C-ares
This hub aggregates every CVE we track for C-ares, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
16
CVEs tracked
1
Critical
6
High
0
In CISA KEV
Severity distribution
MEDIUM7HIGH6LOW2CRITICAL1
Monthly trend
0
0
0
0
0
0
0
1
0
0
0
0
0
0
0
1
0
0
0
0
0
0
0
0
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting C-ares.
- CVE-2025-62408c-ares has a Use After Free vulnerability when connection is cleaned up after error5.9
- CVE-2025-31498c-ares has a use-after-free in read_answers()7.0
- CVE-2024-25629c-ares out of bounds read in ares__read_line()4.4
- CVE-2020-22217Buffer overflow vulnerability in c-ares before 1_16_1 thru 1_17_0 via function ares_parse_soa_reply in ares_parse_soa_reply.c.5.9
- CVE-2023-320670-byte UDP payload DoS in c-ares7.5
- CVE-2023-31147Insufficient randomness in generation of DNS query IDs in c-ares5.9
- CVE-2023-31130Buffer Underwrite in ares_inet_net_pton()4.1
- CVE-2023-31124AutoTools does not set CARES_RANDOM_FILE during cross compilation3.7
- CVE-2022-4904A flaw was found in the c-ares package. The ares_set_sortlist is missing checks about the validity of the input string, which allows a possible arbitrary length stack overflow. This issue may cause...8.6
- CVE-2021-3672A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to ...5.6
- CVE-2020-14354A possible use-after-free and double-free in c-ares lib version 1.16.0 if ares_destroy() is called prior to ares_getaddrinfo() completing. This flaw possibly allows an attacker to crash the service...3.3
- CVE-2020-8277A Node.js application that allows an attacker to trigger a DNS request for a host of their choice could trigger a Denial of Service in versions < 15.2.1, < 14.15.1, and < 12.19.1 by getting the app...7.5
- CVE-2017-1000381The c-ares function `ares_parse_naptr_reply()`, which is used for parsing NAPTR responses, could be triggered to read memory outside of the given input buffer if the passed in DNS response packet w...7.5
- CVE-2016-5180Heap-based buffer overflow in the ares_create_query function in c-ares 1.x before 1.12.0 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly execute arbitrary cod...9.8
- CVE-2007-3153The ares_init:randomize_key function in c-ares, on platforms other than Windows, uses a weak facility for producing a random number sequence (Unix rand), which makes it easier for remote attackers ...5.0
Product normalization is registry-driven with AI assist and human review. How it works