cbcvebase.

Debian Net-Snmp vulnerabilities

31 known vulnerabilities affecting debian/net-snmp.

Total CVEs
31
CISA KEV
0
Public exploits
5
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH5MEDIUM19LOW5

Vulnerabilities

Page 1 of 2
CVE-2008-0960P2MEDIUMCVSS 10.0PoCfixed in net-snmp 5.4.1~dfsg-8.1 (bookworm)2008
CVE-2008-0960 [CRITICAL] CVE-2008-0960: net-snmp - SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.... SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-SNMP; (3) eCos; (4) Juniper Session and Resource Control (SRC) C-series 1.0.0 through 2.0.0; (5) NetApp (aka Network Appliance) Data ONTAP 7.3RC1 and 7.3RC2; (6) SNMP Research before 16.2; (7) multiple Cisco IOS, CatOS, ACE, and Nexus products; (
debian
CVE-2015-5621P2HIGHCVSS 7.5PoCfixed in net-snmp 5.7.3+dfsg-1.1 (bookworm)2015
CVE-2015-5621 [HIGH] CVE-2015-5621: net-snmp - The snmp_pdu_parse function in snmp_api.c in net-snmp 5.7.2 and earlier does not... The snmp_pdu_parse function in snmp_api.c in net-snmp 5.7.2 and earlier does not remove the varBind variable in a netsnmp_variable_list item when parsing of the SNMP PDU fails, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted packet. Scope: local bookworm: resolved (fixed in 5.7.3+dfsg-1.1) bullseye:
debian
CVE-2025-68615P2CRITICALCVSS 9.8fixed in net-snmp 5.9.3+dfsg-2+deb12u1 (bookworm)2025
CVE-2025-68615 [CRITICAL] CVE-2025-68615: net-snmp - net-snmp is a SNMP application library, tools and daemon. Prior to versions 5.9.... net-snmp is a SNMP application library, tools and daemon. Prior to versions 5.9.5 and 5.10.pre2, a specially crafted packet to an net-snmp snmptrapd daemon can cause a buffer overflow and the daemon to crash. This issue has been patched in versions 5.9.5 and 5.10.pre2. Scope: local bookworm: resolved (fixed in 5.9.3+dfsg-2+deb12u1) bullseye: resolved (fixed in
debian
CVE-2018-18065P3MEDIUMCVSS 6.5PoCfixed in net-snmp 5.7.3+dfsg-4 (bookworm)2018
CVE-2018-18065 [MEDIUM] CVE-2018-18065: net-snmp - _set_key in agent/helpers/table_container.c in Net-SNMP before 5.8 has a NULL Po... _set_key in agent/helpers/table_container.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by an authenticated attacker to remotely cause the instance to crash via a crafted UDP packet, resulting in Denial of Service. Scope: local bookworm: resolved (fixed in 5.7.3+dfsg-4) bullseye: resolved (fixed in 5.7.3+dfsg-4) forky: resolved (fixed
debian
CVE-2008-2292P3MEDIUMCVSS 6.8PoCfixed in net-snmp 5.4.1~dfsg-8 (bookworm)2008
CVE-2008-2292 [MEDIUM] CVE-2008-2292: net-snmp - Buffer overflow in the __snprint_value function in snmp_get in Net-SNMP 5.1.4, 5... Buffer overflow in the __snprint_value function in snmp_get in Net-SNMP 5.1.4, 5.2.4, and 5.4.1, as used in SNMP.xs for Perl, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large OCTETSTRING in an attribute value pair (AVP). Scope: local bookworm: resolved (fixed in 5.4.1~dfsg-8) bullseye: resolved (fixed in 5
debian
CVE-2022-24805P3MEDIUMCVSS 6.5fixed in net-snmp 5.9.3+dfsg-1 (bookworm)2022
CVE-2022-24805 [MEDIUM] CVE-2022-24805: net-snmp - net-snmp provides various tools relating to the Simple Network Management Protoc... net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a buffer overflow in the handling of the `INDEX` of `NET-SNMP-VACM-MIB` can cause an out-of-bounds memory access. A user with read-only credentials can exploit the issue. Version 5.9.2 contains a patch. Users should use strong SNMPv3 credentials and avoid s
debian
CVE-2022-44792P3MEDIUMCVSS 6.5fixed in net-snmp 5.9.3+dfsg-2 (bookworm)2022
CVE-2022-44792 [MEDIUM] CVE-2022-44792: net-snmp - handle_ipDefaultTTL in agent/mibgroup/ip-mib/ip_scalars.c in Net-SNMP 5.8 throug... handle_ipDefaultTTL in agent/mibgroup/ip-mib/ip_scalars.c in Net-SNMP 5.8 through 5.9.3 has a NULL Pointer Exception bug that can be used by a remote attacker (who has write access) to cause the instance to crash via a crafted UDP packet, resulting in Denial of Service. Scope: local bookworm: resolved (fixed in 5.9.3+dfsg-2) bullseye: resolved (fixed in 5.9+dfsg-
debian
CVE-2018-1000116P3CRITICALCVSS 9.8fixed in net-snmp 5.7.3+dfsg-1.1 (bookworm)2018
CVE-2018-1000116 [CRITICAL] CVE-2018-1000116: net-snmp - NET-SNMP version 5.7.2 contains a heap corruption vulnerability in the UDP proto... NET-SNMP version 5.7.2 contains a heap corruption vulnerability in the UDP protocol handler that can result in command execution. Scope: local bookworm: resolved (fixed in 5.7.3+dfsg-1.1) bullseye: resolved (fixed in 5.7.3+dfsg-1.1) forky: resolved (fixed in 5.7.3+dfsg-1.1) sid: resolved (fixed in 5.7.3+dfsg-1.1) trixie: resolved (fixed in 5.7.3+dfsg-1.1)
debian
CVE-2022-44793P3MEDIUMCVSS 6.5fixed in net-snmp 5.9.3+dfsg-2 (bookworm)2022
CVE-2022-44793 [MEDIUM] CVE-2022-44793: net-snmp - handle_ipv6IpForwarding in agent/mibgroup/ip-mib/ip_scalars.c in Net-SNMP 5.4.3 ... handle_ipv6IpForwarding in agent/mibgroup/ip-mib/ip_scalars.c in Net-SNMP 5.4.3 through 5.9.3 has a NULL Pointer Exception bug that can be used by a remote attacker to cause the instance to crash via a crafted UDP packet, resulting in Denial of Service. Scope: local bookworm: resolved (fixed in 5.9.3+dfsg-2) bullseye: resolved (fixed in 5.9+dfsg-4+deb11u2) forky:
debian
CVE-2022-24810P3MEDIUMCVSS 6.5fixed in net-snmp 5.9.3+dfsg-1 (bookworm)2022
CVE-2022-24810 [MEDIUM] CVE-2022-24810: net-snmp - net-snmp provides various tools relating to the Simple Network Management Protoc... net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-write credentials can use a malformed OID in a SET to the nsVacmAccessTable to cause a NULL pointer dereference. Version 5.9.2 contains a patch. Users should use strong SNMPv3 credentials and avoid sharing the credentials. Those who must us
debian
CVE-2012-6151P4LOWCVSS 4.3PoCfixed in net-snmp 5.7.2.1~dfsg-3 (bookworm)2012
CVE-2012-6151 [MEDIUM] CVE-2012-6151: net-snmp - Net-SNMP 5.7.1 and earlier, when AgentX is registering to handle a MIB and proce... Net-SNMP 5.7.1 and earlier, when AgentX is registering to handle a MIB and processing GETNEXT requests, allows remote attackers to cause a denial of service (crash or infinite loop, CPU consumption, and hang) by causing the AgentX subagent to timeout. Scope: local bookworm: resolved (fixed in 5.7.2.1~dfsg-3) bullseye: resolved (fixed in 5.7.2.1~dfsg-3) forky: resol
debian
CVE-2007-5846P3HIGHCVSS 7.8fixed in net-snmp 5.4.1~dfsg-1 (bookworm)2007
CVE-2007-5846 [HIGH] CVE-2007-5846: net-snmp - The SNMP agent (snmp_agent.c) in net-snmp before 5.4.1 allows remote attackers t... The SNMP agent (snmp_agent.c) in net-snmp before 5.4.1 allows remote attackers to cause a denial of service (CPU and memory consumption) via a GETBULK request with a large max-repeaters value. Scope: local bookworm: resolved (fixed in 5.4.1~dfsg-1) bullseye: resolved (fixed in 5.4.1~dfsg-1) forky: resolved (fixed in 5.4.1~dfsg-1) sid: resolved (fixed in 5.4.1~dfsg-1)
debian
CVE-2018-18066P3HIGHCVSS 7.5fixed in net-snmp 5.7.3+dfsg-1.1 (bookworm)2018
CVE-2018-18066 [HIGH] CVE-2018-18066: net-snmp - snmp_oid_compare in snmplib/snmp_api.c in Net-SNMP before 5.8 has a NULL Pointer... snmp_oid_compare in snmplib/snmp_api.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by an unauthenticated attacker to remotely cause the instance to crash via a crafted UDP packet, resulting in Denial of Service. Scope: local bookworm: resolved (fixed in 5.7.3+dfsg-1.1) bullseye: resolved (fixed in 5.7.3+dfsg-1.1) forky: resolved (fixed
debian
CVE-2020-15862P3HIGHCVSS 7.8fixed in net-snmp 5.8+dfsg-4 (bookworm)2020
CVE-2020-15862 [HIGH] CVE-2020-15862: net-snmp - Net-SNMP through 5.8 has Improper Privilege Management because SNMP WRITE access... Net-SNMP through 5.8 has Improper Privilege Management because SNMP WRITE access to the EXTEND MIB provides the ability to run arbitrary commands as root. Scope: local bookworm: resolved (fixed in 5.8+dfsg-4) bullseye: resolved (fixed in 5.8+dfsg-4) forky: resolved (fixed in 5.8+dfsg-4) sid: resolved (fixed in 5.8+dfsg-4) trixie: resolved (fixed in 5.8+dfsg-4)
debian
CVE-2022-24807P3MEDIUMCVSS 6.5fixed in net-snmp 5.9.3+dfsg-1 (bookworm)2022
CVE-2022-24807 [MEDIUM] CVE-2022-24807: net-snmp - net-snmp provides various tools relating to the Simple Network Management Protoc... net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a malformed OID in a SET request to `SNMP-VIEW-BASED-ACM-MIB::vacmAccessTable` can cause an out-of-bounds memory access. A user with read-write credentials can exploit the issue. Version 5.9.2 contains a patch. Users should use strong SNMPv3 credentials and
debian
CVE-2020-15861P3HIGHCVSS 7.8fixed in net-snmp 5.8+dfsg-5 (bookworm)2020
CVE-2020-15861 [HIGH] CVE-2020-15861: net-snmp - Net-SNMP through 5.7.3 allows Escalation of Privileges because of UNIX symbolic ... Net-SNMP through 5.7.3 allows Escalation of Privileges because of UNIX symbolic link (symlink) following. Scope: local bookworm: resolved (fixed in 5.8+dfsg-5) bullseye: resolved (fixed in 5.8+dfsg-5) forky: resolved (fixed in 5.8+dfsg-5) sid: resolved (fixed in 5.8+dfsg-5) trixie: resolved (fixed in 5.8+dfsg-5)
debian
CVE-2008-4309P3MEDIUMCVSS 5.0fixed in net-snmp 5.4.1~dfsg-11 (bookworm)2008
CVE-2008-4309 [MEDIUM] CVE-2008-4309: net-snmp - Integer overflow in the netsnmp_create_subtree_cache function in agent/snmp_agen... Integer overflow in the netsnmp_create_subtree_cache function in agent/snmp_agent.c in net-snmp 5.4 before 5.4.2.1, 5.3 before 5.3.2.3, and 5.2 before 5.2.5.1 allows remote attackers to cause a denial of service (crash) via a crafted SNMP GETBULK request, which triggers a heap-based buffer overflow, related to the number of responses or repeats. Scope: local bookwo
debian
CVE-2022-24808P3MEDIUMCVSS 6.5fixed in net-snmp 5.9.3+dfsg-1 (bookworm)2022
CVE-2022-24808 [MEDIUM] CVE-2022-24808: net-snmp - net-snmp provides various tools relating to the Simple Network Management Protoc... net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-write credentials can use a malformed OID in a `SET` request to `NET-SNMP-AGENT-MIB::nsLogTable` to cause a NULL pointer dereference. Version 5.9.2 contains a patch. Users should use strong SNMPv3 credentials and avoid sharing the credentia
debian
CVE-2022-24809P3MEDIUMCVSS 6.5fixed in net-snmp 5.9.3+dfsg-1 (bookworm)2022
CVE-2022-24809 [MEDIUM] CVE-2022-24809: net-snmp - net-snmp provides various tools relating to the Simple Network Management Protoc... net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-only credentials can use a malformed OID in a `GET-NEXT` to the `nsVacmAccessTable` to cause a NULL pointer dereference. Version 5.9.2 contains a patch. Users should use strong SNMPv3 credentials and avoid sharing the credentials. Those who
debian
CVE-2005-4837P4MEDIUMCVSS 5.0fixed in net-snmp 5.2.2-1 (bookworm)2005
CVE-2005-4837 [MEDIUM] CVE-2005-4837: net-snmp - snmp_api.c in snmpd in Net-SNMP 5.2.x before 5.2.2, 5.1.x before 5.1.3, and 5.0.... snmp_api.c in snmpd in Net-SNMP 5.2.x before 5.2.2, 5.1.x before 5.1.3, and 5.0.x before 5.0.10.2, when running in master agentx mode, allows remote attackers to cause a denial of service (crash) by causing a particular TCP disconnect, which triggers a free of an incorrect variable, a different vulnerability than CVE-2005-2177. Scope: local bookworm: resolved (fixe
debian