ISC / Kea
9 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-3608 | Stack overflow in Kea daemons | HIGH | 7.5 | Mar 25, 2026 |
| CVE-2025-11232 | Invalid characters cause assert | HIGH | 7.5 | Oct 29, 2025 |
| CVE-2025-40779 | Kea crash upon interaction between specific client options and subnet selection | HIGH | 7.5 | Aug 27, 2025 |
| CVE-2025-32803 | Insecure file permissions can result in confidential information leakage | MEDIUM | 4.0 | May 28, 2025 |
| CVE-2025-32802 | Insecure handling of file paths allows multiple local attacks | MEDIUM | 6.1 | May 28, 2025 |
| CVE-2025-32801 | Loading a malicious hook library can lead to local privilege escalation | HIGH | 7.8 | May 28, 2025 |
| CVE-2019-6474 | A packet containing a malformed DUID can cause the kea-dhcp6 server to terminate | MEDIUM | 6.5 | Oct 16, 2019 |
| CVE-2019-6473 | A packet containing a malformed DUID can cause the kea-dhcp6 server to terminate | MEDIUM | 6.5 | Oct 16, 2019 |
| CVE-2019-6472 | A packet containing a malformed DUID can cause the kea-dhcp6 server to terminate | MEDIUM | 6.5 | Oct 16, 2019 |
| CVE-2018-5739 | Failure to release memory may exhaust system resources | HIGH | 7.5 | Jan 16, 2019 |
| CVE-2015-8373 | The kea-dhcp4 and kea-dhcp6 servers 0.9.2 and 1.0.0-beta in ISC Kea, when certain debugging settings are used, allow remote attackers to cause a denial of serv… | MEDIUM | 6.8 | Dec 22, 2015 |
Showing 1 to 9 of 9 CVEs