CVEs (12)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Dhcpcd Project2Debian Linux DhcpcdNov 21, 2024 May 5, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 dhcp6.c in dhcpcd before 6.11.7 and 7.x before 7.2.2 has a buffer over-read in the D6_OPTION_PD_EXCLUDE feature. |
2Debian Dhcpcd Project2Debian Linux DhcpcdNov 21, 2024 Apr 28, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 dhcp.c in dhcpcd before 7.2.1 contains a 1-byte read overflow with DHO_OPTSOVERLOADED. |
auth.c in dhcpcd before 7.2.1 allowed attackers to infer secrets by performing latency attacks. |
dhcpcd before 7.2.1 contains a buffer overflow in dhcp6_findna in dhcp6.c when reading NA/TA addresses. |
dhcpcd before 6.10.0 allows remote attackers to cause a denial of service (invalid read and crash) via vectors related to the option length. |
2Dhcpcd Project Google2Android DhcpcdMay 6, 2026 Apr 18, 2016 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 dhcpcd before 6.10.0, as used in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 and other products, mismanages option lengths, which allows remote attackers to execute arbitra...Show more |
2Debian Dhcpcd Project2Debian Linux DhcpcdMay 6, 2026 Apr 11, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The decode_search function in dhcp.c in dhcpcd 3.x does not properly free allocated memory, which allows remote DHCP servers to cause a denial of service via a crafted response. |
2Debian Dhcpcd Project2Debian Linux DhcpcdMay 6, 2026 Apr 11, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The decode_search function in dhcp.c in dhcpcd 3.x allows remote DHCP servers to cause a denial of service (out-of-bounds read) via a crafted response. |
2Debian Dhcpcd Project2Debian Linux DhcpcdMay 6, 2026 Apr 11, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The decode_search function in dhcp.c in dhcpcd 3.x allows remote DHCP servers to cause a denial of service (out-of-bounds write) via a crafted response. |
The print_option function in dhcp-common.c in dhcpcd through 6.9.1, as used in dhcp.c in dhcpcd 5.x in Android before 5.1 and other products, misinterprets the return value of the snprintf function, which allows remote D...Show more |
The get_option function in dhcp.c in dhcpcd before 6.2.0, as used in dhcpcd 5.x in Android before 5.1 and other products, does not validate the relationship between length fields and the amount of data, which allows remo...Show more |
The get_option function in dhcpcd 4.0.0 through 6.x before 6.4.3 allows remote DHCP servers to cause a denial of service by resetting the DHO_OPTIONSOVERLOADED option in the (1) bootfile or (2) servername section, which...Show more |