CVE Tools

Memcached

7 CVEs tracked since 2013. Since Dec 2013, none of them reached CISA KEV.

Memcached CVEs per month

Dec 2013 to Mar 2018. Point at a month, or focus the strip and use the arrow keys.
Memcached CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2013-1210
2014-0140
2014-02null or fewer
2014-03null or fewer
2014-04null or fewer
2014-05null or fewer
2014-06null or fewer
2014-07null or fewer
2014-08null or fewer
2014-09null or fewer
2014-10null or fewer
2014-11null or fewer
2014-12null or fewer
2015-01null or fewer
2015-02null or fewer
2015-03null or fewer
2015-04null or fewer
2015-05null or fewer
2015-06null or fewer
2015-07null or fewer
2015-08null or fewer
2015-09null or fewer
2015-10null or fewer
2015-11null or fewer
2015-12null or fewer
2016-01null or fewer
2016-02null or fewer
2016-03null or fewer
2016-04null or fewer
2016-05null or fewer
2016-06null or fewer
2016-07null or fewer
2016-08null or fewer
2016-09null or fewer
2016-10null or fewer
2016-11null or fewer
2016-12null or fewer
2017-01null or fewer
2017-02null or fewer
2017-03null or fewer
2017-04null or fewer
2017-05null or fewer
2017-06null or fewer
2017-07null or fewer
2017-08null or fewer
2017-09null or fewer
2017-10null or fewer
2017-11null or fewer
2017-12null or fewer
2018-01null or fewer
2018-02null or fewer
2018-0320

Products

The products that kept showing up in Memcached's monthly top three, with their CVEs summed over those months.

  1. Memcached73 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Memcached.

  1. CVE-2026-47784In memcached before 1.6.42, password data for SASL password database authentication has a timing side channel because memcmp is used by sasl_server_userdb_checkpass.8.1
  2. CVE-2026-47783In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon as a valid username is found by sasl_server_userdb_checkpass.8.1
  3. CVE-2023-46852In Memcached before 1.6.22, a buffer overflow exists when processing multiget requests in proxy mode, if there are many spaces after the "get" substring.7.5
  4. CVE-2023-46853In Memcached before 1.6.22, an off-by-one error exists when processing proxy requests in proxy mode, if \n is used instead of \r\n.9.8
  5. CVE-2022-48571memcached 1.6.7 allows a Denial of Service via multi-packet uploads in UDP.7.5
  6. CVE-2020-22570Memcached 1.6.0 before 1.6.3 allows remote attackers to cause a denial of service (daemon crash) via a crafted meta command.7.5
  7. CVE-2021-37519Buffer Overflow vulnerability in authfile.c memcached 1.6.9 allows attackers to cause a denial of service via crafted authenticattion file.5.5
  8. CVE-2020-10931Memcached 1.6.x before 1.6.2 allows remote attackers to cause a denial of service (daemon crash) via a crafted binary protocol header to try_read_command_binary in memcached.c.7.5
  9. CVE-2019-15026memcached 1.5.16, when UNIX sockets are used, has a stack-based buffer over-read in conn_to_str in memcached.c.7.5
  10. CVE-2019-11596In memcached before 1.5.14, a NULL pointer dereference was found in the "lru mode" and "lru temp_ttl" commands. This causes a denial of service when parsing crafted lru command messages in process_...7.5
  11. CVE-2018-1000127memcached version prior to 1.4.37 contains an Integer Overflow vulnerability in items.c:item_free() that can result in data corruption and deadlocks due to items existing in hash table being reused...7.5
  12. CVE-2018-1000115Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amplification, CWE-406) vulnerability in the UDP support of the memcached server that can result in denia...7.5
  13. CVE-2017-9951The try_read_command function in memcached.c in memcached before 1.4.39 allows remote attackers to cause a denial of service (segmentation fault) via a request to add/set a key, which makes a compa...7.5
  14. CVE-2016-8705Multiple integer overflows in process_bin_update function in Memcached, which is responsible for processing multiple commands of Memcached binary protocol, can be abused to cause heap overflow and ...9.8
  15. CVE-2016-8704An integer overflow in the process_bin_append_prepend function in Memcached, which is responsible for processing multiple commands of Memcached binary protocol, can be abused to cause heap overflow...9.8

The record

Peak rank
#37 in Jan 2014
Busiest month shown
Jan 2014, 4 CVEs
Months with a KEV entry
0 since Dec 2013
Monthly snapshots
3 since 2013
Memcached's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store