Dhcpcd
Vendor:
First CVE: Sep 4, 2014 · Active for 11 years
16
Total CVEs
More Total CVEs than 93% of tracked products
2.7
Avg CVEs / Year
Higher CVE frequency than 78% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 45% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Dhcpcd over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 4, 2014
11 years ago
Most Recent CVE
Jun 23, 2026
35 days ago
CVE Severity & Scoring
Dhcpcd16 CVEs
50%
25%
19%
All CVEs353,240 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (6.3%)
Network9 (56.3%)
Unknown3 (18.8%)
Physical0 (0.0%)
Adjacent Network3 (18.8%)
Attack Complexity
Low12 (75.0%)
High1 (6.3%)
Unknown3 (18.8%)
User Interaction
None13 (81.3%)
Unknown3 (18.8%)
Required0 (0.0%)
Privileges Required
Low1 (6.3%)
High0 (0.0%)
None12 (75.0%)
Unknown3 (18.8%)
Top CVEs
Signals from CVEs in this product scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-11577CRITICAL dhcpcd before 7.2.1 contains a buffer overflow in dhcp6_findna in dhcp6.c when reading NA/TA addresses. | Apr 28, 2019 | 9.8 | 61 | NO | NO |
CVE-2016-1503CRITICAL dhcpcd before 6.10.0, as used in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 and other products, mismanages option lengths, which al | Apr 18, 2016 | 9.8 | 33 | NO | NO |
CVE-2019-11766CRITICAL dhcp6.c in dhcpcd before 6.11.7 and 7.x before 7.2.2 has a buffer over-read in the D6_OPTION_PD_EXCLUDE feature. | May 5, 2019 | 9.8 | 31 | NO | NO |
CVE-2026-56116MEDIUM dhcpcd through 10.3.2, fixed in commit 708b4a5, contains a memory leak vulnerability in the IPv6 Router Advertisement route information handling that allows an unauthenticated same | Jun 23, 2026 | 6.5 | 28 | NO | NO |
CVE-2026-56114MEDIUM dhcpcd through 10.3.2, fixed in commit 2f00c7b, contains a one-byte stack out-of-bounds write vulnerability in dhcp6_makemessage() in src/dhcp6.c that allows unauthenticated same-l | Jun 23, 2026 | 6.5 | 28 | NO | NO |
CVE-2026-56113MEDIUM dhcpcd through 10.3.2, fixed in commit 5733d3c, contains a heap use-after-free vulnerability that allows unauthenticated same-link attackers to crash the daemon by sending a crafte | Jun 23, 2026 | 6.5 | 27 | NO | NO |
CVE-2026-56117MEDIUM dhcpcd through 10.3.2, fixed in commit 78ea09e, contains a heap use-after-free vulnerability in the control socket handling within src/control.c that allows local unprivileged atta | Jun 23, 2026 | 5.5 | 26 | NO | NO |
CVE-2016-1504HIGH dhcpcd before 6.10.0 allows remote attackers to cause a denial of service (invalid read and crash) via vectors related to the option length. | Feb 7, 2017 | 7.5 | 25 | NO | NO |
CVE-2012-6700HIGH The decode_search function in dhcp.c in dhcpcd 3.x does not properly free allocated memory, which allows remote DHCP servers to cause a denial of service via a crafted response. | Apr 11, 2016 | 7.5 | 24 | NO | NO |
CVE-2012-6699HIGH The decode_search function in dhcp.c in dhcpcd 3.x allows remote DHCP servers to cause a denial of service (out-of-bounds read) via a crafted response. | Apr 11, 2016 | 7.5 | 24 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (16 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (16 CVEs).
Media Mentions
Signals from CVEs in this product scope (16 CVEs).
Top CNAs Publishing CVEs For Dhcpcd
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 6.4.2 | 1 | 3.3 | 0.4% | 0 | 0 |
| 6.4.1 | 1 | 3.3 | 0.4% | 0 | 0 |
| 6.4.0 | 1 | 3.3 | 0.4% | 0 | 0 |
| 6.3.2 | 1 | 3.3 | 0.4% | 0 | 0 |
| 6.3.1 | 1 | 3.3 | 0.4% | 0 | 0 |
| 6.3.0 | 1 | 3.3 | 0.4% | 0 | 0 |
| 6.2.1 | 1 | 3.3 | 0.4% | 0 | 0 |
| 6.2.0 | 1 | 3.3 | 0.4% | 0 | 0 |
| 6.1.0 | 1 | 3.3 | 0.4% | 0 | 0 |
| 6.0.5 | 1 | 3.3 | 0.4% | 0 | 0 |
| 6.0.4 | 1 | 3.3 | 0.4% | 0 | 0 |
| 6.0.3 | 1 | 3.3 | 0.4% | 0 | 0 |
| 6.0.2 | 1 | 3.3 | 0.4% | 0 | 0 |
| 6.0.1 | 1 | 3.3 | 0.4% | 0 | 0 |
| 6.0.0 | 1 | 3.3 | 0.4% | 0 | 0 |
| 5.99.7 | 1 | 3.3 | 0.4% | 0 | 0 |
| 5.99.6 | 1 | 3.3 | 0.4% | 0 | 0 |
| 5.99.5 | 1 | 3.3 | 0.4% | 0 | 0 |
| 5.99.4 | 1 | 3.3 | 0.4% | 0 | 0 |
| 5.99.3 | 1 | 3.3 | 0.4% | 0 | 0 |