Known vulnerabilities in mosquitto (Debian package)
Vendor:
Debian
Software:
mosquitto (Debian package)
Software CPE:
cpe:2.3:o:debian:mosquitto_debian_package:*:*:*:*:*:debian_linux:*:*
Website:
https://www.debian.org/
Total vulnerabilities:
9
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.8
Breakdown by Severity Chart
1.4.10-3+deb9u5
2.0.7-1
2.0.7-2
2.0.7-3
2.0.8-1
2.0.9-1
2.0.10-1
2.0.10-2
2.0.10-3
2.0.10-4
2.0.10-5
2.0.10-6
2.0.11-1
2.0.11-1+deb11u2
2.0.11-1.1
2.0.11-1.2
2.0.11-1.2+deb12u2
2.0.15-1
2.0.15-2~bpo12+1
2.0.15-2
2.0.17-1
2.0.17-2
2.0.17-3
2.0.18-1~bpo12+1
2.0.18-1
2.0.18-1.1
2.0.20-1~bpo12+1
2.0.20-1
2.0.20-2
2.0.20-3
2.0.21-1~bpo12+1
2.0.21-1
2.0.22-1
2.0.22-2
2.0.11-1.2+deb12u1
2.0.11-1+deb11u1
1.6.12
1.6.12-1
1.6.9-1+b1
1.6.9
1.5.7
1.4.10
1.3.4
1.6.9-1
1.6.8-2
1.6.8-1
1.6.8-1~exp3
1.6.8-1~exp2
1.6.8-1~exp1
1.5.7-1+deb10u1
1.3.4-2+deb8u4
1.6.7-1
1.6.6-1
1.5.7-1
1.6.4-1
1.4.10-3+deb9u4
1.5.6-1
1.4.10-3+deb9u3
1.5.5-1
1.5.5-1.1
1.5.4-1
1.4.10-3+deb9u2
1.3.4-2+deb8u3
0.15-2+deb7u1
0.15-2+deb7u2
0.15-2+deb7u3
1.3.4-2+deb8u2
1.4.15-2
1.4.15-1
1.4.14-2
1.4.14-1
1.4.10-3+deb9u1
1.3.4-2+deb8u1
0.15-2
0.10-1
0.11.3-1
0.12-1
0.15-1
1.2-1
1.2.1-1
1.3.4-1
1.3.4-2
1.4.3-1
1.4.4-1
1.4.7-1
1.4.8-1
1.4.10-1
1.4.10-2
1.4.10-3
1.4.12-1
Vulnerabilities (9)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU79938 - Missing release of memory after effective lifetime CVE-2023-3592 |
CWE-401 | Medium | 2.0.11-1+deb11u1, 2.0.11-1.2+deb12u1 | 24.08.2023 |
SB2023082416 SB2023082419 SB2023082420 and 15 more |
||
| #VU79937 - Resource exhaustion CVE-2023-0809 |
CWE-400 | Medium | 2.0.11-1+deb11u1, 2.0.11-1.2+deb12u1 | 24.08.2023 |
SB2023082416 SB2023082419 SB2023082420 and 12 more |
||
| #VU79936 - Missing release of memory after effective lifetime CVE-2023-28366 |
CWE-401 | Medium | 2.0.11-1+deb11u1, 2.0.11-1.2+deb12u1 | 24.08.2023 |
SB2023082416 SB2023082419 SB2023082420 and 13 more |
||
| #VU58484 - Improper input validation CVE-2021-41039 |
CWE-20 | Medium | 2.0.11-1+deb11u1, 2.0.11-1.2+deb12u1 | 02.12.2021 |
SB2021120206 SB2023042751 SB2023100231 and 4 more |
||
| #VU56273 - Improper Authorization CVE-2021-34434 |
CWE-285 | Medium | 2.0.11-1+deb11u1, 2.0.11-1.2+deb12u1 | 02.09.2021 |
SB2021090206 SB2023100231 SB2023112143 and 4 more |
||
| #VU21405 - Stack-based buffer overflow CVE-2019-11779 |
CWE-121 | Low | 1.5.7-1+deb10u1 | 29.09.2019 |
SB2019092905 SB2019092906 SB2019100403 and 6 more |
||
| #VU17467 - Improper input validation CVE-2018-12551 |
CWE-20 | Low | 1.4.10-3+deb9u3 | 11.02.2019 |
SB2019021103 SB2019021104 SB2019022303 and 5 more |
||
| #VU17466 - Permissions, Privileges, and Access Controls CVE-2018-12550 |
CWE-264 | Medium | 1.4.10-3+deb9u3 | 11.02.2019 |
SB2019021103 SB2019021104 SB2019022303 and 5 more |
||
| #VU17464 - Permissions, Privileges, and Access Controls CVE-2018-12546 |
CWE-264 | Low | 1.4.10-3+deb9u3 | 11.02.2019 |
SB2019021103 SB2019021104 SB2019022303 and 5 more |