Filtered by vendor Emqx
Subscriptions
Total
42 CVE
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2024-42648 | 1 Emqx | 1 Nanomq | 2025-07-16 | 6.5 Medium |
| NanoMQ v0.22.10 was discovered to contain a heap overflow which allows attackers to cause a Denial of Service (DoS) via a crafted CONNECT message. | ||||
| CVE-2024-42646 | 1 Emqx | 1 Nanomq | 2025-07-16 | 7.5 High |
| A segmentation fault in NanoMQ v0.21.10 allows attackers to cause a Denial of Service (DoS) via crafted messages. | ||||
| CVE-2024-42649 | 1 Emqx | 1 Nanomq | 2025-07-16 | 6.5 Medium |
| NanoMQ v0.22.10 was discovered to contain a memory leak which allows attackers to cause a Denial of Service (DoS) via a crafted PUBLISH message. | ||||
| CVE-2024-31040 | 1 Emqx | 1 Nanomq | 2025-06-10 | 2.7 Low |
| Buffer Overflow vulnerability in the get_var_integer function in mqtt_parser.c in NanoMQ 0.21.7 allows remote attackers to cause a denial of service via a series of specially crafted hexstreams. | ||||
| CVE-2024-31041 | 1 Emqx | 1 Nanomq | 2025-06-10 | 7.5 High |
| Null Pointer Dereference vulnerability in topic_filtern function in mqtt_parser.c in NanoMQ 0.21.7 allows attackers to cause a denial of service. | ||||
| CVE-2024-31036 | 2 Emqx, Nanomq | 2 Nanomq, Nanomq | 2025-06-10 | 6.8 Medium |
| A heap-buffer-overflow vulnerability in the read_byte function in NanoMQ v.0.21.7 allows attackers to cause a denial of service via transmission of crafted hexstreams. | ||||
| CVE-2024-25767 | 1 Emqx | 1 Nanomq | 2025-05-01 | 6.5 Medium |
| nanomq 0.21.2 contains a Use-After-Free vulnerability in /nanomq/nng/src/core/socket.c. | ||||
| CVE-2023-29996 | 1 Emqx | 1 Nanomq | 2025-01-29 | 7.5 High |
| In NanoMQ v0.15.0-0, segment fault with Null Pointer Dereference occurs in the process of decoding subinfo_decode and unsubinfo_decode. | ||||
| CVE-2023-29995 | 1 Emqx | 1 Nanomq | 2025-01-29 | 7.5 High |
| In NanoMQ v0.15.0-0, a Heap overflow occurs in copyn_utf8_str function of mqtt_parser.c | ||||
| CVE-2023-29994 | 1 Emqx | 1 Nanomq | 2025-01-29 | 7.5 High |
| In NanoMQ v0.15.0-0, Heap overflow occurs in read_byte function of mqtt_code.c. | ||||
| CVE-2023-33656 | 1 Emqx | 1 Nanomq | 2025-01-10 | 5.5 Medium |
| A memory leak vulnerability exists in NanoMQ 0.17.2. The vulnerability is located in the file message.c. An attacker could exploit this vulnerability to cause a denial of service attack by causing the program to consume all available memory resources. | ||||
| CVE-2023-33659 | 1 Emqx | 1 Nanomq | 2025-01-08 | 7.5 High |
| A heap buffer overflow vulnerability exists in NanoMQ 0.17.2. The vulnerability can be triggered by calling the function nmq_subinfo_decode() in the file mqtt_parser.c. An attacker could exploit this vulnerability to cause a denial of service attack. | ||||
| CVE-2023-33660 | 1 Emqx | 1 Nanomq | 2025-01-06 | 7.5 High |
| A heap buffer overflow vulnerability exists in NanoMQ 0.17.2. The vulnerability can be triggered by calling the function copyn_str() in the file mqtt_parser.c. An attacker could exploit this vulnerability to cause a denial of service attack. | ||||
| CVE-2023-33658 | 1 Emqx | 1 Nanomq | 2025-01-06 | 7.5 High |
| A heap buffer overflow vulnerability exists in NanoMQ 0.17.2. The vulnerability can be triggered by calling the function nni_msg_get_pub_pid() in the file message.c. An attacker could exploit this vulnerability to cause a denial of service attack. | ||||
| CVE-2023-33657 | 1 Emqx | 1 Nanomq | 2025-01-06 | 7.5 High |
| A use-after-free vulnerability exists in NanoMQ 0.17.2. The vulnerability can be triggered by calling the function nni_mqtt_msg_get_publish_property() in the file mqtt_msg.c. This vulnerability is caused by improper data tracing, and an attacker could exploit it to cause a denial of service attack. | ||||
| CVE-2023-34494 | 1 Emqx | 1 Nanomq | 2025-01-03 | 7.5 High |
| NanoMQ 0.16.5 is vulnerable to heap-use-after-free in the nano_ctx_send function of nmq_mqtt.c. | ||||
| CVE-2024-10964 | 1 Emqx | 1 Neuron | 2024-11-26 | 6.3 Medium |
| A vulnerability classified as critical has been found in emqx neuron up to 2.10.0. Affected is the function handle_add_plugin in the library cmd.library of the file plugins/restful/plugin_handle.c. The manipulation leads to buffer overflow. It is possible to launch the attack remotely. It is recommended to apply a patch to fix this issue. | ||||
| CVE-2024-10965 | 1 Emqx | 1 Neuron | 2024-11-23 | 4.3 Medium |
| A vulnerability classified as problematic was found in emqx neuron up to 2.10.0. Affected by this vulnerability is an unknown functionality of the file /api/v2/schema of the component JSON File Handler. The manipulation leads to information disclosure. The attack can be launched remotely. The patch is named c9ce39747e0372aaa2157b2b56174914a12c06d8. It is recommended to apply a patch to fix this issue. | ||||
| CVE-2023-37781 | 1 Emqx | 1 Emqx | 2024-11-21 | 6.5 Medium |
| An issue in the emqx_sn plugin of EMQX v4.3.8 allows attackers to execute a directory traversal via uploading a crafted .txt file. | ||||
| CVE-2021-46434 | 1 Emqx | 1 Emqx | 2024-11-21 | 5.3 Medium |
| EMQ X Dashboard V3.0.0 is affected by username enumeration in the "/api /v3/auth" interface. When a user login, the application returns different results depending on whether the account is correct, that allowed an attacker to determine if a given username was valid | ||||