Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown

CVE-2016-5180

Disclosure Date: October 03, 2016 (last updated November 08, 2023)
Heap-based buffer overflow in the ares_create_query function in c-ares 1.x before 1.12.0 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly execute arbitrary code via a hostname with an escaped trailing dot.
Attacker Value
Unknown

CVE-2007-3153

Disclosure Date: June 11, 2007 (last updated October 04, 2023)
The ares_init:randomize_key function in c-ares, on platforms other than Windows, uses a weak facility for producing a random number sequence (Unix rand), which makes it easier for remote attackers to spoof DNS responses by guessing certain values.
0
Attacker Value
Unknown

CVE-2007-3152

Disclosure Date: June 11, 2007 (last updated October 04, 2023)
c-ares before 1.4.0 uses a predictable seed for the random number generator for the DNS Transaction ID field, which might allow remote attackers to spoof DNS responses by guessing the field value.
0