CVE Tools

Zeromq

2 CVEs tracked since 2014. Since Oct 2014, none of them reached CISA KEV.

Zeromq CVEs per month

Oct 2014 to Oct 2014. Point at a month, or focus the strip and use the arrow keys.
Zeromq CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2014-1020

Products

The products that kept showing up in Zeromq's monthly top three, with their CVEs summed over those months.

  1. Zeromq21 month

Latest CVEs

The 11 most recently published vulnerabilities affecting Zeromq.

  1. CVE-2020-36400ZeroMQ libzmq 4.3.3 has a heap-based buffer overflow in zmq::tcp_read, a different vulnerability than CVE-2021-20235.9.8
  2. CVE-2021-20237An uncontrolled resource consumption (memory leak) flaw was found in ZeroMQ's src/xpub.cpp in versions before 4.3.3. This flaw allows a remote unauthenticated attacker to send crafted PUB messages ...7.5
  3. CVE-2021-20236A flaw was found in the ZeroMQ server in versions before 4.3.3. This flaw allows a malicious client to cause a stack buffer overflow on the server by sending crafted topic subscription requests and...9.8
  4. CVE-2021-20235There's a flaw in the zeromq server in versions before 4.3.3 in src/decoder_allocators.hpp. The decoder static allocator could have its sized changed, but the buffer would remain the same as it is ...8.1
  5. CVE-2021-20234An uncontrolled resource consumption (memory leak) flaw was found in the ZeroMQ client in versions before 4.3.3 in src/pipe.cpp. This issue causes a client that connects to multiple malicious or co...6.5
  6. CVE-2020-15166Denial of Service in ZeroMQ7.5
  7. CVE-2019-13132In ZeroMQ libzmq before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.3.2, a remote, unauthenticated client connecting to a libzmq application, running with a socket listening with CURVE encryption...9.8
  8. CVE-2019-6250A pointer overflow, with code execution, was discovered in ZeroMQ libzmq (aka 0MQ) 4.2.x and 4.3.x before 4.3.1. A v2_decoder.cpp zmq::v2_decoder_t::size_ready integer overflow allows an authentica...8.8
  9. CVE-2014-9721libzmq before 4.0.6 and 4.1.x before 4.1.1 allows remote attackers to conduct downgrade attacks and bypass ZMTP v3 protocol security mechanisms via a ZMTP v2 or earlier header.4.3
  10. CVE-2014-7202stream_engine.cpp in libzmq (aka ZeroMQ/C++)) 4.0.5 before 4.0.5 allows man-in-the-middle attackers to conduct downgrade attacks via a crafted connection request.4.3
  11. CVE-2014-7203libzmq (aka ZeroMQ/C++) 4.0.x before 4.0.5 does not ensure that nonces are unique, which allows man-in-the-middle attackers to conduct replay attacks via unspecified vectors.4.3

The record

Peak rank
#129 in Oct 2014
Busiest month shown
Oct 2014, 2 CVEs
Months with a KEV entry
0 since Oct 2014
Monthly snapshots
1 since 2014
Zeromq's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store