Known vulnerabilities in syslog-ng
Vendor:
One Identity
Software:
syslog-ng
Software CPE:
cpe:2.3:a:one_identity:syslog-ng:*:*:*:*:*:*:*:*
Website:
https://www.oneidentity.com/
Total vulnerabilities:
3
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.8
Breakdown by Severity Chart
4.12.0
4.11.0
4.10.2
4.10.1
4.10.0
4.9.0
4.8.3
4.8.2
4.8.1
4.8.0
4.7.1
4.7.0
4.6.0
4.5.0
4.4.0
4.3.1
4.3.0
4.2.0
4.1.1
4.1.0
4.0.1
4.0.0
3.38.1
3.37.1
3.36.1
3.35.1
3.34.1
3.33.2
3.33.1
3.32.1
3.31.2
3.31.1
3.30.1
3.29.1
3.28.1
3.27.1
3.26.1
3.25.1
3.24.1
3.23.1
3.22.1
3.21.1
3.20.1
3.19.1
3.18.1
3.17.2
3.17.1
3.16.1
3.15.1
3.14.1
3.13.2
3.13.1
3.12.1
3.11.1
3.10.1
3.9.1
3.8.1
3.7.3
3.7.2
3.7.1
3.6.4
3.6.3
3.6.2
3.6.1
Vulnerabilities (3)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU134679 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CVE-2026-39879 |
CWE-89 | Medium | 4.12.0 | 16.06.2026 |
SB2026061686 |
||
| #VU108768 - Improper Neutralization of Wildcards or Matching Symbols CVE-2024-47619 |
CWE-155 | Medium | 4.8.2 | 07.05.2025 |
SB2025050772 SB2025050852 SB2025050853 and 6 more |
||
| #VU72142 - Integer overflow CVE-2022-38725 |
CWE-190 | Medium | 3.38.1 | 13.02.2023 |
SB2023021324 SB2023021325 SB2023030629 and 7 more |