Skip to main content

Vendor/product archive

thekelleys / dnsmasq CVEs

Beta · best-effort

39 CVEs tagged to thekelleys / dnsmasq10 Critical, 14 High, 11 Medium, 4 Low, 0 Unrated.

CVE-2026-12969

Published Jun 23, 2026

An out-of-bounds read vulnerability exists in dnsmasq's find_soa() function in src/rfc1035.c. When parsing NS section records, extract_name() is called with extrabytes=0, failing…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2023-50387

Published Feb 14, 2024

Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5

CVE-2023-28450

Published Mar 15, 2023

An issue was discovered in Dnsmasq before 2.90. The default maximum EDNS.0 UDP packet size was set to 4096 but should be 1232 because of DNS Flag Day 2020.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-45957

Published Jan 1, 2022

Dnsmasq 2.86 has a heap-based buffer overflow in answer_request (called from FuzzAnswerTheRequest and fuzz_rfc1035.c). NOTE: the vendor's position is that CVE-2021-45951 through C…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-45956

Published Jan 1, 2022

Dnsmasq 2.86 has a heap-based buffer overflow in print_mac (called from log_packet and dhcp_reply). NOTE: the vendor's position is that CVE-2021-45951 through CVE-2021-45957 "do n…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-45955

Published Jan 1, 2022

Dnsmasq 2.86 has a heap-based buffer overflow in resize_packet (called from FuzzResizePacket and fuzz_rfc1035.c) because of the lack of a proper bounds check upon pseudo header re…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-45954

Published Jan 1, 2022

Dnsmasq 2.86 has a heap-based buffer overflow in extract_name (called from answer_auth and FuzzAuth). NOTE: the vendor's position is that CVE-2021-45951 through CVE-2021-45957 "do…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-45953

Published Jan 1, 2022

Dnsmasq 2.86 has a heap-based buffer overflow in extract_name (called from hash_questions and fuzz_util.c). NOTE: the vendor's position is that CVE-2021-45951 through CVE-2021-459…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-45952

Published Jan 1, 2022

Dnsmasq 2.86 has a heap-based buffer overflow in dhcp_reply (called from dhcp_packet and FuzzDhcp). NOTE: the vendor's position is that CVE-2021-45951 through CVE-2021-45957 "do n…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-45951

Published Jan 1, 2022

Dnsmasq 2.86 has a heap-based buffer overflow in check_bad_address (called from check_for_bogus_wildcard and FuzzCheckForBogusWildcard). NOTE: the vendor's position is that CVE-20…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-14834

Published Jan 7, 2020

A vulnerability was found in dnsmasq before version 2.81, where the memory leak allows remote attackers to cause a denial of service (memory consumption) via vectors involving DHC…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2019-14513

Published Aug 1, 2019

Improper bounds checking in Dnsmasq before 2.76 allows an attacker controlled DNS server to send large DNS packets that result in a read operation beyond the buffer allocated for…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-15107

Published Jan 23, 2018

A vulnerability was found in the implementation of DNSSEC in Dnsmasq up to and including 2.78. Wildcard synthesized NSEC records could be improperly interpreted to prove the non-e…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 39 CVEsPage 1 of 2