c
c-ares project
Security Risk Profile
48
/100
mediumSecurity Risk Score
Comprehensive risk assessment based on 9 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from October 3, 2016 to present
9
Total CVEs
5
Critical+High
0
Exploited
0
Unpatched
Threat Assessment
Avg CVSS
7.5
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
0
Critical/High
Risk Level
48/100
medium
Severity Distribution
Critical
1High
4Medium
4Low
0Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
0Age Distribution
Common Weaknesses (CWE)
1
Buffer Overflow
3
2
Input Validation
2
3
XSS
1
4
Infoleak
1
Most Affected Products
1. c-ares c-ares28
2. Nodejs Node.js18
3. ubuntu/c-ares14
4. Fedoraproject Fedora13
5. C-ares Project C-ares10
Recent Vulnerabilities
See more →CVE-2023-32067
CVSS 7.5high
0-byte UDP payload DoS in c-ares
May 24, 2023
CVE-2023-31147
CVSS 6.5medium
Insufficient randomness in generation of DNS query IDs in c-ares
May 24, 2023
CVE-2023-31130
CVSS 6.4medium
Buffer Underwrite in ares_inet_net_pton()
May 24, 2023
CVE-2023-31124
CVSS 6.5medium
AutoTools does not set CARES_RANDOM_FILE during cross compilation
May 24, 2023🔧 No Patch
CVE-2022-4904
CVSS 8.6high
Dec 13, 2022
CVE-2021-3672
CVSS 6.8medium
Jul 30, 2021
CVE-2020-8277
CVSS 7.5high
Nov 12, 2020
CVE-2017-1000381
CVSS 7.5high
Jul 7, 2017
CVE-2016-5180
CVSS 9.8critical
Oct 3, 2016
Monitor c-ares project in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.