Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

C Ares

First CVE: Oct 3, 2016Active for: 10 yearsTotal CVEs: 24

C Ares is a DNS resolver library embedded across a large range of systems and applications despite its narrow product scope, giving its vulnerabilities impact disproportionate to its volume—a single flaw can propagate to every downstream consumer of the library. The recurring exposure reflects the parsing and protocol complexity inherent to DNS resolution, and defenders should inventory affected dependencies rather than tracking the library alone, since remediation typically depends on downstream vendors rebuilding. Live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
13
Total CVEs
More Total CVEs than 86% of tracked vendors
1.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
6.4
Avg CVSS Score
Higher Avg CVSS Score than 37% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by C Ares over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 3, 2016
9 years ago
Most Recent CVE
Dec 8, 2025
228 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (13 CVEs).

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-8277HIGH
A Node.js application that allows an attacker to trigger a DNS request for a host of their choice could trigger a Denial of Service in versions < 15.2.1, < 14.15.1, and < 12.19.1 b
Nov 19, 20207.554NONO
CVE-2016-5180CRITICAL
Heap-based buffer overflow in the ares_create_query function in c-ares 1.x before 1.12.0 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly exec
Oct 3, 20169.836NONO
CVE-2017-1000381HIGH
The c-ares function `ares_parse_naptr_reply()`, which is used for parsing NAPTR responses, could be triggered to read memory outside of the given input buffer if the passed in DNS
Jul 7, 20177.527NONO
CVE-2023-32067HIGH
c-ares is an asynchronous resolver library. c-ares is vulnerable to denial of service. If a target resolver sends a query, the attacker forges a malformed UDP packet with a length
May 25, 20237.523NONO
CVE-2025-62408MEDIUM
c-ares is an asynchronous resolver library. Versions 1.32.3 through 1.34.5 terminate a query after maximum attempts when using read_answer() and process_answer(), which can cause
Dec 8, 20255.922NONO
CVE-2021-3672MEDIUM
A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might pot
Nov 23, 20215.622NONO
CVE-2023-31147MEDIUM
c-ares is an asynchronous resolver library. When /dev/urandom or RtlGenRandom() are unavailable, c-ares uses rand() to generate random numbers used for DNS query ids. This is not a
May 25, 20236.521NONO
CVE-2022-4904HIGH
A flaw was found in the c-ares package. The ares_set_sortlist is missing checks about the validity of the input string, which allows a possible arbitrary length stack overflow. Thi
Mar 6, 20238.621NONO
CVE-2023-31130MEDIUM
c-ares is an asynchronous resolver library. ares_inet_net_pton() is vulnerable to a buffer underflow for certain ipv6 addresses, in particular "0::00:00:00/2" was found to cause an
May 25, 20236.420NONO
CVE-2020-22217MEDIUM
Buffer overflow vulnerability in c-ares before 1_16_1 thru 1_17_0 via function ares_parse_soa_reply in ares_parse_soa_reply.c.
Aug 22, 20235.919NONO
View all 13 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products13 CVEs
15%
46%
31%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local3 (23.1%)
Network10 (76.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (61.5%)
High5 (38.5%)
Unknown0 (0.0%)
User Interaction
None13 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low2 (15.4%)
High1 (7.7%)
None10 (76.9%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (13 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by C Ares.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by C Ares — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For C Ares's Products

View all 5 CNAs →

Top CWEs