CVE-2022-2929
- EPSS 0.04%
- Veröffentlicht 07.10.2022 05:15:11
- Zuletzt bearbeitet 21.11.2024 07:01:56
In ISC DHCP 1.0 -> 4.4.3, ISC DHCP 4.1-ESV-R1 -> 4.1-ESV-R16-P1 a system with access to a DHCP server, sending DHCP packets crafted to include fqdn labels longer than 63 bytes, could eventually cause the server to run out of memory.
CVE-2022-2928
- EPSS 0.03%
- Veröffentlicht 07.10.2022 05:15:08
- Zuletzt bearbeitet 21.11.2024 07:01:56
In ISC DHCP 4.4.0 -> 4.4.3, ISC DHCP 4.1-ESV-R1 -> 4.1-ESV-R16-P1, when the function option_code_hash_lookup() is called from add_option(), it increases the option's refcount field. However, there is not a corresponding call to option_dereference() t...
CVE-2021-25217
- EPSS 0.41%
- Veröffentlicht 26.05.2021 22:15:07
- Zuletzt bearbeitet 21.11.2024 05:54:34
In ISC DHCP 4.1-ESV-R1 -> 4.1-ESV-R16, ISC DHCP 4.4.0 -> 4.4.2 (Other branches of ISC DHCP (i.e., releases in the 4.0.x series or lower and releases in the 4.3.x series) are beyond their End-of-Life (EOL) and no longer supported by ISC. From inspecti...
CVE-2018-5732
- EPSS 1.76%
- Veröffentlicht 09.10.2019 16:15:13
- Zuletzt bearbeitet 21.11.2024 04:09:16
Failure to properly bounds-check a buffer used for processing DHCP options allows a malicious server (or an entity masquerading as a server) to cause a buffer overflow (and resulting crash) in dhclient by sending a response containing a specially con...
CVE-2018-5733
- EPSS 29.51%
- Veröffentlicht 16.01.2019 20:29:00
- Zuletzt bearbeitet 25.04.2025 23:15:15
A malicious client which is allowed to send very large amounts of traffic (billions of packets) to a DHCP server can eventually overflow a 32-bit reference counter, potentially causing dhcpd to crash. Affects ISC DHCP 4.1.0 -> 4.1-ESV-R15, 4.2.0 -> 4...
CVE-2017-3144
- EPSS 18.41%
- Veröffentlicht 16.01.2019 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:24:55
A vulnerability stemming from failure to properly clean up closed OMAPI connections can lead to exhaustion of the pool of socket descriptors available to the DHCP server. Affects ISC DHCP 4.1.0 to 4.1-ESV-R15, 4.2.0 to 4.2.8, 4.3.0 to 4.3.6. Older ve...
CVE-2016-2774
- EPSS 69.96%
- Veröffentlicht 09.03.2016 15:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
ISC DHCP 4.1.x before 4.1-ESV-R13 and 4.2.x and 4.3.x before 4.3.4 does not restrict the number of concurrent TCP sessions, which allows remote attackers to cause a denial of service (INSIST assertion failure or request-processing outage) by establis...
CVE-2015-8605
- EPSS 49.97%
- Veröffentlicht 14.01.2016 22:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
ISC DHCP 4.x before 4.1-ESV-R12-P1, 4.2.x, and 4.3.x before 4.3.3-P1 allows remote attackers to cause a denial of service (application crash) via an invalid length field in a UDP IPv4 packet.
CVE-2013-2494
- EPSS 1.04%
- Veröffentlicht 28.03.2013 16:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
libdns in ISC DHCP 4.2.x before 4.2.5-P1 allows remote name servers to cause a denial of service (memory consumption) via vectors involving a regular expression, as demonstrated by a memory-exhaustion attack against a machine running a dhcpd process,...
CVE-2012-3955
- EPSS 12.1%
- Veröffentlicht 14.09.2012 10:33:21
- Zuletzt bearbeitet 11.04.2025 00:51:21
ISC DHCP 4.1.x before 4.1-ESV-R7 and 4.2.x before 4.2.4-P2 allows remote attackers to cause a denial of service (daemon crash) in opportunistic circumstances by establishing an IPv6 lease in an environment where the lease expiration time is later red...