Thekelleys maintains dnsmasq, a widely embedded DNS and DHCP server that appears in countless consumer routers, IoT appliances, and embedded systems despite its narrow product footprint, making it a high-impact supply-chain component whose vulnerabilities propagate across a large installed base. The vendor's disclosures skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting the memory-safety demands of a C-based daemon processing untrusted network input. The recurring weakness classes—out-of-bounds writes, buffer overflows, improper input validation, and memory-access boundary failures—are characteristic of the parser and state-management logic in a network service handling DNS queries and DHCP exchanges from potentially hostile sources. Defenders should treat dnsmasq updates as high-priority and inventory embedded occurrences, since remediation often depends on device manufacturers and may lag significantly behind vendor disclosure. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Thekelleys over time
Signals from CVEs in this vendor scope (40 CVEs).
40 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-14492CRITICAL Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted IPv6 router advertisement req | Oct 3, 2017 | 9.8 | 87 | NO | YES |
CVE-2017-14491CRITICAL Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response. | Oct 4, 2017 | 9.8 | 85 | NO | YES |
CVE-2017-14493CRITICAL Stack-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DHCPv6 request. | Oct 3, 2017 | 9.8 | 84 | NO | YES |
CVE-2017-14495HIGH Memory leak in dnsmasq before 2.78, when the --add-mac, --add-cpe-id or --add-subnet option is specified, allows remote attackers to cause a denial of service (memory consumption) | Oct 3, 2017 | 7.5 | 80 | NO | YES |
CVE-2023-50387HIGH Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more D | Feb 14, 2024 | 7.5 | 78 | NO | NO |
CVE-2017-14496HIGH Integer underflow in the add_pseudoheader function in dnsmasq before 2.78 , when the --add-mac, --add-cpe-id or --add-subnet option is specified, allows remote attackers to cause a | Oct 3, 2017 | 7.5 | 73 | NO | YES |
CVE-2020-25681HIGH A flaw was found in dnsmasq before version 2.83. A heap-based buffer overflow was discovered in the way RRSets are sorted before validating with DNSSEC data. An attacker on the net | Jan 20, 2021 | 8.1 | 71 | NO | NO |
CVE-2017-14494MEDIUM dnsmasq before 2.78, when configured as a relay, allows remote attackers to obtain sensitive memory information via vectors involving handling DHCPv6 forwarded requests. | Oct 3, 2017 | 5.9 | 70 | NO | YES |
CVE-2020-25687MEDIUM A flaw was found in dnsmasq before version 2.83. A heap-based buffer overflow was discovered in dnsmasq when DNSSEC is enabled and before it validates the received DNS entries. Thi | Jan 20, 2021 | 5.9 | 68 | NO | NO |
CVE-2020-25683MEDIUM A flaw was found in dnsmasq before version 2.83. A heap-based buffer overflow was discovered in dnsmasq when DNSSEC is enabled and before it validates the received DNS entries. A r | Jan 20, 2021 | 5.9 | 67 | NO | NO |
Signals from CVEs in this vendor scope (40 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Thekelleys.
Media articles that mention a CVE ID that affects a product developed by Thekelleys — matched by CVE ID, not by vendor name.