Search CVE reports


Toggle filters

31 – 40 of 47 results


CVE-2017-14494

Medium priority
Fixed

dnsmasq before 2.78, when configured as a relay, allows remote attackers to obtain sensitive memory information via vectors involving handling DHCPv6 forwarded requests.

1 affected package

dnsmasq

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dnsmasq
Show less packages

CVE-2017-14493

High priority
Fixed

Stack-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DHCPv6 request.

1 affected package

dnsmasq

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dnsmasq
Show less packages

CVE-2017-14492

High priority
Fixed

Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted IPv6 router advertisement request.

1 affected package

dnsmasq

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dnsmasq
Show less packages

CVE-2017-14491

High priority
Fixed

Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response.

1 affected package

dnsmasq

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dnsmasq
Show less packages

CVE-2017-13704

High priority
Not affected

In dnsmasq before 2.78, if the DNS packet size does not match the expected size, the size parameter in a memset call gets a negative value. As it is an unsigned value, memset ends up writing up to 0xffffffff...

1 affected package

dnsmasq

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dnsmasq
Show less packages

CVE-2015-8899

Medium priority
Fixed

Dnsmasq before 2.76 allows remote servers to cause a denial of service (crash) via a reply with an empty DNS address that has an (1) A or (2) AAAA record defined locally.

1 affected package

dnsmasq

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dnsmasq
Show less packages

CVE-2015-3294

Medium priority

Some fixes available 4 of 5

The tcp_request function in Dnsmasq before 2.73rc4 does not properly handle the return value of the setup_reply function, which allows remote attackers to read process memory and cause a denial of service (out-of-bounds read and...

1 affected package

dnsmasq

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dnsmasq
Show less packages

CVE-2013-0198

Low priority

Some fixes available 7 of 12

Dnsmasq before 2.66test2, when used with certain libvirt configurations, replies to queries from prohibited interfaces, which allows remote attackers to cause a denial of service (traffic amplification) via spoofed TCP based DNS...

1 affected package

dnsmasq

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dnsmasq
Show less packages

CVE-2012-3411

Low priority
Ignored

Dnsmasq before 2.63test1, when used with certain libvirt configurations, replies to requests from prohibited interfaces, which allows remote attackers to cause a denial of service (traffic amplification) via a spoofed DNS query.

2 affected packages

dnsmasq, libvirt

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dnsmasq
libvirt
Show less packages

CVE-2009-2958

Medium priority
Fixed

The tftp_request function in tftp.c in dnsmasq before 2.50, when --enable-tftp is used, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a TFTP read (aka RRQ) request with a...

1 affected package

dnsmasq

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dnsmasq
Show less packages