Tinysvcmdns Project maintains a compact mDNS (multicast DNS) service discovery library used in embedded systems and network applications for device advertisement and discovery. The product's vulnerability footprint centers on memory-safety and control-flow weaknesses, including buffer boundary violations, infinite loops, null-pointer dereferences, and out-of-bounds reads that are characteristic of low-level network protocol parsing. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tinysvcmdns Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-12087CRITICAL An exploitable heap overflow vulnerability exists in the tinysvcmdns library version 2016-07-18. A specially crafted packet can make the library overwrite an arbitrary amount of da | Apr 24, 2018 | 9.8 | 30 | NO | NO |
CVE-2019-9748CRITICAL In tinysvcmdns through 2018-01-16, an mDNS server processing a crafted packet can perform arbitrary data read operations up to 16383 bytes from the start of the buffer. This can le | Mar 13, 2019 | 9.1 | 28 | NO | NO |
CVE-2017-12130HIGH An exploitable NULL pointer dereference vulnerability exists in the tinysvcmdns library version 2017-11-05. A specially crafted packet can make the library dereference a NULL point | Jan 20, 2018 | 7.5 | 25 | NO | NO |
CVE-2019-9747HIGH In tinysvcmdns through 2018-01-16, a maliciously crafted mDNS (Multicast DNS) packet triggers an infinite loop while parsing an mDNS query. When mDNS compressed labels point to eac | Mar 13, 2019 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tinysvcmdns Project.
Media articles that mention a CVE ID that affects a product developed by Tinysvcmdns Project — matched by CVE ID, not by vendor name.