Show filters
56 Total Results
Displaying 11-20 of 56
Sort by:
Attacker Value
Unknown
CVE-2019-11579
Disclosure Date: April 28, 2019 (last updated November 27, 2024)
dhcp.c in dhcpcd before 7.2.1 contains a 1-byte read overflow with DHO_OPTSOVERLOADED.
0
Attacker Value
Unknown
Failure to properly clean up closed OMAPI connections can exhaust available soc…
Disclosure Date: January 16, 2019 (last updated November 27, 2024)
A vulnerability stemming from failure to properly clean up closed OMAPI connections can lead to exhaustion of the pool of socket descriptors available to the DHCP server. Affects ISC DHCP 4.1.0 to 4.1-ESV-R15, 4.2.0 to 4.2.8, 4.3.0 to 4.3.6. Older versions may also be affected but are well beyond their end-of-life (EOL). Releases prior to 4.1.0 have not been tested.
0
Attacker Value
Unknown
A malicious client can overflow a reference counter in ISC dhcpd
Disclosure Date: January 16, 2019 (last updated November 27, 2024)
A malicious client which is allowed to send very large amounts of traffic (billions of packets) to a DHCP server can eventually overflow a 32-bit reference counter, potentially causing dhcpd to crash. Affects ISC DHCP 4.1.0 -> 4.1-ESV-R15, 4.2.0 -> 4.2.8, 4.3.0 -> 4.3.6, 4.4.0.
0
Attacker Value
Unknown
CVE-2018-5732
Disclosure Date: February 28, 2018 (last updated November 27, 2024)
Failure to properly bounds-check a buffer used for processing DHCP options allows a malicious server (or an entity masquerading as a server) to cause a buffer overflow (and resulting crash) in dhclient by sending a response containing a specially constructed options section. Affects ISC DHCP versions 4.1.0 -> 4.1-ESV-R15, 4.2.0 -> 4.2.8, 4.3.0 -> 4.3.6, 4.4.0
0
Attacker Value
Unknown
CVE-2016-1504
Disclosure Date: February 07, 2017 (last updated November 26, 2024)
dhcpcd before 6.10.0 allows remote attackers to cause a denial of service (invalid read and crash) via vectors related to the option length.
0
Attacker Value
Unknown
CVE-2016-1503
Disclosure Date: April 18, 2016 (last updated November 25, 2024)
dhcpcd before 6.10.0, as used in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 and other products, mismanages option lengths, which allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow) via a malformed DHCP response, aka internal bug 26461634.
0
Attacker Value
Unknown
CVE-2012-6699
Disclosure Date: April 11, 2016 (last updated November 25, 2024)
The decode_search function in dhcp.c in dhcpcd 3.x allows remote DHCP servers to cause a denial of service (out-of-bounds read) via a crafted response.
0
Attacker Value
Unknown
CVE-2012-6698
Disclosure Date: April 11, 2016 (last updated November 25, 2024)
The decode_search function in dhcp.c in dhcpcd 3.x allows remote DHCP servers to cause a denial of service (out-of-bounds write) via a crafted response.
0
Attacker Value
Unknown
CVE-2012-6700
Disclosure Date: April 11, 2016 (last updated November 25, 2024)
The decode_search function in dhcp.c in dhcpcd 3.x does not properly free allocated memory, which allows remote DHCP servers to cause a denial of service via a crafted response.
0
Attacker Value
Unknown
CVE-2016-2774
Disclosure Date: March 09, 2016 (last updated November 25, 2024)
ISC DHCP 4.1.x before 4.1-ESV-R13 and 4.2.x and 4.3.x before 4.3.4 does not restrict the number of concurrent TCP sessions, which allows remote attackers to cause a denial of service (INSIST assertion failure or request-processing outage) by establishing many sessions.
0