderr.
0
Attacker Value
Unknown

CVE-2013-7291

Disclosure Date: January 13, 2014 (last updated October 05, 2023)
memcached before 1.4.17, when running in verbose mode, allows remote attackers to cause a denial of service (crash) via a request that triggers an "unbounded key print" during logging, related to an issue that was "quickly grepped out of the source tree," a different vulnerability than CVE-2013-0179 and CVE-2013-7290.
0
Attacker Value
Unknown

CVE-2011-4971

Disclosure Date: December 12, 2013 (last updated October 05, 2023)
Multiple integer signedness errors in the (1) process_bin_sasl_auth, (2) process_bin_complete_sasl_auth, (3) process_bin_update, and (4) process_bin_append_prepend functions in Memcached 1.4.5 and earlier allow remote attackers to cause a denial of service (crash) via a large body length value in a packet.
0
Attacker Value
Unknown

CVE-2010-5275

Disclosure Date: October 07, 2012 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in memcache_admin in the Memcache module 5.x before 5.x-1.10 and 6.x before 6.x-1.6 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2010-5276

Disclosure Date: October 07, 2012 (last updated October 05, 2023)
The Memcache module 5.x before 5.x-1.10 and 6.x before 6.x-1.6 for Drupal does not properly handle the $user object in memcache_admin, which might "lead to a role change not being recognized until the user logs in again."
0
Attacker Value
Unknown

CVE-2010-1152

Disclosure Date: April 12, 2010 (last updated November 08, 2023)
memcached.c in memcached before 1.4.3 allows remote attackers to cause a denial of service (daemon hang or crash) via a long line that triggers excessive memory allocation. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2009-2415

Disclosure Date: August 10, 2009 (last updated October 04, 2023)
Multiple integer overflows in memcached 1.1.12 and 1.2.2 allow remote attackers to execute arbitrary code via vectors involving length attributes that trigger heap-based buffer overflows.
0
Attacker Value
Unknown

CVE-2009-1255

Disclosure Date: April 30, 2009 (last updated October 04, 2023)
The process_stat function in (1) Memcached before 1.2.8 and (2) MemcacheDB 1.2.0 discloses (a) the contents of /proc/self/maps in response to a stats maps command and (b) memory-allocation statistics in response to a stats malloc command, which allows remote attackers to obtain sensitive information such as the locations of memory regions, and defeat ASLR protection, by sending a command to the daemon's TCP port.
0
Attacker Value
Unknown

CVE-2009-1494

Disclosure Date: April 30, 2009 (last updated October 04, 2023)
The process_stat function in Memcached 1.2.8 discloses memory-allocation statistics in response to a stats malloc command, which allows remote attackers to obtain potentially sensitive information by sending this command to the daemon's TCP port.
0