OpenSLP is a service-location protocol implementation that, despite a narrow product footprint, occupies a prominent position in enterprise network infrastructure where it enables service discovery across distributed systems. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and have an elevated tendency toward confirmed in-the-wild exploitation, with frequent public exploit availability; the recurring weakness classes—including buffer-boundary violations, double-free conditions, and NULL-pointer dereferences—reflect the memory-safety hazards inherent to the protocol parser and service-lookup logic. Defenders should prioritize tracking and patching this vendor's disclosures where OpenSLP is deployed in network-accessible environments; live exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openslp over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-5544CRITICAL OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Critical severity range with a maxi | Dec 6, 2019 | 9.8 | 97 | YES | YES |
CVE-2016-7567CRITICAL Buffer overflow in the SLPFoldWhiteSpace function in common/slp_compare.c in OpenSLP 2.0 allows remote attackers to have unspecified impact via a crafted string. | Jan 23, 2017 | 9.8 | 48 | NO | YES |
CVE-2010-3609MEDIUM The extension parser in slp_v2message.c in OpenSLP 1.2.1, and other versions before SVN revision 1647, as used in Service Location Protocol daemon (SLPD) in VMware ESX 4.0 and 4.1 | Mar 11, 2011 | 5.0 | 36 | NO | YES |
CVE-2017-17833CRITICAL OpenSLP releases in the 1.0.2 and 1.1.0 code streams have a heap-related memory corruption issue which may manifest itself as a denial-of-service or a remote code-execution vulnera | Apr 23, 2018 | 9.8 | 31 | NO | NO |
CVE-2012-4428HIGH openslp: SLPIntersectStringList()' Function has a DoS vulnerability | Dec 2, 2019 | 7.5 | 28 | NO | NO |
CVE-2016-4912HIGH The _xrealloc function in xlsp_xmalloc.c in OpenSLP 2.0.0 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a large number of crafted pa | Mar 27, 2017 | 7.5 | 26 | NO | NO |
CVE-2015-5177HIGH Double free vulnerability in the SLPDKnownDAAdd function in slpd/slpd_knownda.c in OpenSLP 1.2.1 allows remote attackers to cause a denial of service (crash) via a crafted package. | Oct 22, 2017 | 7.5 | 21 | NO | NO |
CVE-2005-0769HIGH Multiple buffer overflows in OpenSLP before 1.1.5 allow remote attackers to have an unknown impact via malformed SLP packets. | May 2, 2005 | 7.5 | 20 | NO | NO |
Symbolic link vulnerability in the slpd script slpd.all_init for OpenSLP before 1.0.11 allows local users to overwrite arbitrary files via the route.check temporary file. | Nov 17, 2003 | 2.1 | 11 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openslp.
Media articles that mention a CVE ID that affects a product developed by Openslp — matched by CVE ID, not by vendor name.