Total vulnerabilities in the database
The c-ares function ares_parse_naptr_reply()
, which is used for parsing NAPTR responses, could be triggered to read memory outside of the given input buffer if the passed in DNS response packet was crafted in a particular way.
Software | From | Fixed in |
---|---|---|
c-ares_project / c-ares | 1.11.0-rc1 | 1.11.0-rc1.x |
c-ares_project / c-ares | 1.11.0 | 1.11.0.x |
nodejs / node.js | 4.0.0 | 4.1.2.x |
nodejs / node.js | 6.0.0 | 6.8.1.x |
nodejs / node.js | 4.2.0 | 4.8.4 |
nodejs / node.js | 8.0.0 | 8.1.4 |
nodejs / node.js | 7.0.0 | 7.10.1 |
nodejs / node.js | 6.9.0 | 6.11.1 |
nodejs / node.js | 5.0.0 | 5.12.0.x |
c-ares / c-ares | 1.9.1 | 1.9.1.x |
c-ares / c-ares | 1.8.0 | 1.8.0.x |
c-ares / c-ares | 1.10.0 | 1.10.0.x |
c-ares / c-ares | 1.9.0 | 1.9.0.x |
c-ares / c-ares | 1.12.0 | 1.12.0.x |