<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Memcached (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/memcached.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/memcached-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Memcached (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:33 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-45686 – OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the Op...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45686</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45686</guid>
    <pubDate>Tue, 02 Jun 2026 16:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45686</strong></p>
  <p>OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.7.0 to before version 0.9.0, a remotely reachable integer overflow in OBI's memcached text protocol parser can crash the OBI process and cause denial of service. When parsing memcached storage commands such as set, add, replace, append, prepend, or cas, OBI accepts extremely large…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45686">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-47784 – In memcached before 1.6.42, password data for SASL password database authenticat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-47784</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-47784</guid>
    <pubDate>Wed, 20 May 2026 07:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-47784</strong></p>
  <p>In memcached before 1.6.42, password data for SASL password database authentication has a timing side channel because memcmp is used by sasl_server_userdb_checkpass.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-208</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-47784">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-47783 – In memcached before 1.6.42, username data for SASL password database authenticat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-47783</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-47783</guid>
    <pubDate>Wed, 20 May 2026 07:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-47783</strong></p>
  <p>In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon as a valid username is found by sasl_server_userdb_checkpass.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-208</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-47783">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-29093 – WWBN AVideo is an open source video platform. Prior to version 24.0, the officia...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-29093</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-29093</guid>
    <pubDate>Fri, 06 Mar 2026 04:16:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-29093</strong></p>
  <p>WWBN AVideo is an open source video platform. Prior to version 24.0, the official docker-compose.yml publishes the memcached service on host port 11211 (0.0.0.0:11211) with no authentication, while the Dockerfile configures PHP to store all user sessions in that memcached instance. An attacker who can reach port 11211 can read, modify, or flush session data — enabling session hijacking, admin imp…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-29093">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-43768 – An issue was discovered in Couchbase Server 6.6.x through 7.2.0, before 7.1.5 an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-43768</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-43768</guid>
    <pubDate>Wed, 27 Mar 2024 07:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-43768</strong></p>
  <p>An issue was discovered in Couchbase Server 6.6.x through 7.2.0, before 7.1.5 and 7.2.1. Unauthenticated users may cause memcached to run out of memory via large commands.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-43768">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-46853 – In Memcached before 1.6.22, an off-by-one error exists when processing proxy req...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-46853</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-46853</guid>
    <pubDate>Fri, 27 Oct 2023 20:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-46853</strong></p>
  <p>In Memcached before 1.6.22, an off-by-one error exists when processing proxy requests in proxy mode, if \n is used instead of \r\n.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-193</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-46853">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-46852 – In Memcached before 1.6.22, a buffer overflow exists when processing multiget re...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-46852</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-46852</guid>
    <pubDate>Fri, 27 Oct 2023 20:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-46852</strong></p>
  <p>In Memcached before 1.6.22, a buffer overflow exists when processing multiget requests in proxy mode, if there are many spaces after the "get" substring.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-46852">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-48571 – memcached 1.6.7 allows a Denial of Service via multi-packet uploads in UDP.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-48571</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-48571</guid>
    <pubDate>Tue, 22 Aug 2023 19:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-48571</strong></p>
  <p>memcached 1.6.7 allows a Denial of Service via multi-packet uploads in UDP.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-48571">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-22570 – Memcached 1.6.0 before 1.6.3 allows remote attackers to cause a denial of servic...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-22570</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-22570</guid>
    <pubDate>Tue, 22 Aug 2023 19:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-22570</strong></p>
  <p>Memcached 1.6.0 before 1.6.3 allows remote attackers to cause a denial of service (daemon crash) via a crafted meta command.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-22570">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-26635 – PHP-Memcached v2.2.0 and below contains an improper NULL termination which allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-26635</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-26635</guid>
    <pubDate>Tue, 05 Apr 2022 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-26635</strong></p>
  <p>PHP-Memcached v2.2.0 and below contains an improper NULL termination which allows attackers to execute CLRF injection. Note: Third parties have disputed this as not affecting PHP-Memcached directly.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-26635">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-35945 – Couchbase Server 6.5.x, 6.6.0 through 6.6.2, and 7.0.0, has a Buffer Overflow. A...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-35945</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-35945</guid>
    <pubDate>Wed, 29 Sep 2021 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-35945</strong></p>
  <p>Couchbase Server 6.5.x, 6.6.0 through 6.6.2, and 7.0.0, has a Buffer Overflow. A specially crafted network packet sent from an attacker can crash memcached.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-35945">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-35944 – Couchbase Server 6.5.x, 6.6.x through 6.6.2, and 7.0.0 has a Buffer Overflow. A ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-35944</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-35944</guid>
    <pubDate>Wed, 29 Sep 2021 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-35944</strong></p>
  <p>Couchbase Server 6.5.x, 6.6.x through 6.6.2, and 7.0.0 has a Buffer Overflow. A specially crafted network packet sent from an attacker can crash memcached.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-35944">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-33026 – The Flask-Caching extension through 1.10.1 for Flask relies on Pickle for serial...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-33026</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-33026</guid>
    <pubDate>Thu, 13 May 2021 23:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-33026</strong></p>
  <p>The Flask-Caching extension through 1.10.1 for Flask relies on Pickle for serialization, which may lead to remote code execution or local privilege escalation. If an attacker gains access to cache storage (e.g., filesystem, Memcached, Redis, etc.), they can construct a crafted payload, poison the cache, and execute Python code. NOTE: a third party indicates that exploitation is extremely unlikely…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-33026">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-35197 – The official memcached docker images before 1.5.11-alpine (Alpine specific) cont...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-35197</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-35197</guid>
    <pubDate>Thu, 17 Dec 2020 02:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-35197</strong></p>
  <p>The official memcached docker images before 1.5.11-alpine (Alpine specific) contain a blank password for a root user. System using the memcached docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-35197">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-10931 – Memcached 1.6.x before 1.6.2 allows remote attackers to cause a denial of servic...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-10931</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-10931</guid>
    <pubDate>Tue, 24 Mar 2020 15:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-10931</strong></p>
  <p>Memcached 1.6.x before 1.6.2 allows remote attackers to cause a denial of service (daemon crash) via a crafted binary protocol header to try_read_command_binary in memcached.c.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-10931">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-15026 – memcached 1.5.16, when UNIX sockets are used, has a stack-based buffer over-read...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-15026</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-15026</guid>
    <pubDate>Fri, 30 Aug 2019 15:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-15026</strong></p>
  <p>memcached 1.5.16, when UNIX sockets are used, has a stack-based buffer over-read in conn_to_str in memcached.c.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-15026">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-11596 – In memcached before 1.5.14, a NULL pointer dereference was found in the "lru mod...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-11596</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-11596</guid>
    <pubDate>Mon, 29 Apr 2019 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-11596</strong></p>
  <p>In memcached before 1.5.14, a NULL pointer dereference was found in the "lru mode" and "lru temp_ttl" commands. This causes a denial of service when parsing crafted lru command messages in process_lru_command in memcached.c.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-11596">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-6340 – The Memcache::getextendedstats function can be used to trigger an out-of-bounds ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-6340</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-6340</guid>
    <pubDate>Mon, 31 Dec 2018 22:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-6340</strong></p>
  <p>The Memcache::getextendedstats function can be used to trigger an out-of-bounds read. Exploiting this issue requires control over memcached server hostnames and/or ports. This affects all supported versions of HHVM (3.30 and 3.27.4 and below).</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-6340">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-1295 – In Apache Ignite 2.3 or earlier, the serialization mechanism does not have a lis...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1295</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1295</guid>
    <pubDate>Mon, 02 Apr 2018 17:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-1295</strong></p>
  <p>In Apache Ignite 2.3 or earlier, the serialization mechanism does not have a list of classes allowed for serialization/deserialization, which makes it possible to run arbitrary code when 3-rd party vulnerable classes are present in Ignite classpath. The vulnerability can be exploited if the one sends a specially prepared form of a serialized object to one of the deserialization endpoints of some…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1295">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-1000127 – memcached version prior to 1.4.37 contains an Integer Overflow vulnerability in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1000127</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1000127</guid>
    <pubDate>Tue, 13 Mar 2018 21:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-1000127</strong></p>
  <p>memcached version prior to 1.4.37 contains an Integer Overflow vulnerability in items.c:item_free() that can result in data corruption and deadlocks due to items existing in hash table being reused from free list. This attack appear to be exploitable via network connectivity to the memcached service. This vulnerability appears to have been fixed in 1.4.37 and later.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1000127">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-1000115 – Memcached version 1.5.5 contains an Insufficient Control of Network Message Volu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1000115</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1000115</guid>
    <pubDate>Mon, 05 Mar 2018 14:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-1000115</strong></p>
  <p>Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amplification, CWE-406) vulnerability in the UDP support of the memcached server that can result in denial of service via network flood (traffic amplification of 1:50,000 has been reported by reliable sources). This attack appear to be exploitable via network connectivity to port 11211 UDP. This vulnerabil…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1000115">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-9951 – The try_read_command function in memcached.c in memcached before 1.4.39 allows r...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-9951</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-9951</guid>
    <pubDate>Mon, 17 Jul 2017 13:18:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-9951</strong></p>
  <p>The try_read_command function in memcached.c in memcached before 1.4.39 allows remote attackers to cause a denial of service (segmentation fault) via a request to add/set a key, which makes a comparison between signed and unsigned int and triggers a heap-based buffer over-read. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-8705.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-9951">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-3450 – Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Serve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-3450</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-3450</guid>
    <pubDate>Mon, 24 Apr 2017 19:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-3450</strong></p>
  <p>Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Memcached). Supported versions that are affected are 5.6.35 and earlier and 5.7.17 and earlier. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cau…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-3450">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-8706 – An integer overflow in process_bin_sasl_auth function in Memcached, which is res...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-8706</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-8706</guid>
    <pubDate>Fri, 06 Jan 2017 21:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-8706</strong></p>
  <p>An integer overflow in process_bin_sasl_auth function in Memcached, which is responsible for authentication commands of Memcached binary protocol, can be abused to cause heap overflow and lead to remote code execution.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-8706">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2016-8705 – Multiple integer overflows in process_bin_update function in Memcached, which is...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-8705</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-8705</guid>
    <pubDate>Fri, 06 Jan 2017 21:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2016-8705</strong></p>
  <p>Multiple integer overflows in process_bin_update function in Memcached, which is responsible for processing multiple commands of Memcached binary protocol, can be abused to cause heap overflow and lead to remote code execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-8705">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2016-8704 – An integer overflow in the process_bin_append_prepend function in Memcached, whi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-8704</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-8704</guid>
    <pubDate>Fri, 06 Jan 2017 21:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2016-8704</strong></p>
  <p>An integer overflow in the process_bin_append_prepend function in Memcached, which is responsible for processing multiple commands of Memcached binary protocol, can be abused to cause heap overflow and lead to remote code execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-8704">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2012-4406 – OpenStack Object Storage (swift) before 1.7.0 uses the loads function in the pic...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-4406</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-4406</guid>
    <pubDate>Mon, 22 Oct 2012 23:55:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2012-4406</strong></p>
  <p>OpenStack Object Storage (swift) before 1.7.0 uses the loads function in the pickle Python module unsafely when storing and loading metadata in memcached, which allows remote attackers to execute arbitrary code via a crafted pickle object.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-4406">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2009-2415 – Multiple integer overflows in memcached 1.1.12 and 1.2.2 allow remote attackers ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-2415</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-2415</guid>
    <pubDate>Mon, 10 Aug 2009 18:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2009-2415</strong></p>
  <p>Multiple integer overflows in memcached 1.1.12 and 1.2.2 allow remote attackers to execute arbitrary code via vectors involving length attributes that trigger heap-based buffer overflows.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-189</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-2415">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
