CVE-2016-8704 is a critical integer overflow vulnerability in the Memcached process_bin_append_prepend function, affecting Memcached versions. This flaw allows for remote code execution due to a heap overflow when processing multiple binary protocol commands. With a CVSS score of 9.8, it is easily exploitable over the network with low attack complexity, leading to complete compromise of confidentiality, integrity, and availability. While no public exploit code or active exploitation is currently reported, the vulnerability has garnered significant community attention and media coverage, indicating its potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.4.31CPE matchmatch criteria | cpe:2.3:a:memcached:memcached:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.