Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
50 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.1) | 81% | — | Thekelleys DnsmasqFedoraproject FedoraDebian Linux | 20/1/2021 | 17/6/2026 | A flaw was found in dnsmasq before version 2.83. A heap-based buffer overflow was discovered in the way RRSets are sorted before validating with DNSSEC data. An attacker on the network, who can forge DNS replies such as that they are accepted as valid, could use this flaw to cause a buffer overflow with arbitrary data… | |
| Modificada | Baja (3.7) | 2.2% | — | Thekelleys DnsmasqFedoraproject FedoraDebian LinuxArista EOS | 20/1/2021 | 17/6/2026 | A flaw was found in dnsmasq before version 2.83. When getting a reply from a forwarded query, dnsmasq checks in forward.c:reply_query(), which is the forwarded query that matches the reply, by only using a weak hash of the query name. Due to the weak hash (CRC32 when dnsmasq is compiled without DNSSEC, SHA-1 when it… | |
| Modificada | Baja (3.7) | 4.0% | — | Thekelleys DnsmasqFedoraproject FedoraDebian LinuxArista EOS | 20/1/2021 | 17/6/2026 | A flaw was found in dnsmasq before version 2.83. When getting a reply from a forwarded query, dnsmasq checks in the forward.c:reply_query() if the reply destination address/port is used by the pending forwarded queries. However, it does not use the address/port to retrieve the exact forwarded query, substantially… | |
| Modificada | Media (5.9) | 86% | — | Thekelleys DnsmasqFedoraproject FedoraDebian Linux | 20/1/2021 | 17/6/2026 | A flaw was found in dnsmasq before version 2.83. A heap-based buffer overflow was discovered in dnsmasq when DNSSEC is enabled and before it validates the received DNS entries. A remote attacker, who can create valid DNS replies, could use this flaw to cause an overflow in a heap-allocated memory. This flaw is caused… | |
| Modificada | Baja (3.7) | 2.7% | — | Thekelleys DnsmasqFedoraproject Fedora | 7/1/2020 | 17/6/2026 | A vulnerability was found in dnsmasq before version 2.81, where the memory leak allows remote attackers to cause a denial of service (memory consumption) via vectors involving DHCP response creation. | |
| Modificada | Alta (7.5) | 1.7% | — | Thekelleys DnsmasqDebian Linux | 1/8/2019 | 17/6/2026 | Improper bounds checking in Dnsmasq before 2.76 allows an attacker controlled DNS server to send large DNS packets that result in a read operation beyond the buffer allocated for the packet, a different vulnerability than CVE-2017-14491. | |
| Modificada | Alta (7.5) | 2.6% | — | Thekelleys Dnsmasq | 23/1/2018 | 17/6/2026 | A vulnerability was found in the implementation of DNSSEC in Dnsmasq up to and including 2.78. Wildcard synthesized NSEC records could be improperly interpreted to prove the non-existence of hostnames that actually exist. | |
| Modificada | Crítica (9.8) | 85% | 💥 Exploit | Thekelleys DnsmasqRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+17 | 4/10/2017 | 17/6/2026 | Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response. | |
| Modificada | Alta (7.5) | 66% | 💥 Exploit | Canonical Ubuntu LinuxDebian LinuxGoogle AndroidNovell Leap+4 | 3/10/2017 | 17/6/2026 | Integer underflow in the add_pseudoheader function in dnsmasq before 2.78 , when the --add-mac, --add-cpe-id or --add-subnet option is specified, allows remote attackers to cause a denial of service via a crafted DNS request. | |
| Modificada | Alta (7.5) | 84% | 💥 Exploit | Canonical Ubuntu LinuxDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+2 | 3/10/2017 | 17/6/2026 | Memory leak in dnsmasq before 2.78, when the --add-mac, --add-cpe-id or --add-subnet option is specified, allows remote attackers to cause a denial of service (memory consumption) via vectors involving DNS response creation. | |
| Modificada | Media (5.9) | 68% | 💥 Exploit | Canonical Ubuntu LinuxDebian LinuxNovell LeapRedhat Enterprise Linux Desktop+3 | 3/10/2017 | 17/6/2026 | dnsmasq before 2.78, when configured as a relay, allows remote attackers to obtain sensitive memory information via vectors involving handling DHCPv6 forwarded requests. | |
| Modificada | Crítica (9.8) | 84% | 💥 Exploit | Canonical Ubuntu LinuxDebian LinuxOpensuse LeapRedhat Enterprise Linux Desktop+3 | 3/10/2017 | 17/6/2026 | Stack-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DHCPv6 request. | |
| Modificada | Crítica (9.8) | 93% | 💥 Exploit | Canonical Ubuntu LinuxDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+2 | 3/10/2017 | 17/6/2026 | Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted IPv6 router advertisement request. | |
| Modificada | Alta (7.5) | 65% | — | Canonical Ubuntu LinuxDebian LinuxFedoraproject FedoraNovell Leap+4 | 3/10/2017 | 17/6/2026 | In dnsmasq before 2.78, if the DNS packet size does not match the expected size, the size parameter in a memset call gets a negative value. As it is an unsigned value, memset ends up writing up to 0xffffffff zero's (0xffffffffffffffff in 64 bit platforms), making dnsmasq crash. | |
| Modificada | Alta (7.5) | 2.4% | — | Canonical Ubuntu LinuxThekelleys Dnsmasq | 30/6/2016 | 17/6/2026 | Dnsmasq before 2.76 allows remote servers to cause a denial of service (crash) via a reply with an empty DNS address that has an (1) A or (2) AAAA record defined locally. | |
| Modificada | Media (6.4) | 4.4% | — | Thekelleys DnsmasqOracle Solaris | 8/5/2015 | 17/6/2026 | The tcp_request function in Dnsmasq before 2.73rc4 does not properly handle the return value of the setup_reply function, which allows remote attackers to read process memory and cause a denial of service (out-of-bounds read and crash) via a malformed DNS request. | |
| Modificada | Media (5) | 2.8% | — | Thekelleys Dnsmasq | 5/3/2013 | 16/6/2026 | Dnsmasq before 2.66test2, when used with certain libvirt configurations, replies to queries from prohibited interfaces, which allows remote attackers to cause a denial of service (traffic amplification) via spoofed TCP based DNS queries. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-3411. | |
| Modificada | Media (5) | 5.0% | — | Thekelleys DnsmasqRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation | 5/3/2013 | 16/6/2026 | Dnsmasq before 2.63test1, when used with certain libvirt configurations, replies to requests from prohibited interfaces, which allows remote attackers to cause a denial of service (traffic amplification) via a spoofed DNS query. | |
| Modificada | Media (4.3) | 10% | 💥 Exploit | Thekelleys Dnsmasq | 2/9/2009 | 16/6/2026 | The tftp_request function in tftp.c in dnsmasq before 2.50, when --enable-tftp is used, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a TFTP read (aka RRQ) request with a malformed blksize option. | |
| Modificada | Media (6.8) | 13% | 💥 Exploit | Thekelleys Dnsmasq | 2/9/2009 | 16/6/2026 | Heap-based buffer overflow in the tftp_request function in tftp.c in dnsmasq before 2.50, when --enable-tftp is used, might allow remote attackers to execute arbitrary code via a long filename in a TFTP packet, as demonstrated by a read (aka RRQ) request. | |
| Modificada | Media (5) | 1.7% | — | THE Kelleys Dnsmasq | 28/7/2008 | 16/6/2026 | dnsmasq 2.43 allows remote attackers to cause a denial of service (daemon crash) by (1) sending a DHCPINFORM while lacking a DHCP lease, or (2) attempting to renew a nonexistent DHCP lease for an invalid subnet as an "unknown client," a different vulnerability than CVE-2008-3214. | |
| Modificada | Alta (7.8) | 2.5% | — | Thekelleys Dnsmasq | 18/7/2008 | 16/6/2026 | dnsmasq 2.25 allows remote attackers to cause a denial of service (daemon crash) by (1) renewing a nonexistent lease or (2) sending a DHCPREQUEST for an IP address that is not in the same network, related to the DHCP NAK response from the daemon. | |
| Modificada | Media (5) | 1.8% | — | Dnsmasq | 25/4/2006 | 16/6/2026 | Dnsmasq 2.29 allows remote attackers to cause a denial of service (application crash) via a DHCP client broadcast reply request. | |
| Modificada | Media (5) | 2.6% | — | Dnsmasq | 2/5/2005 | 16/6/2026 | Off-by-one buffer overflow in Dnsmasq before 2.21 may allow attackers to execute arbitrary code via the DHCP lease file. | |
| Modificada | Alta (7.5) | 1.9% | — | Thekelleys Dnsmasq | 2/5/2005 | 16/6/2026 | Dnsmasq before 2.21 allows remote attackers to poison the DNS cache via answers to queries that were not made by Dnsmasq. |