Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Rsyslog

First CVE: Sep 27, 2005Active for: 21 yearsTotal CVEs: 19
41.8
VTI Score
High

Rsyslog is a widely deployed open-source logging daemon and its associated libraries that handle syslog processing across servers and infrastructure, sitting deep in observability pipelines. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, driven by the product's memory-management demands and its exposure through network-facing input handling and buffer-boundary operations. The recurring weakness classes—resource leaks, buffer overflows and out-of-bounds writes, and input-size validation gaps—are characteristic of C-based system software operating at the protocol parsing layer. Defenders should monitor this vendor's advisories for memory-safety disclosures affecting logging infrastructure; live exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
19
Total CVEs
More Total CVEs than 96% of tracked vendors
0.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 50% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Rsyslog over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 27, 2005
20 years ago
Most Recent CVE
May 6, 2022
1,540 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (19 CVEs).

19 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2011-3200MEDIUM
Stack-based buffer overflow in the parseLegacySyslogMsg function in tools/syslogd.c in rsyslogd in rsyslog 4.6.x before 4.6.8 and 5.2.0 through 5.8.4 might allow remote attackers t
Sep 6, 20115.038NOYES
CVE-2018-1000140CRITICAL
rsyslog librelp version 1.2.14 and earlier contains a Buffer Overflow vulnerability in the checking of x509 certificates from a peer that can result in Remote code execution. This
Mar 23, 20189.835NONO
CVE-2019-17041CRITICAL
An issue was discovered in Rsyslog v8.1908.0. contrib/pmaixforwardedfrom/pmaixforwardedfrom.c has a heap overflow in the parser for AIX log messages. The parser tries to locate a l
Oct 7, 20199.832NONO
CVE-2019-17042CRITICAL
An issue was discovered in Rsyslog v8.1908.0. contrib/pmcisconames/pmcisconames.c has a heap overflow in the parser for Cisco log messages. The parser tries to locate a log message
Oct 7, 20199.831NONO
CVE-2019-17040CRITICAL
contrib/pmdb2diag/pmdb2diag.c in Rsyslog v8.1908.0 allows out-of-bounds access because the level length is mishandled.
Sep 30, 20199.829NONO
CVE-2022-24903HIGH
Rsyslog is a rocket-fast system for log processing. Modules for TCP syslog reception have a potential heap buffer overflow when octet-counted framing is used. This can result in a
May 6, 20228.128NONO
CVE-2018-16881HIGH
A denial of service vulnerability was found in rsyslog in the imptcp module. An attacker could send a specially crafted message to the imptcp socket, which would cause rsyslog to c
Jan 25, 20197.526NONO
CVE-2017-12588CRITICAL
The zmq3 input and output modules in rsyslog before 8.28.0 interpreted description fields as format strings, possibly allowing a format string attack with unspecified impact.
Aug 6, 20179.825NONO
CVE-2014-3634HIGH
rsyslog before 7.6.6 and 8.x before 8.4.1 and sysklogd 1.5 and earlier allows remote attackers to cause a denial of service (crash), possibly execute arbitrary code, or have other
Nov 2, 20147.522NONO
CVE-2008-5617HIGH
The ACL handling in rsyslog 3.12.1 to 3.20.0, 4.1.0, and 4.1.1 does not follow $AllowedSender directive, which allows remote attackers to bypass intended access restrictions and sp
Dec 17, 20088.522NONO
View all 19 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products19 CVEs
42%
26%
26%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local4 (21.1%)
Network7 (36.8%)
Unknown8 (42.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (52.6%)
High1 (5.3%)
Unknown8 (42.1%)
User Interaction
None11 (57.9%)
Unknown8 (42.1%)
Required0 (0.0%)
Privileges Required
Low4 (21.1%)
High0 (0.0%)
None7 (36.8%)
Unknown8 (42.1%)

Exploit Exposure

Signals from CVEs in this vendor scope (19 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
5.3% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Rsyslog.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Rsyslog — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Rsyslog's Products

View all 3 CNAs →

Top CWEs