← Back

Openslp

openslp

9 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Openslp
openslp

CVEs (9)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
4Fedoraproject
OpenslpRedhat+1 more
16Enterprise Linux Desktop
Enterprise Linux For Ibm Z SystemsEnterprise Linux For Ibm Z Systems Eus+13 more
Jun 17, 2026
Dec 6, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.
4Canonical
DebianFedoraproject+1 more
4Debian Linux
FedoraOpenslp+1 more
Nov 21, 2024
Dec 2, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
openslp: SLPIntersectStringList()' Function has a DoS vulnerability
5Canonical
DebianLenovo+2 more
38Bm Nextscale Fan Power Controller
CmmDebian Linux+35 more
Nov 21, 2024
Apr 23, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
OpenSLP releases in the 1.0.2 and 1.1.0 code streams have a heap-related memory corruption issue which may manifest itself as a denial-of-service or a remote code-execution vulnerability.
2Debian
Openslp
2Debian Linux
Openslp
May 13, 2026
Oct 22, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Double free vulnerability in the SLPDKnownDAAdd function in slpd/slpd_knownda.c in OpenSLP 1.2.1 allows remote attackers to cause a denial of service (crash) via a crafted package.
1Openslp
1Openslp
May 13, 2026
Mar 27, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The _xrealloc function in xlsp_xmalloc.c in OpenSLP 2.0.0 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a large number of crafted packets, which triggers a memory allocatio...Show more
The _xrealloc function in xlsp_xmalloc.c in OpenSLP 2.0.0 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a large number of crafted packets, which triggers a memory allocation failure.Show less
1Openslp
1Openslp
May 13, 2026
Jan 23, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Buffer overflow in the SLPFoldWhiteSpace function in common/slp_compare.c in OpenSLP 2.0 allows remote attackers to have unspecified impact via a crafted string.
2Openslp
Vmware
3Esx
EsxiOpenslp
Apr 29, 2026
Mar 11, 2011
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The extension parser in slp_v2message.c in OpenSLP 1.2.1, and other versions before SVN revision 1647, as used in Service Location Protocol daemon (SLPD) in VMware ESX 4.0 and 4.1 and ESXi 4.0 and 4.1, allows remote atta...Show more
The extension parser in slp_v2message.c in OpenSLP 1.2.1, and other versions before SVN revision 1647, as used in Service Location Protocol daemon (SLPD) in VMware ESX 4.0 and 4.1 and ESXi 4.0 and 4.1, allows remote attackers to cause a denial of service (infinite loop) via a packet with a "next extension offset" that references this extension or a previous extension. NOTE: some of these details are obtained from third party information.Show less
1Openslp
1Openslp
Apr 16, 2026
May 2, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple buffer overflows in OpenSLP before 1.1.5 allow remote attackers to have an unknown impact via malformed SLP packets.
1Openslp
1Openslp
Apr 16, 2026
Nov 17, 2003
N/A· v4
N/A· v3
2.1 LOW· v2
Symbolic link vulnerability in the slpd script slpd.all_init for OpenSLP before 1.0.11 allows local users to overwrite arbitrary files via the route.check temporary file.