Dhcpcd Project
Dhcpcd Project Dhcpcd: vulnerabilidades y CVE
Dhcpcd Project Dhcpcd tiene 16 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE16
Últimos 12 meses4
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-56117 | Media (5.7) | 0.14% | — | 23 jun 2026 | dhcpcd through 10.3.2, fixed in commit 78ea09e, contains a heap use-after-free vulnerability in the control socket handling within src/control.c that allows local unprivileged attackers to trigger memory corruption when… |
| CVE-2026-56116 | Alta (7.1) | 0.29% | — | 23 jun 2026 | dhcpcd through 10.3.2, fixed in commit 708b4a5, contains a memory leak vulnerability in the IPv6 Router Advertisement route information handling that allows an unauthenticated same-link attacker to cause denial of… |
| CVE-2026-56114 | Media (6) | 0.27% | — | 23 jun 2026 | dhcpcd through 10.3.2, fixed in commit 2f00c7b, contains a one-byte stack out-of-bounds write vulnerability in dhcp6_makemessage() in src/dhcp6.c that allows unauthenticated same-link attackers to write beyond a fixed… |
| CVE-2026-56113 | Media (6) | 0.27% | — | 23 jun 2026 | dhcpcd through 10.3.2, fixed in commit 5733d3c, contains a heap use-after-free vulnerability that allows unauthenticated same-link attackers to crash the daemon by sending a crafted DHCPv6 RENEW reply with RFC6603… |
| CVE-2019-11766 | Crítica (9.8) | 2.1% | — | 5 may 2019 | dhcp6.c in dhcpcd before 6.11.7 and 7.x before 7.2.2 has a buffer over-read in the D6_OPTION_PD_EXCLUDE feature. |
| CVE-2019-11579 | Media (5.3) | 1.4% | — | 28 abr 2019 | dhcp.c in dhcpcd before 7.2.1 contains a 1-byte read overflow with DHO_OPTSOVERLOADED. |
| CVE-2019-11578 | Media (5.9) | 2.0% | — | 28 abr 2019 | auth.c in dhcpcd before 7.2.1 allowed attackers to infer secrets by performing latency attacks. |
| CVE-2019-11577 | Crítica (9.8) | 53% | — | 28 abr 2019 | dhcpcd before 7.2.1 contains a buffer overflow in dhcp6_findna in dhcp6.c when reading NA/TA addresses. |
| CVE-2016-1504 | Alta (7.5) | 2.9% | — | 7 feb 2017 | dhcpcd before 6.10.0 allows remote attackers to cause a denial of service (invalid read and crash) via vectors related to the option length. |
| CVE-2016-1503 | Crítica (9.8) | 6.3% | — | 18 abr 2016 | dhcpcd before 6.10.0, as used in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 and other products, mismanages option lengths, which allows remote attackers to execute… |
| CVE-2012-6700 | Alta (7.5) | 2.0% | — | 11 abr 2016 | The decode_search function in dhcp.c in dhcpcd 3.x does not properly free allocated memory, which allows remote DHCP servers to cause a denial of service via a crafted response. |
| CVE-2012-6699 | Alta (7.5) | 2.0% | — | 11 abr 2016 | The decode_search function in dhcp.c in dhcpcd 3.x allows remote DHCP servers to cause a denial of service (out-of-bounds read) via a crafted response. |
| CVE-2012-6698 | Alta (7.5) | 2.0% | — | 11 abr 2016 | The decode_search function in dhcp.c in dhcpcd 3.x allows remote DHCP servers to cause a denial of service (out-of-bounds write) via a crafted response. |
| CVE-2014-7913 | Media (6.8) | 1.8% | — | 30 jul 2015 | The print_option function in dhcp-common.c in dhcpcd through 6.9.1, as used in dhcp.c in dhcpcd 5.x in Android before 5.1 and other products, misinterprets the return value of the snprintf function, which allows remote… |
| CVE-2014-7912 | Media (6.8) | 2.7% | — | 30 jul 2015 | The get_option function in dhcp.c in dhcpcd before 6.2.0, as used in dhcpcd 5.x in Android before 5.1 and other products, does not validate the relationship between length fields and the amount of data, which allows… |
| CVE-2014-6060 | Baja (3.3) | 0.44% | — | 4 sept 2014 | The get_option function in dhcpcd 4.0.0 through 6.x before 6.4.3 allows remote DHCP servers to cause a denial of service by resetting the DHO_OPTIONSOVERLOADED option in the (1) bootfile or (2) servername section, which… |