Dhcpcd

Vendor:

First CVE: Sep 4, 2014 · Active for 11 years

16
Total CVEs
More Total CVEs than 93% of tracked products
2.7
Avg CVEs / Year
Higher CVE frequency than 78% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 45% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Dhcpcd over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 4, 2014
11 years ago
Most Recent CVE
Jun 23, 2026
35 days ago

CVE Severity & Scoring

Dhcpcd16 CVEs
All CVEs353,240 CVEs
LowMediumHighCritical
Attack Vector
Local1 (6.3%)
Network9 (56.3%)
Unknown3 (18.8%)
Physical0 (0.0%)
Adjacent Network3 (18.8%)
Attack Complexity
Low12 (75.0%)
High1 (6.3%)
Unknown3 (18.8%)
User Interaction
None13 (81.3%)
Unknown3 (18.8%)
Required0 (0.0%)
Privileges Required
Low1 (6.3%)
High0 (0.0%)
None12 (75.0%)
Unknown3 (18.8%)

Top CVEs

Signals from CVEs in this product scope (16 CVEs).

16 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
dhcpcd before 7.2.1 contains a buffer overflow in dhcp6_findna in dhcp6.c when reading NA/TA addresses.
Apr 28, 20199.861NONO
dhcpcd before 6.10.0, as used in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 and other products, mismanages option lengths, which al
Apr 18, 20169.833NONO
dhcp6.c in dhcpcd before 6.11.7 and 7.x before 7.2.2 has a buffer over-read in the D6_OPTION_PD_EXCLUDE feature.
May 5, 20199.831NONO
dhcpcd through 10.3.2, fixed in commit 708b4a5, contains a memory leak vulnerability in the IPv6 Router Advertisement route information handling that allows an unauthenticated same
Jun 23, 20266.528NONO
dhcpcd through 10.3.2, fixed in commit 2f00c7b, contains a one-byte stack out-of-bounds write vulnerability in dhcp6_makemessage() in src/dhcp6.c that allows unauthenticated same-l
Jun 23, 20266.528NONO
dhcpcd through 10.3.2, fixed in commit 5733d3c, contains a heap use-after-free vulnerability that allows unauthenticated same-link attackers to crash the daemon by sending a crafte
Jun 23, 20266.527NONO
dhcpcd through 10.3.2, fixed in commit 78ea09e, contains a heap use-after-free vulnerability in the control socket handling within src/control.c that allows local unprivileged atta
Jun 23, 20265.526NONO
dhcpcd before 6.10.0 allows remote attackers to cause a denial of service (invalid read and crash) via vectors related to the option length.
Feb 7, 20177.525NONO
The decode_search function in dhcp.c in dhcpcd 3.x does not properly free allocated memory, which allows remote DHCP servers to cause a denial of service via a crafted response.
Apr 11, 20167.524NONO
The decode_search function in dhcp.c in dhcpcd 3.x allows remote DHCP servers to cause a denial of service (out-of-bounds read) via a crafted response.
Apr 11, 20167.524NONO

Exploit Exposure

Signals from CVEs in this product scope (16 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (16 CVEs).

Media Mentions

Signals from CVEs in this product scope (16 CVEs).

Top CNAs Publishing CVEs For Dhcpcd

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
6.4.213.30.4%00
6.4.113.30.4%00
6.4.013.30.4%00
6.3.213.30.4%00
6.3.113.30.4%00
6.3.013.30.4%00
6.2.113.30.4%00
6.2.013.30.4%00
6.1.013.30.4%00
6.0.513.30.4%00
6.0.413.30.4%00
6.0.313.30.4%00
6.0.213.30.4%00
6.0.113.30.4%00
6.0.013.30.4%00
5.99.713.30.4%00
5.99.613.30.4%00
5.99.513.30.4%00
5.99.413.30.4%00
5.99.313.30.4%00