Skip to main content

Vendor/product archive

isc / dhcp CVEs

Beta · best-effort

25 CVEs tagged to isc / dhcp1 Critical, 9 High, 14 Medium, 1 Low, 0 Unrated.

CVE-2018-5732

Published Oct 9, 2019

Failure to properly bounds-check a buffer used for processing DHCP options allows a malicious server (or an entity masquerading as a server) to cause a buffer overflow (and result…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2018-5733

Published Jan 16, 2019

A malicious client which is allowed to send very large amounts of traffic (billions of packets) to a DHCP server can eventually overflow a 32-bit reference counter, potentially ca…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2017-3144

Published Jan 16, 2019

A vulnerability stemming from failure to properly clean up closed OMAPI connections can lead to exhaustion of the pool of socket descriptors available to the DHCP server. Affects…

CVSS 7.5 · High
evidence mentions
3
Buzz score
21.9

CVE-2013-2494

Published Mar 28, 2013

libdns in ISC DHCP 4.2.x before 4.2.5-P1 allows remote name servers to cause a denial of service (memory consumption) via vectors involving a regular expression, as demonstrated b…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-3570

Published Jul 25, 2012

Buffer overflow in ISC DHCP 4.2.x before 4.2.4-P1, when DHCPv6 mode is enabled, allows remote attackers to cause a denial of service (segmentation fault and daemon exit) via a cra…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4868

Published Jan 15, 2012

The logging functionality in dhcpd in ISC DHCP before 4.2.3-P2, when using Dynamic DNS (DDNS) and issuing IPv6 addresses, does not properly handle the DHCPv6 lease structure, whic…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0413

Published Jan 31, 2011

The DHCPv6 server in ISC DHCP 4.0.x and 4.1.x before 4.1.2-P1, 4.0-ESV and 4.1-ESV before 4.1-ESV-R1, and 4.2.x before 4.2.1b1 allows remote attackers to cause a denial of service…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2010-3616

Published Dec 17, 2010

ISC DHCP server 4.2 before 4.2.0-P2, when configured to use failover partnerships, allows remote attackers to cause a denial of service (communications-interrupted state and DHCP…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3611

Published Nov 4, 2010

ISC DHCP server 4.0 before 4.0.2, 4.1 before 4.1.2, and 4.2 before 4.2.0-P1 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a DHCPv6…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-2156

Published Jun 7, 2010

ISC DHCP 4.1 before 4.1.1-P1 and 4.0 before 4.0.2-P1 allows remote attackers to cause a denial of service (server exit) via a zero-length client ID.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-1893

Published Jul 17, 2009

The configtest function in the Red Hat dhcpd init script for DHCP 3.0.1 in Red Hat Enterprise Linux (RHEL) 3 allows local users to overwrite arbitrary files via a symlink attack o…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-1892

Published Jul 17, 2009

dhcpd in ISC DHCP 3.0.4 and 3.1.1, when the dhcp-client-identifier and hardware ethernet configuration settings are both used, allows remote attackers to cause a denial of service…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0692

Published Jul 14, 2009

Stack-based buffer overflow in the script_write_params method in client/dhclient.c in ISC DHCP dhclient 4.1 before 4.1.0p1, 4.0 before 4.0.1p1, 3.1 before 3.1.2p1, 3.0, and 2.0 al…

CVSS 10.0 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort
Showing 1-25 of 25 CVEsPage 1 of 1