CVEs (35)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Net Snmp2Debian Linux Net SnmpFeb 19, 2026 Dec 23, 2025 N/A· v4 9.8 CRITICAL· v3 N/A· v2 net-snmp is a SNMP application library, tools and daemon. Prior to versions 5.9.5 and 5.10.pre2, a specially crafted packet to an net-snmp snmptrapd daemon can cause a buffer overflow and the daemon to crash. This issue...Show more |
3Debian FedoraprojectNet Snmp3Debian Linux FedoraNet SnmpFeb 11, 2025 Apr 16, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-write credentials can use a malformed OID in a SET to the nsVacmAccessTable to cause a NULL poi...Show more |
4Debian FedoraprojectNet Snmp+1 more15Debian Linux Enterprise LinuxEnterprise Linux Eus+12 moreJan 17, 2025 Apr 16, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-only credentials can use a malformed OID in a `GET-NEXT` to the `nsVacmAccessTable` to cause a...Show more |
4Debian FedoraprojectNet Snmp+1 more15Debian Linux Enterprise LinuxEnterprise Linux Eus+12 moreJan 17, 2025 Apr 16, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-write credentials can use a malformed OID in a `SET` request to `NET-SNMP-AGENT-MIB::nsLogTable...Show more |
4Debian FedoraprojectNet Snmp+1 more15Debian Linux Enterprise LinuxEnterprise Linux Eus+12 moreJan 17, 2025 Apr 16, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a malformed OID in a SET request to `SNMP-VIEW-BASED-ACM-MIB::vacmAccessTable` can cause an out-of-bounds memory...Show more |
4Debian FedoraprojectNet Snmp+1 more15Debian Linux Enterprise LinuxEnterprise Linux Eus+12 moreJan 17, 2025 Apr 16, 2024 N/A· v4 5.3 MEDIUM· v3 N/A· v2 net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-write credentials can exploit an Improper Input Validation vulnerability when SETing malformed...Show more |
4Debian FedoraprojectNet Snmp+1 more15Debian Linux Enterprise LinuxEnterprise Linux Eus+12 moreJan 17, 2025 Apr 16, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a buffer overflow in the handling of the `INDEX` of `NET-SNMP-VACM-MIB` can cause an out-of-bounds m...Show more |
3Debian Net SnmpNetapp6Debian Linux H300s FirmwareH410s Firmware+3 moreMay 5, 2025 Nov 7, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 handle_ipv6IpForwarding in agent/mibgroup/ip-mib/ip_scalars.c in Net-SNMP 5.4.3 through 5.9.3 has a NULL Pointer Exception bug that can be used by a remote attacker to cause the instance to crash via a crafted UDP packet...Show more |
3Debian Net SnmpNetapp6Debian Linux H300s FirmwareH410s Firmware+3 moreMay 5, 2025 Nov 7, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 handle_ipDefaultTTL in agent/mibgroup/ip-mib/ip_scalars.c in Net-SNMP 5.8 through 5.9.3 has a NULL Pointer Exception bug that can be used by a remote attacker (who has write access) to cause the instance to crash via a c...Show more |
3Canonical Net SnmpNetapp6Cloud Backup Hci Management NodeNet Snmp+3 moreNov 21, 2024 Aug 20, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Net-SNMP through 5.8 has Improper Privilege Management because SNMP WRITE access to the EXTEND MIB provides the ability to run arbitrary commands as root. |
3Canonical Net SnmpNetapp5Cloud Backup Net SnmpSmi S Provider+2 moreDec 3, 2025 Aug 20, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Net-SNMP through 5.7.3 allows Escalation of Privileges because of UNIX symbolic link (symlink) following. |
2Net Snmp Oracle2Net Snmp Zfs Storage Appliance KitNov 21, 2024 Jun 25, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 net-snmp before 5.8.1.pre1 has a double free in usm_free_usmStateReference in snmplib/snmpusm.c via an SNMPv3 GetBulk request. NOTE: this affects net-snmp packages shipped to end users by multiple Linux distributions, bu...Show more |
2Net Snmp Netapp7Cloud Backup Data OntapE Series Santricity Os Controller+4 moreMay 6, 2025 Oct 8, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 snmp_oid_compare in snmplib/snmp_api.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by an unauthenticated attacker to remotely cause the instance to crash via a crafted UDP packet, resulting i...Show more |
5Canonical DebianNet Snmp+2 more10Cloud Backup Data OntapDebian Linux+7 moreNov 21, 2024 Oct 8, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 _set_key in agent/helpers/table_container.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by an authenticated attacker to remotely cause the instance to crash via a crafted UDP packet, resultin...Show more |
2Debian Net Snmp2Debian Linux Net SnmpNov 21, 2024 Mar 7, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 NET-SNMP version 5.7.2 contains a heap corruption vulnerability in the UDP protocol handler that can result in command execution. |
The net-snmp package in OpenBSD through 5.8 uses 0644 permissions for snmpd.conf, which allows local users to obtain sensitive community information by reading this file. |
The snmp_pdu_parse function in snmp_api.c in net-snmp 5.7.2 and earlier does not remove the varBind variable in a netsnmp_variable_list item when parsing of the SNMP PDU fails, which allows remote attackers to cause a de...Show more |
3Apple CanonicalNet Snmp3Mac Os X Net SnmpUbuntu LinuxMay 6, 2026 Oct 7, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 snmplib/mib.c in net-snmp 5.7.0 and earlier, when the -OQ option is used, allows remote attackers to cause a denial of service (snmptrapd crash) via a crafted SNMP trap message, which triggers a conversion to the variabl...Show more |
The perl_trapd_handler function in perl/TrapReceiver/TrapReceiver.xs in Net-SNMP 5.7.3.pre3 and earlier, when using certain Perl versions, allows remote attackers to cause a denial of service (snmptrapd crash) via an emp...Show more |
The AgentX subagent in Net-SNMP before 5.4.4 allows remote attackers to cause a denial of service (hang) by sending a multi-object request with an Object ID (OID) containing more subids than previous requests, a differen...Show more |