Syslog Ng
Vendor:
First CVE: Oct 28, 2002 · Active for 23 years
7
Total CVEs
More Total CVEs than 83% of tracked products
1.2
Avg CVEs / Year
Higher CVE frequency than 55% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 45% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Syslog Ng over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 28, 2002
23 years ago
Most Recent CVE
May 7, 2025
444 days ago
CVE Severity & Scoring
Syslog Ng7 CVEs
29%
71%
All CVEs352,427 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local1 (14.3%)
Network2 (28.6%)
Unknown4 (57.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (42.9%)
High0 (0.0%)
Unknown4 (57.1%)
User Interaction
None3 (42.9%)
Unknown4 (57.1%)
Required0 (0.0%)
Privileges Required
Low1 (14.3%)
High0 (0.0%)
None2 (28.6%)
Unknown4 (57.1%)
Top CVEs
Signals from CVEs in this product scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-5110HIGH syslog-ng does not call chdir when it calls chroot, which might allow attackers to escape the intended jail. NOTE: this is only a vulnerability when a separate vulnerability is pre | Nov 17, 2008 | 9.3 | 27 | NO | NO |
CVE-2020-8019HIGH A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of syslog-ng of SUSE Linux Enterprise Debuginfo 11-SP3, SUSE Linux Enterprise Debuginfo 11-SP4, SUSE Linux E | Jun 29, 2020 | 7.8 | 26 | NO | NO |
CVE-2022-38725HIGH An integer overflow in the RFC3164 parser in One Identity syslog-ng 3.0 through 3.37 allows remote attackers to cause a Denial of Service via crafted syslog input that is mishandle | Jan 23, 2023 | 7.5 | 25 | NO | NO |
CVE-2024-47619HIGH syslog-ng is an enhanced log daemo. Prior to version 4.8.2, `tls_wildcard_match()` matches on certificates such as `foo.*.bar` although that is not allowed. It is also possible to | May 7, 2025 | 7.5 | 22 | NO | NO |
CVE-2002-1200HIGH Balabit Syslog-NG 1.4.x before 1.4.15, and 1.5.x before 1.5.20, when using template filenames or output, does not properly track the size of a buffer when constant characters are e | Oct 28, 2002 | 7.5 | 22 | NO | NO |
CVE-2011-0343MEDIUM Balabit syslog-ng 2.0, 3.0, 3.1, 3.2 OSE and PE, when running on FreeBSD or HP-UX, does not properly perform cast operations, which causes syslog-ng to use a default value of -1 to | Jan 28, 2011 | 6.9 | 21 | NO | NO |
CVE-2011-1951MEDIUM lib/logmatcher.c in Balabit syslog-ng before 3.2.4, when the global flag is set and when using PCRE 8.12 and possibly other versions, allows remote attackers to cause a denial of s | Jul 11, 2011 | 4.3 | 17 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (7 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (7 CVEs).
Media Mentions
Signals from CVEs in this product scope (7 CVEs).
Top CNAs Publishing CVEs For Syslog Ng
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.2 | 1 | 6.9 | 0.4% | 0 | 0 |
| 3.1 | 1 | 6.9 | 0.4% | 0 | 0 |
| 3.0 | 1 | 6.9 | 0.4% | 0 | 0 |
| 2.0 | 1 | 6.9 | 0.4% | 0 | 0 |
| 1.5.20 | 1 | 7.5 | 5.6% | 0 | 0 |
| 1.5.15 | 1 | 7.5 | 5.6% | 0 | 0 |
| 1.4.9 | 1 | 7.5 | 5.6% | 0 | 0 |
| 1.4.8 | 1 | 7.5 | 5.6% | 0 | 0 |
| 1.4.7 | 1 | 7.5 | 5.6% | 0 | 0 |
| 1.4.15 | 1 | 7.5 | 5.6% | 0 | 0 |
| 1.4.10 | 1 | 7.5 | 5.6% | 0 | 0 |
| 1.4.0 | 1 | 7.5 | 5.6% | 0 | 0 |