peter bassill · operator
$ cve CVE-2016-8704 JSON

CVE-2016-8704

9.8
CRITICAL · CVSS 3.0 · EPSS 23.2% (pctl 98)

Patch early

EPSS 23.2% — above the 10% action threshold.

Description

An integer overflow in the process_bin_append_prepend function in Memcached, which is responsible for processing multiple commands of Memcached binary protocol, can be abused to cause heap overflow and lead to remote code execution.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS23.17% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-190
On CISA KEVno
Public exploitnone known
Published2017-01-06
Last modified2026-06-17

Affected (1)

VendorProduct
memcachedmemcached

References

→ the Explorer  ·  watch your stack  ·  NVD