Balabit specializes in syslog-ng, a widely deployed log collection and processing platform used for centralized event management across enterprise infrastructures. Its vulnerability footprint centers on the core syslog-ng product and recurs through input-validation weaknesses inherent to message parsing in a log aggregation tool. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Balabit over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-6437MEDIUM Balabit syslog-ng 2.0.x before 2.0.6 and 2.1.x before 2.1.8 allows remote attackers to cause a denial of service (crash) via a message with a timestamp that does not contain a trai | Dec 19, 2007 | 5.0 | 16 | NO | NO |
CVE-2000-1165MEDIUM Balabit syslog-ng allows remote attackers to cause a denial of service (application crash) via a malformed log message that does not have a closing > in the priority specifier. | Jan 9, 2001 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Balabit.
Media articles that mention a CVE ID that affects a product developed by Balabit — matched by CVE ID, not by vendor name.