Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Hugo Martinez

#18475of 53,625
14.6Total CVSS
Vulnerabilities · 2
High
2
PT-2026-39702
7.3
2026-05-11
Dnsmasq · Dnsmasq · CVE-2026-5172
**Name of the Vulnerable Software and Affected Versions** dnsmasq (affected versions not specified) **Description** A buffer overflow in the `extract addresses()` function allows an attacker to trigger a heap out-of-bounds read and cause a crash. This occurs when a malformed DNS response is processed, enabling the `extract name()` function to advance the pointer beyond the end of the record. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2026-39648
7.3
2026-05-09
Dnsmasq · Dnsmasq · CVE-2026-2291
**Name of the Vulnerable Software and Affected Versions** dnsmasq (affected versions not specified) **Description** The `extract name()` function can be abused to cause a heap buffer overflow, a condition where data exceeds the allocated memory buffer on the heap. This allows an attacker to inject false DNS cache entries, potentially redirecting DNS lookups to an attacker-controlled IP address or causing a Denial of Service (DoS). **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.