Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown
CVE-2010-1152
Disclosure Date: April 12, 2010 (last updated November 08, 2023)
memcached.c in memcached before 1.4.3 allows remote attackers to cause a denial of service (daemon hang or crash) via a long line that triggers excessive memory allocation. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2009-2415
Disclosure Date: August 10, 2009 (last updated October 04, 2023)
Multiple integer overflows in memcached 1.1.12 and 1.2.2 allow remote attackers to execute arbitrary code via vectors involving length attributes that trigger heap-based buffer overflows.
0
Attacker Value
Unknown
CVE-2009-1255
Disclosure Date: April 30, 2009 (last updated October 04, 2023)
The process_stat function in (1) Memcached before 1.2.8 and (2) MemcacheDB 1.2.0 discloses (a) the contents of /proc/self/maps in response to a stats maps command and (b) memory-allocation statistics in response to a stats malloc command, which allows remote attackers to obtain sensitive information such as the locations of memory regions, and defeat ASLR protection, by sending a command to the daemon's TCP port.
0
Attacker Value
Unknown
CVE-2009-1494
Disclosure Date: April 30, 2009 (last updated October 04, 2023)
The process_stat function in Memcached 1.2.8 discloses memory-allocation statistics in response to a stats malloc command, which allows remote attackers to obtain potentially sensitive information by sending this command to the daemon's TCP port.
0