← Back

Dproxy Nexgen Project

dproxy-nexgen_project

4 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Dproxy Nexgen
dproxy-nexgen

CVEs (4)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Dproxy Nexgen Project
1Dproxy Nexgen
Nov 21, 2024
Aug 15, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
dproxy-nexgen (aka dproxy nexgen) forwards and caches DNS queries with the CD (aka checking disabled) bit set to 1. This leads to disabling of DNSSEC protection provided by upstream resolvers.
1Dproxy Nexgen Project
1Dproxy Nexgen
Nov 21, 2024
Aug 15, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Misinterpretation of special domain name characters in dproxy-nexgen (aka dproxy nexgen) leads to cache poisoning because domain names and their associated IP addresses are cached in their misinterpreted form.
1Dproxy Nexgen Project
1Dproxy Nexgen
Nov 21, 2024
Aug 15, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
dproxy-nexgen (aka dproxy nexgen) uses a static UDP source port (selected randomly only at boot time) in upstream queries sent to DNS resolvers. This allows DNS cache poisoning because there is not enough entropy to prev...Show more
dproxy-nexgen (aka dproxy nexgen) uses a static UDP source port (selected randomly only at boot time) in upstream queries sent to DNS resolvers. This allows DNS cache poisoning because there is not enough entropy to prevent traffic injection attacks.Show less
1Dproxy Nexgen Project
1Dproxy Nexgen
Nov 21, 2024
Aug 15, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
dproxy-nexgen (aka dproxy nexgen) re-uses the DNS transaction id (TXID) value from client queries, which allows attackers (able to send queries to the resolver) to conduct DNS cache-poisoning attacks because the TXID val...Show more
dproxy-nexgen (aka dproxy nexgen) re-uses the DNS transaction id (TXID) value from client queries, which allows attackers (able to send queries to the resolver) to conduct DNS cache-poisoning attacks because the TXID value is known to the attacker.Show less