← Vulnerability feed

Vulnerability record · CVE-2016-4912 · published 27 March 2017

CVE-2016-4912: Openslp null pointer dereference vulnerability

Openslp · Openslp

The _xrealloc function in xlsp_xmalloc.c in OpenSLP 2.0.0 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a large number of crafted packets, which triggers a memory allocation failure.

7.5 CVSS 3.0 High EPSS 5.4% · top 7.6% CWE-476 · NULL pointer dereference
7.5CVSS 3.0 base score, v2 5.0
5.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

The _xrealloc function in xlsp_xmalloc.c in OpenSLP 2.0.0 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a large number of crafted packets, which triggers a memory allocation failure.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-4912 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-5544OpenSLP heap out-of-bounds write in VMware ESXi and Horizon DaaSOpenSLP as shipped in VMware ESXi and Horizon DaaS contains a heap overwrite (out-of-bounds write) flaw. VMware rates it Critical with a maximum CVSS…KEVEPSS 97%analysed9.8CVE-2017-17833Openslp memory buffer overflow vulnerabilityOpenSLP releases in the 1.0.2 and 1.1.0 code streams have a heap-related memory corruption issue which may manifest itself as a denial-of-service or …EPSS 3.8%9.8CVE-2016-7567Openslp memory buffer overflow vulnerabilityBuffer overflow in the SLPFoldWhiteSpace function in common/slp_compare.c in OpenSLP 2.0 allows remote attackers to have unspecified impact via a cra…EPSS 12%7.5CVE-2012-4428Openslp out-of-bounds read vulnerabilityopenslp: SLPIntersectStringList()' Function has a DoS vulnerabilityEPSS 9.6%7.5CVE-2015-5177Openslp double free vulnerabilityDouble free vulnerability in the SLPDKnownDAAdd function in slpd/slpd_knownda.c in OpenSLP 1.2.1 allows remote attackers to cause a denial of service…EPSS 6.3%7.5CVE-2005-0769Openslp vulnerabilityMultiple buffer overflows in OpenSLP before 1.1.5 allow remote attackers to have an unknown impact via malformed SLP packets.EPSS 2.6%5.0CVE-2010-3609Openslp vulnerabilityThe extension parser in slp_v2message.c in OpenSLP 1.2.1, and other versions before SVN revision 1647, as used in Service Location Protocol daemon (S…EPSS 17%2.1CVE-2003-0875Openslp vulnerabilitySymbolic link vulnerability in the slpd script slpd.all_init for OpenSLP before 1.0.11 allows local users to overwrite arbitrary files via the route.…EPSS 0.30%

Source: NIST National Vulnerability Database (record CVE-2016-4912), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.