← Back

Totd

totd

Vendor: Totd Project • 2 CVEs

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Totd Project
1Totd
Jun 17, 2026
Aug 15, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
totd 1.5.3 uses a fixed UDP source port in upstream queries sent to DNS resolvers. This allows DNS cache poisoning because there is not enough entropy to prevent traffic injection attacks.
1Totd Project
1Totd
Jun 17, 2026
Jun 23, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
totd before 1.5.3 does not properly randomize mesg IDs.