Debian Libmodbus vulnerabilities
7 known vulnerabilities affecting debian/libmodbus.
Total CVEs
7
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH3MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2024-36844HIGHCVSS 7.5fixed in libmodbus 3.1.6-2.1 (bookworm)2024
CVE-2024-36844 [HIGH] CVE-2024-36844: libmodbus - libmodbus v3.1.6 was discovered to contain a use-after-free via the ctx->backend...
libmodbus v3.1.6 was discovered to contain a use-after-free via the ctx->backend pointer. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted message sent to the unit-test-server.
Scope: local
bookworm: resolved (fixed in 3.1.6-2.1)
bullseye: resolved (fixed in 3.1.6-2+deb11u1)
forky: resolved (fixed in 3.1.6-2.1)
sid: resolved (fi
debian
CVE-2024-36843HIGHCVSS 7.5fixed in libmodbus 3.1.6-2.1 (bookworm)2024
CVE-2024-36843 [HIGH] CVE-2024-36843: libmodbus - libmodbus v3.1.6 was discovered to contain a heap overflow via the modbus_mappin...
libmodbus v3.1.6 was discovered to contain a heap overflow via the modbus_mapping_free() function.
Scope: local
bookworm: resolved (fixed in 3.1.6-2.1)
bullseye: resolved (fixed in 3.1.6-2+deb11u1)
forky: resolved (fixed in 3.1.6-2.1)
sid: resolved (fixed in 3.1.6-2.1)
trixie: resolved (fixed in 3.1.6-2.1)
debian
CVE-2024-10918MEDIUMCVSS 4.8fixed in libmodbus 3.1.6-2+deb11u1 (bullseye)2024
CVE-2024-10918 [MEDIUM] CVE-2024-10918: libmodbus - Stack-based Buffer Overflow vulnerability in libmodbus v3.1.10 allows to overflo...
Stack-based Buffer Overflow vulnerability in libmodbus v3.1.10 allows to overflow the buffer allocated for the Modbus response if the function tries to reply to a Modbus request with an unexpected length.
Scope: local
bookworm: open
bullseye: resolved (fixed in 3.1.6-2+deb11u1)
forky: resolved (fixed in 3.1.11-1)
sid: resolved (fixed in 3.1.11-1)
trixie: resolve
debian
CVE-2024-36845MEDIUMCVSS 4.3fixed in libmodbus 3.1.6-2.1 (bookworm)2024
CVE-2024-36845 [MEDIUM] CVE-2024-36845: libmodbus - An invalid pointer in the modbus_receive() function of libmodbus v3.1.6 allows a...
An invalid pointer in the modbus_receive() function of libmodbus v3.1.6 allows attackers to cause a Denial of Service (DoS) via a crafted message sent to the unit-test-server.
Scope: local
bookworm: resolved (fixed in 3.1.6-2.1)
bullseye: resolved (fixed in 3.1.6-2+deb11u1)
forky: resolved (fixed in 3.1.6-2.1)
sid: resolved (fixed in 3.1.6-2.1)
trixie: resolved
debian
CVE-2022-0367HIGHCVSS 7.8fixed in libmodbus 3.1.6-2.1 (bookworm)2022
CVE-2022-0367 [HIGH] CVE-2022-0367: libmodbus - A heap-based buffer overflow flaw was found in libmodbus in function modbus_repl...
A heap-based buffer overflow flaw was found in libmodbus in function modbus_reply() in src/modbus.c.
Scope: local
bookworm: resolved (fixed in 3.1.6-2.1)
bullseye: resolved (fixed in 3.1.6-2+deb11u1)
forky: resolved (fixed in 3.1.6-2.1)
sid: resolved (fixed in 3.1.6-2.1)
trixie: resolved (fixed in 3.1.6-2.1)
debian
CVE-2019-14463CRITICALCVSS 9.1fixed in libmodbus 3.1.6-1 (bookworm)2019
CVE-2019-14463 [CRITICAL] CVE-2019-14463: libmodbus - An issue was discovered in libmodbus before 3.0.7 and 3.1.x before 3.1.5. There ...
An issue was discovered in libmodbus before 3.0.7 and 3.1.x before 3.1.5. There is an out-of-bounds read for the MODBUS_FC_WRITE_MULTIPLE_REGISTERS case, aka VD-1301.
Scope: local
bookworm: resolved (fixed in 3.1.6-1)
bullseye: resolved (fixed in 3.1.6-1)
forky: resolved (fixed in 3.1.6-1)
sid: resolved (fixed in 3.1.6-1)
trixie: resolved (fixed in 3.1.6-1)
debian
CVE-2019-14462CRITICALCVSS 9.1fixed in libmodbus 3.1.6-1 (bookworm)2019
CVE-2019-14462 [CRITICAL] CVE-2019-14462: libmodbus - An issue was discovered in libmodbus before 3.0.7 and 3.1.x before 3.1.5. There ...
An issue was discovered in libmodbus before 3.0.7 and 3.1.x before 3.1.5. There is an out-of-bounds read for the MODBUS_FC_WRITE_MULTIPLE_COILS case, aka VD-1302.
Scope: local
bookworm: resolved (fixed in 3.1.6-1)
bullseye: resolved (fixed in 3.1.6-1)
forky: resolved (fixed in 3.1.6-1)
sid: resolved (fixed in 3.1.6-1)
trixie: resolved (fixed in 3.1.6-1)
debian