VYPR

Dnsmasq

by Thekelleys

CVEs (50)

  • CVE-2019-14834LowJan 7, 2020
    risk 0.24cvss 3.7epss 0.03

    A vulnerability was found in dnsmasq before version 2.81, where the memory leak allows remote attackers to cause a denial of service (memory consumption) via vectors involving DHCP response creation.

  • CVE-2009-2958Sep 2, 2009
    risk 0.04cvss epss 0.10

    The tftp_request function in tftp.c in dnsmasq before 2.50, when --enable-tftp is used, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a TFTP read (aka RRQ) request with a malformed blksize option.

  • CVE-2009-2957Sep 2, 2009
    risk 0.04cvss epss 0.13

    Heap-based buffer overflow in the tftp_request function in tftp.c in dnsmasq before 2.50, when --enable-tftp is used, might allow remote attackers to execute arbitrary code via a long filename in a TFTP packet, as demonstrated by a read (aka RRQ) request.

  • CVE-2015-3294May 8, 2015
    risk 0.00cvss epss 0.04

    The tcp_request function in Dnsmasq before 2.73rc4 does not properly handle the return value of the setup_reply function, which allows remote attackers to read process memory and cause a denial of service (out-of-bounds read and crash) via a malformed DNS request.

  • CVE-2013-0198Mar 5, 2013
    risk 0.00cvss epss 0.03

    Dnsmasq before 2.66test2, when used with certain libvirt configurations, replies to queries from prohibited interfaces, which allows remote attackers to cause a denial of service (traffic amplification) via spoofed TCP based DNS queries. NOTE: this vulnerability exists because…

  • CVE-2012-3411Mar 5, 2013
    risk 0.00cvss epss 0.05

    Dnsmasq before 2.63test1, when used with certain libvirt configurations, replies to requests from prohibited interfaces, which allows remote attackers to cause a denial of service (traffic amplification) via a spoofed DNS query.

  • CVE-2008-3350Jul 28, 2008
    risk 0.00cvss epss 0.02

    dnsmasq 2.43 allows remote attackers to cause a denial of service (daemon crash) by (1) sending a DHCPINFORM while lacking a DHCP lease, or (2) attempting to renew a nonexistent DHCP lease for an invalid subnet as an "unknown client," a different vulnerability than CVE-2008-3214.

  • CVE-2008-3214Jul 18, 2008
    risk 0.00cvss epss 0.03

    dnsmasq 2.25 allows remote attackers to cause a denial of service (daemon crash) by (1) renewing a nonexistent lease or (2) sending a DHCPREQUEST for an IP address that is not in the same network, related to the DHCP NAK response from the daemon.

  • CVE-2006-2017Apr 25, 2006
    risk 0.00cvss epss 0.02

    Dnsmasq 2.29 allows remote attackers to cause a denial of service (application crash) via a DHCP client broadcast reply request.

  • CVE-2005-0876May 2, 2005
    risk 0.00cvss epss 0.03

    Off-by-one buffer overflow in Dnsmasq before 2.21 may allow attackers to execute arbitrary code via the DHCP lease file.

Page 3 of 3