Collectd is a widely embedded systems monitoring daemon used across enterprise infrastructure and cloud environments to collect and aggregate performance metrics, giving its modest disclosure history outsized relevance across many deployments. Its observed vulnerabilities center on memory-safety issues—including double frees, input-validation gaps, buffer boundary violations, and infinite loops—that reflect the low-level, daemon-oriented nature of the codebase. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Collectd over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-6254CRITICAL Heap-based buffer overflow in the parse_packet function in network.c in collectd before 5.4.3 and 5.x before 5.5.2 allows remote attackers to cause a denial of service (daemon cras | Aug 19, 2016 | 9.1 | 32 | NO | NO |
CVE-2017-16820CRITICAL The csnmp_read_table function in snmp.c in the SNMP plugin in collectd before 5.6.3 is susceptible to a double free in a certain error case, which could lead to a crash (or potenti | Nov 14, 2017 | 9.8 | 31 | NO | NO |
CVE-2017-7401HIGH Incorrect interaction of the parse_packet() and parse_part_sign_sha256() functions in network.c in collectd 5.7.1 and earlier allows remote attackers to cause a denial of service ( | Apr 3, 2017 | 7.5 | 26 | NO | NO |
CVE-2017-18240MEDIUM The Gentoo app-admin/collectd package before 5.7.2-r1 sets the ownership of PID file directory to the collectd account, which might allow local users to kill arbitrary processes by | Mar 19, 2018 | 5.5 | 19 | NO | NO |
CVE-2010-4336MEDIUM The cu_rrd_create_file function (src/utils_rrdcreate.c) in collectd 4.x before 4.9.4 and before 4.10.2 allow remote attackers to cause a denial of service (assertion failure) via a | Dec 17, 2010 | 5.0 | 19 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Collectd.
Media articles that mention a CVE ID that affects a product developed by Collectd — matched by CVE ID, not by vendor name.