Eclipse / Mosquitto
26 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2024-3935 | Eclipse Mosquito: Double free vulnerability | MEDIUM | 6.0 | Oct 30, 2024 |
| CVE-2024-10525 | Eclipse Mosquito: Heap Buffer Overflow in my_subscribe_callback | HIGH | 7.2 | Oct 30, 2024 |
| CVE-2024-8376 | Memory leak | HIGH | 7.2 | Oct 11, 2024 |
| CVE-2023-5632 | Unconditionally adding an event to the epoll causes excessive CPU consumption | HIGH | 7.5 | Oct 18, 2023 |
| CVE-2023-3592 | mosquitto: memory leak leads to unresponsive broker | HIGH | 7.5 | Oct 2, 2023 |
| CVE-2023-0809 | mosquitto: memory leak leads to unresponsive broker | HIGH | 7.5 | Oct 2, 2023 |
| CVE-2023-28366 | mosquitto: memory leak leads to unresponsive broker | HIGH | 7.5 | Sep 1, 2023 |
| CVE-2021-41039 | In versions 1.6 to 2.0.11 of Eclipse Mosquitto, an MQTT v5 client connecting with a large number of user-property properties could cause excessive CPU usage, l… | HIGH | 7.5 | Dec 1, 2021 |
| CVE-2021-34434 | In Eclipse Mosquitto versions 2.0 to 2.0.11, when using the dynamic security plugin, if the ability for a client to make subscriptions on a topic is revoked wh… | MEDIUM | 5.3 | Aug 30, 2021 |
| CVE-2021-34432 | In Eclipse Mosquitto versions 2.0.7 and earlier, the server will crash if the client tries to send a PUBLISH packet with topic length = 0. | HIGH | 7.5 | Jul 27, 2021 |
| CVE-2021-34431 | In Eclipse Mosquitto version 1.6 to 2.0.10, if an authenticated client that had connected with MQTT v5 sent a crafted CONNECT message to the broker a memory le… | MEDIUM | 6.5 | Jul 22, 2021 |
| CVE-2021-28166 | In Eclipse Mosquitto version 2.0.0 to 2.0.9, if an authenticated client that had connected with MQTT v5 sent a crafted CONNACK message to the broker, a NULL po… | MEDIUM | 6.5 | Apr 7, 2021 |
| CVE-2019-11779 | In Eclipse Mosquitto 1.5.0 to 1.6.5 inclusive, if a malicious MQTT client sends a SUBSCRIBE packet containing a topic that consists of approximately 65400 or m… | MEDIUM | 6.5 | Sep 19, 2019 |
| CVE-2019-11778 | If an MQTT v5 client connects to Eclipse Mosquitto versions 1.6.0 to 1.6.4 inclusive, sets a last will and testament, sets a will delay interval, sets a sessio… | MEDIUM | 5.4 | Sep 18, 2019 |
| CVE-2017-7655 | In Eclipse Mosquitto version from 1.0 to 1.4.15, a Null Dereference vulnerability was found in the Mosquitto library which could lead to crashes for those appl… | HIGH | 7.5 | Mar 27, 2019 |
| CVE-2018-12551 | When Eclipse Mosquitto version 1.0 to 1.5.5 (inclusive) is configured to use a password file for authentication, any malformed data in the password file will b… | HIGH | 8.1 | Mar 27, 2019 |
| CVE-2018-12550 | When Eclipse Mosquitto version 1.0 to 1.5.5 (inclusive) is configured to use an ACL file, and that ACL file is empty, or contains only comments or blank lines,… | HIGH | 8.1 | Mar 27, 2019 |
| CVE-2018-12546 | In Eclipse Mosquitto version 1.0 to 1.5.5 (inclusive) when a client publishes a retained message to a topic, then has its access to that topic revoked, the ret… | MEDIUM | 6.5 | Mar 27, 2019 |
| CVE-2018-20145 | Eclipse Mosquitto 1.5.x before 1.5.5 allows ACL bypass: if the option per_listener_settings was set to true, and the default listener was in use, and the defau… | HIGH | 7.5 | Dec 13, 2018 |
| CVE-2018-12543 | In Eclipse Mosquitto versions 1.5 to 1.5.2 inclusive, if a message is published to Mosquitto that has a topic starting with $, but that is not $SYS, e.g. $test… | HIGH | 7.5 | Nov 15, 2018 |
| CVE-2017-7654 | In Eclipse Mosquitto 1.4.15 and earlier, a Memory Leak vulnerability was found within the Mosquitto Broker. Unauthenticated clients can send crafted CONNECT pa… | HIGH | 7.5 | Jun 5, 2018 |
| CVE-2017-7653 | The Eclipse Mosquitto broker up to version 1.4.15 does not reject strings that are not valid UTF-8. A malicious client could cause other clients that do reject… | MEDIUM | 5.3 | Jun 5, 2018 |
| CVE-2017-7652 | In Eclipse Mosquitto 1.4.14, if a Mosquitto instance is set running with a configuration file, then sending a HUP signal to server triggers the configuration t… | HIGH | 7.5 | Apr 25, 2018 |
| CVE-2017-7651 | In Eclipse Mosquitto 1.4.14, a user can shutdown the Mosquitto server simply by filling the RAM memory with a lot of connections with large payload. This can b… | HIGH | 7.5 | Apr 24, 2018 |
| CVE-2017-7650 | In Mosquitto before 1.4.12, pattern based ACLs can be bypassed by clients that set their username/client id to '#' or '+'. This allows locally or remotely conn… | MEDIUM | 6.5 | Sep 11, 2017 |
Showing 1 to 25 of 26 CVEs