Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
72 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 1.4% | — | Dhcpcd Project DhcpcdDebian Linux | 28/4/2019 | 17/6/2026 | dhcp.c in dhcpcd before 7.2.1 contains a 1-byte read overflow with DHO_OPTSOVERLOADED. | |
| Modificada | Media (5.9) | 2.0% | — | Dhcpcd Project Dhcpcd | 28/4/2019 | 17/6/2026 | auth.c in dhcpcd before 7.2.1 allowed attackers to infer secrets by performing latency attacks. | |
| Modificada | Crítica (9.8) | 53% | — | Dhcpcd Project Dhcpcd | 28/4/2019 | 17/6/2026 | dhcpcd before 7.2.1 contains a buffer overflow in dhcp6_findna in dhcp6.c when reading NA/TA addresses. | |
| Modificada | Alta (7.5) | 20% | — | ISC DhcpRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+4 | 16/1/2019 | 17/6/2026 | A malicious client which is allowed to send very large amounts of traffic (billions of packets) to a DHCP server can eventually overflow a 32-bit reference counter, potentially causing dhcpd to crash. Affects ISC DHCP 4.1.0 -> 4.1-ESV-R15, 4.2.0 -> 4.2.8, 4.3.0 -> 4.3.6, 4.4.0. | |
| Modificada | Alta (7.5) | 73% | — | ISC DhcpRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+5 | 16/1/2019 | 17/6/2026 | A vulnerability stemming from failure to properly clean up closed OMAPI connections can lead to exhaustion of the pool of socket descriptors available to the DHCP server. Affects ISC DHCP 4.1.0 to 4.1-ESV-R15, 4.2.0 to 4.2.8, 4.3.0 to 4.3.6. Older versions may also be affected but are well beyond their end-of-life… | |
| Modificada | Alta (7.5) | 2.9% | — | Dhcpcd Project Dhcpcd | 7/2/2017 | 17/6/2026 | dhcpcd before 6.10.0 allows remote attackers to cause a denial of service (invalid read and crash) via vectors related to the option length. | |
| Modificada | Crítica (9.8) | 6.3% | — | Dhcpcd Project DhcpcdGoogle Android | 18/4/2016 | 17/6/2026 | dhcpcd before 6.10.0, as used in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 and other products, mismanages option lengths, which allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow) via a malformed DHCP response,… | |
| Modificada | Alta (7.5) | 2.0% | — | Debian LinuxDhcpcd Project Dhcpcd | 11/4/2016 | 16/6/2026 | The decode_search function in dhcp.c in dhcpcd 3.x does not properly free allocated memory, which allows remote DHCP servers to cause a denial of service via a crafted response. | |
| Modificada | Alta (7.5) | 2.0% | — | Debian LinuxDhcpcd Project Dhcpcd | 11/4/2016 | 16/6/2026 | The decode_search function in dhcp.c in dhcpcd 3.x allows remote DHCP servers to cause a denial of service (out-of-bounds read) via a crafted response. | |
| Modificada | Alta (7.5) | 2.0% | — | Debian LinuxDhcpcd Project Dhcpcd | 11/4/2016 | 16/6/2026 | The decode_search function in dhcp.c in dhcpcd 3.x allows remote DHCP servers to cause a denial of service (out-of-bounds write) via a crafted response. | |
| Modificada | Media (5.9) | 74% | — | ISC DhcpDebian LinuxCanonical Ubuntu Linux | 9/3/2016 | 17/6/2026 | ISC DHCP 4.1.x before 4.1-ESV-R13 and 4.2.x and 4.3.x before 4.3.4 does not restrict the number of concurrent TCP sessions, which allows remote attackers to cause a denial of service (INSIST assertion failure or request-processing outage) by establishing many sessions. | |
| Modificada | Media (6.5) | 83% | — | Sophos Unified Threat Management Up2dateISC DhcpDebian LinuxCanonical Ubuntu Linux | 14/1/2016 | 17/6/2026 | ISC DHCP 4.x before 4.1-ESV-R12-P1, 4.2.x, and 4.3.x before 4.3.3-P1 allows remote attackers to cause a denial of service (application crash) via an invalid length field in a UDP IPv4 packet. | |
| Modificada | Media (6.8) | 1.8% | — | Dhcpcd Project Dhcpcd | 30/7/2015 | 17/6/2026 | The print_option function in dhcp-common.c in dhcpcd through 6.9.1, as used in dhcp.c in dhcpcd 5.x in Android before 5.1 and other products, misinterprets the return value of the snprintf function, which allows remote DHCP servers to execute arbitrary code or cause a denial of service (memory corruption) via a… | |
| Modificada | Media (6.8) | 2.7% | 💥 PoC | Dhcpcd Project Dhcpcd | 30/7/2015 | 17/6/2026 | The get_option function in dhcp.c in dhcpcd before 6.2.0, as used in dhcpcd 5.x in Android before 5.1 and other products, does not validate the relationship between length fields and the amount of data, which allows remote DHCP servers to execute arbitrary code or cause a denial of service (memory corruption) via a… | |
| Modificada | Baja (3.3) | 0.44% | — | Dhcpcd Project DhcpcdGoogle Android | 4/9/2014 | 17/6/2026 | The get_option function in dhcpcd 4.0.0 through 6.x before 6.4.3 allows remote DHCP servers to cause a denial of service by resetting the DHO_OPTIONSOVERLOADED option in the (1) bootfile or (2) servername section, which triggers the option to be processed again. | |
| Modificada | Media (4.9) | 1.2% | — | ISC Dhcp | 28/3/2013 | 16/6/2026 | libdns in ISC DHCP 4.2.x before 4.2.5-P1 allows remote name servers to cause a denial of service (memory consumption) via vectors involving a regular expression, as demonstrated by a memory-exhaustion attack against a machine running a dhcpd process, a related issue to CVE-2013-2266. | |
| Modificada | Alta (7.1) | 22% | — | ISC DhcpDebian LinuxCanonical Ubuntu Linux | 14/9/2012 | 16/6/2026 | ISC DHCP 4.1.x before 4.1-ESV-R7 and 4.2.x before 4.2.4-P2 allows remote attackers to cause a denial of service (daemon crash) in opportunistic circumstances by establishing an IPv6 lease in an environment where the lease expiration time is later reduced. | |
| Modificada | Alta (7.5) | 4.0% | — | ROY Marples Dhcpcd | 25/7/2012 | 16/6/2026 | Stack-based buffer overflow in the get_packet method in socket.c in dhcpcd 3.2.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long packet. | |
| Modificada | Baja (3.3) | 4.3% | — | ISC DhcpDebian LinuxCanonical Ubuntu Linux | 25/7/2012 | 16/6/2026 | Multiple memory leaks in ISC DHCP 4.1.x and 4.2.x before 4.2.4-P1 and 4.1-ESV before 4.1-ESV-R6 allow remote attackers to cause a denial of service (memory consumption) by sending many requests. | |
| Modificada | Media (6.1) | 13% | 💥 Exploit | ISC DhcpCanonical Ubuntu LinuxDebian Linux | 25/7/2012 | 16/6/2026 | ISC DHCP 4.1.2 through 4.2.4 and 4.1-ESV before 4.1-ESV-R6 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a malformed client identifier. | |
| Modificada | Media (5.7) | 2.6% | — | ISC Dhcp | 25/7/2012 | 16/6/2026 | Buffer overflow in ISC DHCP 4.2.x before 4.2.4-P1, when DHCPv6 mode is enabled, allows remote attackers to cause a denial of service (segmentation fault and daemon exit) via a crafted client identifier parameter. | |
| Modificada | Media (6.1) | 3.4% | — | ISC Dhcp | 15/1/2012 | 16/6/2026 | The logging functionality in dhcpd in ISC DHCP before 4.2.3-P2, when using Dynamic DNS (DDNS) and issuing IPv6 addresses, does not properly handle the DHCPv6 lease structure, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via crafted packets related to a… | |
| Modificada | Media (5) | 15% | — | ISC DhcpCanonical Ubuntu LinuxDebian Linux | 8/12/2011 | 16/6/2026 | dhcpd in ISC DHCP 4.x before 4.2.3-P1 and 4.1-ESV before 4.1-ESV-R4 does not properly handle regular expressions in dhcpd.conf, which allows remote attackers to cause a denial of service (daemon crash) via a crafted request packet. | |
| Modificada | Alta (7.8) | 39% | — | ISC DhcpDebian LinuxCanonical Ubuntu Linux | 15/8/2011 | 16/6/2026 | The server in ISC DHCP 3.x and 4.x before 4.2.2, 3.1-ESV before 3.1-ESV-R3, and 4.1-ESV before 4.1-ESV-R3 allows remote attackers to cause a denial of service (daemon exit) via a crafted BOOTP packet. | |
| Modificada | Alta (7.8) | 39% | — | ISC DhcpCanonical Ubuntu LinuxDebian Linux | 15/8/2011 | 16/6/2026 | The server in ISC DHCP 3.x and 4.x before 4.2.2, 3.1-ESV before 3.1-ESV-R3, and 4.1-ESV before 4.1-ESV-R3 allows remote attackers to cause a denial of service (daemon exit) via a crafted DHCP packet. |