Syslog Ng

Vendor:

First CVE: Oct 28, 2002 · Active for 23 years

7
Total CVEs
More Total CVEs than 83% of tracked products
1.2
Avg CVEs / Year
Higher CVE frequency than 55% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 45% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Syslog Ng over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 28, 2002
23 years ago
Most Recent CVE
May 7, 2025
444 days ago

CVE Severity & Scoring

Syslog Ng7 CVEs
All CVEs352,427 CVEs
MediumHigh
Attack Vector
Local1 (14.3%)
Network2 (28.6%)
Unknown4 (57.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (42.9%)
High0 (0.0%)
Unknown4 (57.1%)
User Interaction
None3 (42.9%)
Unknown4 (57.1%)
Required0 (0.0%)
Privileges Required
Low1 (14.3%)
High0 (0.0%)
None2 (28.6%)
Unknown4 (57.1%)

Top CVEs

Signals from CVEs in this product scope (7 CVEs).

7 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
syslog-ng does not call chdir when it calls chroot, which might allow attackers to escape the intended jail. NOTE: this is only a vulnerability when a separate vulnerability is pre
Nov 17, 20089.327NONO
A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of syslog-ng of SUSE Linux Enterprise Debuginfo 11-SP3, SUSE Linux Enterprise Debuginfo 11-SP4, SUSE Linux E
Jun 29, 20207.826NONO
An integer overflow in the RFC3164 parser in One Identity syslog-ng 3.0 through 3.37 allows remote attackers to cause a Denial of Service via crafted syslog input that is mishandle
Jan 23, 20237.525NONO
syslog-ng is an enhanced log daemo. Prior to version 4.8.2, `tls_wildcard_match()` matches on certificates such as `foo.*.bar` although that is not allowed. It is also possible to
May 7, 20257.522NONO
Balabit Syslog-NG 1.4.x before 1.4.15, and 1.5.x before 1.5.20, when using template filenames or output, does not properly track the size of a buffer when constant characters are e
Oct 28, 20027.522NONO
Balabit syslog-ng 2.0, 3.0, 3.1, 3.2 OSE and PE, when running on FreeBSD or HP-UX, does not properly perform cast operations, which causes syslog-ng to use a default value of -1 to
Jan 28, 20116.921NONO
lib/logmatcher.c in Balabit syslog-ng before 3.2.4, when the global flag is set and when using PCRE 8.12 and possibly other versions, allows remote attackers to cause a denial of s
Jul 11, 20114.317NONO

Exploit Exposure

Signals from CVEs in this product scope (7 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (7 CVEs).

Media Mentions

Signals from CVEs in this product scope (7 CVEs).

Top CNAs Publishing CVEs For Syslog Ng

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
3.216.90.4%00
3.116.90.4%00
3.016.90.4%00
2.016.90.4%00
1.5.2017.55.6%00
1.5.1517.55.6%00
1.4.917.55.6%00
1.4.817.55.6%00
1.4.717.55.6%00
1.4.1517.55.6%00
1.4.1017.55.6%00
1.4.017.55.6%00