Known Vulnerabilities for C-ares by C-ares Project
Listed below are 10 of the newest known vulnerabilities associated with "C-ares" by "C-ares Project".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-69186 json | c-ares is an asynchronous resolver library. Prior to 1.34.7, ares_dns_parse() trusts the attacker-controlled ANCOUNT, NSCOUNT... | Not Provided | 2026-09-18 | 2026-09-18 |
| CVE-2026-69184 json | c-ares is an asynchronous resolver library. Prior to 1.34.7, ares_dns_name_parse() enforces backward DNS compression pointers... | Not Provided | 2026-09-18 | 2026-09-21 |
| CVE-2026-33630 json | c-ares is an asynchronous resolver library. From ver 1.32.3 until 1.34.7, a use-after-free / double-free in c-ares' query-com... | Not Provided | 2026-09-03 | 2026-09-05 |
| CVE-2024-38570 json | In the Linux kernel, the following vulnerability has been resolved: gfs2: Fix potential glock use-after-free on unmount Whe... | Not Provided | 2024-06-19 | 2026-08-04 |
| CVE-2024-23682 json | Artemis Java Test Sandbox versions before 1.8.0 are vulnerable to a sandbox escape when an attacker includes class files in a... | Not Provided | 2024-01-19 | 2026-07-14 |
| CVE-2023-32067 json | c-ares is an asynchronous resolver library. c-ares is vulnerable to denial of service. If a target resolver sends a query, th... | 7.5 - HIGH | 2023-05-25 | 2023-10-31 |
| CVE-2023-31147 json | c-ares is an asynchronous resolver library. When /dev/urandom or RtlGenRandom() are unavailable, c-ares uses rand() to genera... | 6.5 - MEDIUM | 2023-05-25 | 2023-10-31 |
| CVE-2023-31130 json | c-ares is an asynchronous resolver library. ares_inet_net_pton() is vulnerable to a buffer underflow for certain ipv6 address... | 6.4 - MEDIUM | 2023-05-25 | 2023-10-31 |
| CVE-2023-31124 json | c-ares is an asynchronous resolver library. When cross-compiling c-ares and using the autotools build system, CARES_RANDOM_FI... | 3.7 - LOW | 2023-05-25 | 2023-10-31 |
| CVE-2022-4904 json | A flaw was found in the c-ares package. The ares_set_sortlist is missing checks about the validity of the input string, which... | 8.6 - HIGH | 2023-03-06 | 2024-01-05 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | C-ares Project | C-ares | 1.9.1 | |||
| Application | C-ares Project | C-ares | 1.9.0 | |||
| Application | C-ares Project | C-ares | 1.8.0 | |||
| Application | C-ares Project | C-ares | 1.7.5 | |||
| Application | C-ares Project | C-ares | 1.7.4 | |||
| Application | C-ares Project | C-ares | 1.7.3 | |||
| Application | C-ares Project | C-ares | 1.7.2 | |||
| Application | C-ares Project | C-ares | 1.7.1 | |||
| Application | C-ares Project | C-ares | 1.7.0 | |||
| Application | C-ares Project | C-ares | 1.6.0 | |||
| Application | C-ares Project | C-ares | 1.5.3 | |||
| Application | C-ares Project | C-ares | 1.5.2 | |||
| Application | C-ares Project | C-ares | 1.5.1 | |||
| Application | C-ares Project | C-ares | 1.5.0 | |||
| Application | C-ares Project | C-ares | 1.4.0 | |||
| Application | C-ares Project | C-ares | 1.3.2 | |||
| Application | C-ares Project | C-ares | 1.3.1 | |||
| Application | C-ares Project | C-ares | 1.3.0 | |||
| Application | C-ares Project | C-ares | 1.2.1 | |||
| Application | C-ares Project | C-ares | 1.2.0 |