Vulnerabilities
Vulnerable Software
Memcached:  >> Memcached  >> 1.4.38  Security Vulnerabilities
In Memcached before 1.6.22, a buffer overflow exists when processing multiget requests in proxy mode, if there are many spaces after the "get" substring.
CVSS Score
7.5
EPSS Score
0.001
Published
2023-10-27
In Memcached before 1.6.22, an off-by-one error exists when processing proxy requests in proxy mode, if \n is used instead of \r\n.
CVSS Score
9.8
EPSS Score
0.001
Published
2023-10-27
In memcached before 1.5.14, a NULL pointer dereference was found in the "lru mode" and "lru temp_ttl" commands. This causes a denial of service when parsing crafted lru command messages in process_lru_command in memcached.c.
CVSS Score
7.5
EPSS Score
0.016
Published
2019-04-29
The try_read_command function in memcached.c in memcached before 1.4.39 allows remote attackers to cause a denial of service (segmentation fault) via a request to add/set a key, which makes a comparison between signed and unsigned int and triggers a heap-based buffer over-read. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-8705.
CVSS Score
7.5
EPSS Score
0.034
Published
2017-07-17


Contact Us

Shodan ® - All rights reserved