Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2811▼ 173 respecto a la semana anterior
Críticas / altas1356▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)267▼ 256 respecto a la semana anterior
–

50 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.3)0.40%—Redhat Enterprise LinuxThekelleys Dnsmasq23/6/202631/8/2026
An out-of-bounds read vulnerability exists in dnsmasq's find_soa() function in src/rfc1035.c. When parsing NS section records, extract_name() is called with extrabytes=0, failing to validate that 10 additional bytes exist for fixed-length DNS record fields. A remote attacker controlling a DNS zone can exploit this via…
AnalizadaMedia (5.9)0.53%—Redhat Openshift Container PlatformRedhat Enterprise LinuxThekelleys Dnsmasq22/6/202631/8/2026
A heap-based buffer overflow was found in dnsmasq. When DNSSEC validation and query logging are both enabled, logging of DS or DNSKEY replies containing unsupported algorithm or digest types can cause dnsmasq to write past the end of an internal logging buffer. A remote attacker able to supply such a DNS response may…
Pendiente de análisisAlta (7.3)0.69%—DnsmasqAI11/5/202624/8/2026
A buffer overflow in dnsmasq’s extract_addresses() function allows an attacker to trigger a heap out-of-bounds read and crash by exploiting a malformed DNS response, enabling extract_name() to advance the pointer past the record’s end.
Pendiente de análisisMedia (5.3)0.58%—DnsmasqAI11/5/202617/6/2026
An information disclosure vulnerability in dnsmasq allows remote attackers to bypass source checks via a crafted DNS packet with RFC 7871 client subnet information.
Pendiente de análisisAlta (8.4)0.31%—DnsmasqAI11/5/202625/8/2026
A heap-based out-of-bounds write vulnerability in the DHCPv6 implementation of dnsmasq allows local attackers to execute arbitrary code with root privileges via a crafted DHCPv6 packet.
Pendiente de análisisMedia (5.3)0.84%—DnsmasqAI11/5/202625/8/2026
A heap-based out-of-bounds read vulnerability in the DNSSEC validation of dnsmasq allows remote attackers to cause a denial of service via a crafted DNS packet.
Pendiente de análisisAlta (7.5)1.1%—DnsmasqAI11/5/202625/8/2026
A Denial of Service (DoS) vulnerability in the DNSSEC validation of dnsmasq allows remote attackers to cause a denial of service via a crafted DNS packet.
Pendiente de análisisAlta (7.3)0.61%—DnsmasqAI11/5/202620/7/2026
dnsmasqs extract_name() function can be abused to cause a heap buffer overflow, allowing an attacker to inject false DNS cache entries, which could result in DNS lookups to redirect to an attacker-controlled IP address, or to cause a DoS.
Pendiente de análisisAlta (7.5)0.58%—DnsmasqAI17/4/20261/9/2026
A flaw was found in dnsmasq. A remote attacker could exploit an out-of-bounds write vulnerability by sending a specially crafted BOOTREPLY (Bootstrap Protocol Reply) packet to a dnsmasq server configured with the `--dhcp-split-relay` option. This can lead to memory corruption, causing the dnsmasq daemon to crash and…
AplazadaMedia (6.9)0.21%—Dnsmasq-utilsAI5/2/202617/6/2026
Dnsmasq-utils 2.79-1 contains a buffer overflow vulnerability in the dhcp_release utility that allows attackers to cause a denial of service by supplying excessive input. Attackers can trigger a core dump and terminate the dhcp_release process by sending a crafted input string longer than 16 characters.
ModificadaAlta (7.5)0.66%—Thekelleys Dnsmasq6/6/202417/6/2026
dnsmasq 2.9 is vulnerable to Integer Overflow via forward_query.
ModificadaAlta (7.5)100%—Redhat Enterprise LinuxMicrosoft Windows Server 2008Microsoft Windows Server 2012Microsoft Windows Server 2016+914/2/202417/6/2026
Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the "KeyTrap" issue. One of the concerns is that, when there is a zone with many DNSKEY and RRSIG records, the…
ModificadaAlta (7.5)1.8%—Thekelleys Dnsmasq15/3/202317/6/2026
An issue was discovered in Dnsmasq before 2.90. The default maximum EDNS.0 UDP packet size was set to 4096 but should be 1232 because of DNS Flag Day 2020.
ModificadaAlta (7.5)2.5%—Thekelleys DnsmasqRedhat Enterprise Linux29/8/202217/6/2026
A single-byte, non-arbitrary write/use-after-free flaw was found in dnsmasq. This flaw allows an attacker who sends a crafted packet processed by dnsmasq, potentially causing a denial of service.
ModificadaCrítica (9.8)2.4%—Thekelleys Dnsmasq1/1/202217/6/2026
Dnsmasq 2.86 has a heap-based buffer overflow in answer_request (called from FuzzAnswerTheRequest and fuzz_rfc1035.c). NOTE: the vendor's position is that CVE-2021-45951 through CVE-2021-45957 "do not represent real vulnerabilities, to the best of our knowledge.
ModificadaCrítica (9.8)2.6%—Thekelleys Dnsmasq1/1/202217/6/2026
Dnsmasq 2.86 has a heap-based buffer overflow in print_mac (called from log_packet and dhcp_reply). NOTE: the vendor's position is that CVE-2021-45951 through CVE-2021-45957 "do not represent real vulnerabilities, to the best of our knowledge.
ModificadaCrítica (9.8)2.5%—Thekelleys Dnsmasq1/1/202217/6/2026
Dnsmasq 2.86 has a heap-based buffer overflow in resize_packet (called from FuzzResizePacket and fuzz_rfc1035.c) because of the lack of a proper bounds check upon pseudo header re-insertion. NOTE: the vendor's position is that CVE-2021-45951 through CVE-2021-45957 "do not represent real vulnerabilities, to the best of…
ModificadaCrítica (9.8)2.6%—Thekelleys Dnsmasq1/1/202217/6/2026
Dnsmasq 2.86 has a heap-based buffer overflow in extract_name (called from answer_auth and FuzzAuth). NOTE: the vendor's position is that CVE-2021-45951 through CVE-2021-45957 "do not represent real vulnerabilities, to the best of our knowledge.
ModificadaCrítica (9.8)2.6%—Thekelleys Dnsmasq1/1/202217/6/2026
Dnsmasq 2.86 has a heap-based buffer overflow in extract_name (called from hash_questions and fuzz_util.c). NOTE: the vendor's position is that CVE-2021-45951 through CVE-2021-45957 "do not represent real vulnerabilities, to the best of our knowledge.
ModificadaCrítica (9.8)2.6%—Thekelleys Dnsmasq1/1/202217/6/2026
Dnsmasq 2.86 has a heap-based buffer overflow in dhcp_reply (called from dhcp_packet and FuzzDhcp). NOTE: the vendor's position is that CVE-2021-45951 through CVE-2021-45957 "do not represent real vulnerabilities, to the best of our knowledge.
ModificadaCrítica (9.8)2.6%—Thekelleys Dnsmasq1/1/202217/6/2026
Dnsmasq 2.86 has a heap-based buffer overflow in check_bad_address (called from check_for_bogus_wildcard and FuzzCheckForBogusWildcard). NOTE: the vendor's position is that CVE-2021-45951 through CVE-2021-45957 "do not represent real vulnerabilities, to the best of our knowledge.
ModificadaMedia (4)2.3%—Thekelleys DnsmasqRedhat Enterprise LinuxFedoraproject FedoraOracle Communications Cloud Native Core Network Function Cloud Native Environment8/4/202117/6/2026
A flaw was found in dnsmasq in versions before 2.85. When configured to use a specific server for a given network interface, dnsmasq uses a fixed port while forwarding queries. An attacker on the network, able to find the outgoing port used by dnsmasq, only needs to guess the random transmission ID to forge a reply…
ModificadaMedia (5.9)87%—Thekelleys DnsmasqFedoraproject FedoraDebian Linux20/1/202117/6/2026
A flaw was found in dnsmasq before version 2.83. A heap-based buffer overflow was discovered in dnsmasq when DNSSEC is enabled and before it validates the received DNS entries. This flaw allows a remote attacker, who can create valid DNS replies, to cause an overflow in a heap-allocated memory. This flaw is caused by…
ModificadaBaja (3.7)4.9%—Thekelleys DnsmasqFedoraproject FedoraDebian LinuxArista EOS20/1/202117/6/2026
A flaw was found in dnsmasq before version 2.83. When receiving a query, dnsmasq does not check for an existing pending request for the same name and forwards a new request. By default, a maximum of 150 pending queries can be sent to upstream servers, so there can be at most 150 queries for the same name. This flaw…
ModificadaAlta (8.1)71%—Thekelleys DnsmasqFedoraproject FedoraDebian Linux20/1/202117/6/2026
A flaw was found in dnsmasq before 2.83. A buffer overflow vulnerability was discovered in the way dnsmasq extract names from DNS packets before validating them with DNSSEC data. An attacker on the network, who can create valid DNS replies, could use this flaw to cause an overflow with arbitrary data in a…