Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Thekelleys

First CVE: May 2, 2005Active for: 21 yearsTotal CVEs: 40
57.8
VTI Score
TOP TARGET

Thekelleys maintains dnsmasq, a widely embedded DNS and DHCP server that appears in countless consumer routers, IoT appliances, and embedded systems despite its narrow product footprint, making it a high-impact supply-chain component whose vulnerabilities propagate across a large installed base. The vendor's disclosures skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting the memory-safety demands of a C-based daemon processing untrusted network input. The recurring weakness classes—out-of-bounds writes, buffer overflows, improper input validation, and memory-access boundary failures—are characteristic of the parser and state-management logic in a network service handling DNS queries and DHCP exchanges from potentially hostile sources. Defenders should treat dnsmasq updates as high-priority and inventory embedded occurrences, since remediation often depends on device manufacturers and may lag significantly behind vendor disclosure. Live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
40
Total CVEs
More Total CVEs than 98% of tracked vendors
2.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
7.1
Avg CVSS Score
Higher Avg CVSS Score than 52% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Thekelleys over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 2, 2005
21 years ago
Most Recent CVE
Jun 23, 2026
31 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (40 CVEs).

40 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2017-14492CRITICAL
Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted IPv6 router advertisement req
Oct 3, 20179.887NOYES
CVE-2017-14491CRITICAL
Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response.
Oct 4, 20179.885NOYES
CVE-2017-14493CRITICAL
Stack-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DHCPv6 request.
Oct 3, 20179.884NOYES
CVE-2017-14495HIGH
Memory leak in dnsmasq before 2.78, when the --add-mac, --add-cpe-id or --add-subnet option is specified, allows remote attackers to cause a denial of service (memory consumption)
Oct 3, 20177.580NOYES
CVE-2023-50387HIGH
Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more D
Feb 14, 20247.578NONO
CVE-2017-14496HIGH
Integer underflow in the add_pseudoheader function in dnsmasq before 2.78 , when the --add-mac, --add-cpe-id or --add-subnet option is specified, allows remote attackers to cause a
Oct 3, 20177.573NOYES
CVE-2020-25681HIGH
A flaw was found in dnsmasq before version 2.83. A heap-based buffer overflow was discovered in the way RRSets are sorted before validating with DNSSEC data. An attacker on the net
Jan 20, 20218.171NONO
CVE-2017-14494MEDIUM
dnsmasq before 2.78, when configured as a relay, allows remote attackers to obtain sensitive memory information via vectors involving handling DHCPv6 forwarded requests.
Oct 3, 20175.970NOYES
CVE-2020-25687MEDIUM
A flaw was found in dnsmasq before version 2.83. A heap-based buffer overflow was discovered in dnsmasq when DNSSEC is enabled and before it validates the received DNS entries. Thi
Jan 20, 20215.968NONO
CVE-2020-25683MEDIUM
A flaw was found in dnsmasq before version 2.83. A heap-based buffer overflow was discovered in dnsmasq when DNSSEC is enabled and before it validates the received DNS entries. A r
Jan 20, 20215.967NONO
View all 40 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products40 CVEs
10%
30%
35%
25%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network33 (82.5%)
Unknown7 (17.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low22 (55.0%)
High11 (27.5%)
Unknown7 (17.5%)
User Interaction
None33 (82.5%)
Unknown7 (17.5%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None33 (82.5%)
Unknown7 (17.5%)

Exploit Exposure

Signals from CVEs in this vendor scope (40 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
8 CVEs
20.0% of CVEs· 78th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Thekelleys.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Thekelleys — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Thekelleys's Products

View all 3 CNAs →

Top CWEs