Vulnerabilities > Thekelleys > Critical

DATE CVE VULNERABILITY TITLE RISK
2022-01-01 CVE-2021-45951 Out-of-bounds Write vulnerability in Thekelleys Dnsmasq 2.86
Dnsmasq 2.86 has a heap-based buffer overflow in check_bad_address (called from check_for_bogus_wildcard and FuzzCheckForBogusWildcard).
network
low complexity
thekelleys CWE-787
critical
9.8
2022-01-01 CVE-2021-45952 Out-of-bounds Write vulnerability in Thekelleys Dnsmasq 2.86
Dnsmasq 2.86 has a heap-based buffer overflow in dhcp_reply (called from dhcp_packet and FuzzDhcp).
network
low complexity
thekelleys CWE-787
critical
9.8
2022-01-01 CVE-2021-45953 Out-of-bounds Write vulnerability in Thekelleys Dnsmasq 2.86
Dnsmasq 2.86 has a heap-based buffer overflow in extract_name (called from hash_questions and fuzz_util.c).
network
low complexity
thekelleys CWE-787
critical
9.8
2022-01-01 CVE-2021-45954 Out-of-bounds Write vulnerability in Thekelleys Dnsmasq 2.86
Dnsmasq 2.86 has a heap-based buffer overflow in extract_name (called from answer_auth and FuzzAuth).
network
low complexity
thekelleys CWE-787
critical
9.8
2022-01-01 CVE-2021-45955 Out-of-bounds Write vulnerability in Thekelleys Dnsmasq 2.86
Dnsmasq 2.86 has a heap-based buffer overflow in resize_packet (called from FuzzResizePacket and fuzz_rfc1035.c) because of the lack of a proper bounds check upon pseudo header re-insertion.
network
low complexity
thekelleys CWE-787
critical
9.8
2022-01-01 CVE-2021-45956 Out-of-bounds Write vulnerability in Thekelleys Dnsmasq 2.86
Dnsmasq 2.86 has a heap-based buffer overflow in print_mac (called from log_packet and dhcp_reply).
network
low complexity
thekelleys CWE-787
critical
9.8
2022-01-01 CVE-2021-45957 Out-of-bounds Write vulnerability in Thekelleys Dnsmasq 2.86
Dnsmasq 2.86 has a heap-based buffer overflow in answer_request (called from FuzzAnswerTheRequest and fuzz_rfc1035.c).
network
low complexity
thekelleys CWE-787
critical
9.8
2017-10-04 CVE-2017-14491 Out-of-bounds Write vulnerability in multiple products
Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response.
9.8
2017-10-03 CVE-2017-14493 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
Stack-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DHCPv6 request.
network
low complexity
redhat debian canonical opensuse thekelleys CWE-119
critical
9.8
2017-10-03 CVE-2017-14492 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted IPv6 router advertisement request.
network
low complexity
redhat debian canonical thekelleys CWE-119
critical
9.8