← Back

Zeromq

zeromq

Vendor: Zeromq • 4 CVEs

CVEs (4)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Fedoraproject
RedhatZeromq
4Ceph Storage
Enterprise LinuxFedora+1 more
Nov 21, 2024
May 28, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A flaw was found in the ZeroMQ server in versions before 4.3.3. This flaw allows a malicious client to cause a stack buffer overflow on the server by sending crafted topic subscription requests and then unsubscribing. Th...Show more
A flaw was found in the ZeroMQ server in versions before 4.3.3. This flaw allows a malicious client to cause a stack buffer overflow on the server by sending crafted topic subscription requests and then unsubscribing. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.Show less
1Zeromq
1Zeromq
May 6, 2026
Jun 3, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
libzmq before 4.0.6 and 4.1.x before 4.1.1 allows remote attackers to conduct downgrade attacks and bypass ZMTP v3 protocol security mechanisms via a ZMTP v2 or earlier header.
1Zeromq
1Zeromq
May 6, 2026
Oct 8, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
libzmq (aka ZeroMQ/C++) 4.0.x before 4.0.5 does not ensure that nonces are unique, which allows man-in-the-middle attackers to conduct replay attacks via unspecified vectors.
1Zeromq
1Zeromq
May 6, 2026
Oct 8, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
stream_engine.cpp in libzmq (aka ZeroMQ/C++)) 4.0.5 before 4.0.5 allows man-in-the-middle attackers to conduct downgrade attacks via a crafted connection request.