Net-snmp
36 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Net-snmp, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
Net-snmp CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 1 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 1 |
Severity
How the 36 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical4
- High8
- Medium22
- Low2
Latest CVEs
The 15 most recently published vulnerabilities affecting Net-snmp.
- CVE-2026-89147Net-SNMP through 5.9.5.2 Denial of Service via Blocking Unauthenticated SMUX Read7.5
- CVE-2025-68615Net-SNMP snmptrapd crash9.8
- CVE-2022-24810net-snmp: A malformed OID in a SET to the nsVacmAccessTable can cause a NULL pointer dereference.6.5
- CVE-2022-24809net-snmp: A malformed OID in a SET request to NET-SNMP-AGENT-MIB::nsLogTable can cause a NULL pointer dereference6.5
- CVE-2022-24808net-snmp: A malformed OID in a SET request to NET-SNMP-AGENT-MIB::nsLogTable can cause a NULL pointer dereference6.5
- CVE-2022-24807net-snmp: A malformed OID in a SET request to SNMP-VIEW-BASED-ACM-MIB::vacmAccessTable can cause an out-of-bounds memory access6.5
- CVE-2022-24806net-snmp vulnerable to Improper Input Validation when SETing malformed OIDs in master agent and subagent simultaneously6.5
- CVE-2022-24805net-snmp: A buffer overflow in the handling of the INDEX of NET-SNMP-VACM-MIB can cause an out-of-bounds memory access.6.5
- CVE-2022-44792handle_ipDefaultTTL in agent/mibgroup/ip-mib/ip_scalars.c in Net-SNMP 5.8 through 5.9.3 has a NULL Pointer Exception bug that can be used by a remote attacker (who has write access) to cause the in...6.5
- CVE-2022-44793handle_ipv6IpForwarding in agent/mibgroup/ip-mib/ip_scalars.c in Net-SNMP 5.4.3 through 5.9.3 has a NULL Pointer Exception bug that can be used by a remote attacker to cause the instance to crash v...6.5
- CVE-2020-15861Net-SNMP through 5.7.3 allows Escalation of Privileges because of UNIX symbolic link (symlink) following.7.8
- CVE-2020-15862Net-SNMP through 5.8 has Improper Privilege Management because SNMP WRITE access to the EXTEND MIB provides the ability to run arbitrary commands as root.7.8
- CVE-2019-20892net-snmp before 5.8.1.pre1 has a double free in usm_free_usmStateReference in snmplib/snmpusm.c via an SNMPv3 GetBulk request. NOTE: this affects net-snmp packages shipped to end users by multiple ...6.5
- CVE-2018-18065_set_key in agent/helpers/table_container.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by an authenticated attacker to remotely cause the instance to crash via a craft...6.5
- CVE-2018-18066snmp_oid_compare in snmplib/snmp_api.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by an unauthenticated attacker to remotely cause the instance to crash via a crafted ...7.5
Product grouping is registry-driven, with AI assist and human review. How it works