CVE-2026-4890
- EPSS 3.14%
- Veröffentlicht 11.05.2026 18:16:41
- Zuletzt bearbeitet 12.05.2026 14:15:46
A Denial of Service (DoS) vulnerability in the DNSSEC validation of dnsmasq allows remote attackers to cause a denial of service via a crafted DNS packet.
CVE-2026-4891
- EPSS 2.49%
- Veröffentlicht 11.05.2026 18:16:41
- Zuletzt bearbeitet 12.05.2026 14:15:46
A heap-based out-of-bounds read vulnerability in the DNSSEC validation of dnsmasq allows remote attackers to cause a denial of service via a crafted DNS packet.
CVE-2026-4892
- EPSS 0.34%
- Veröffentlicht 11.05.2026 18:16:41
- Zuletzt bearbeitet 12.05.2026 14:15:46
A heap-based out-of-bounds write vulnerability in the DHCPv6 implementation of dnsmasq allows local attackers to execute arbitrary code with root privileges via a crafted DHCPv6 packet.
CVE-2026-4893
- EPSS 2.68%
- Veröffentlicht 11.05.2026 18:16:41
- Zuletzt bearbeitet 12.05.2026 14:15:46
An information disclosure vulnerability in dnsmasq allows remote attackers to bypass source checks via a crafted DNS packet with RFC 7871 client subnet information.
CVE-2026-5172
- EPSS 0.65%
- Veröffentlicht 11.05.2026 18:16:41
- Zuletzt bearbeitet 13.05.2026 14:17:59
A buffer overflow in dnsmasq’s extract_addresses() function allows an attacker to trigger a heap out-of-bounds read and crash by exploiting a malformed DNS response, enabling extract_name() to advance the pointer past the record’s end.
CVE-2026-2291
- EPSS 0.75%
- Veröffentlicht 11.05.2026 18:16:31
- Zuletzt bearbeitet 13.05.2026 14:17:14
dnsmasqs extract_name() function can be abused to cause a heap buffer overflow, allowing an attacker to inject false DNS cache entries, which could result in DNS lookups to redirect to an attacker-controlled IP address, or to cause a DoS.
CVE-2025-12199
- EPSS 0.01%
- Veröffentlicht 27.10.2025 01:02:09
- Zuletzt bearbeitet 03.11.2025 23:17:36
Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: Based on the analysis by MITRE and review of comm...
- EPSS 1.8%
- Veröffentlicht 25.04.2006 12:50:00
- Zuletzt bearbeitet 16.06.2026 22:24:08
Dnsmasq 2.29 allows remote attackers to cause a denial of service (application crash) via a DHCP client broadcast reply request.
- EPSS 2.61%
- Veröffentlicht 02.05.2005 04:00:00
- Zuletzt bearbeitet 16.06.2026 22:11:58
Off-by-one buffer overflow in Dnsmasq before 2.21 may allow attackers to execute arbitrary code via the DHCP lease file.