Nlnetlabs
nlnetlabs
72 CVEs • 7 products
Products (7)
Click to collapseToggle
Products (7)
Click to collapse
CVEs (72)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Nlnetlabs2Debian Linux UnboundJun 17, 2026 Apr 27, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Unbound before 1.9.5 allows an integer overflow in a size calculation in respip/respip.c. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot...Show more |
2Debian Nlnetlabs2Debian Linux UnboundJun 17, 2026 Apr 27, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Unbound before 1.9.5 allows an integer overflow in a size calculation in dnscrypt/dnscrypt.c. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation ca...Show more |
2Debian Nlnetlabs2Debian Linux UnboundJun 17, 2026 Apr 27, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Unbound before 1.9.5 allows an assertion failure and denial of service in dname_pkt_copy via an invalid packet. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbou...Show more |
2Debian Nlnetlabs2Debian Linux UnboundJun 17, 2026 Apr 27, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Unbound before 1.9.5 allows an assertion failure and denial of service in synth_cname. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be...Show more |
2Debian Nlnetlabs2Debian Linux UnboundJun 17, 2026 Apr 27, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Unbound before 1.9.5 allows an out-of-bounds write in sldns_bget_token_par. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely o...Show more |
2Debian Nlnetlabs2Debian Linux UnboundJun 17, 2026 Apr 27, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Unbound before 1.9.5 allows an integer overflow in sldns_str2wire_dname_buf_origin, leading to an out-of-bounds write. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a runnin...Show more |
2Debian Nlnetlabs2Debian Linux UnboundJun 17, 2026 Apr 27, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Unbound before 1.9.5 allows an integer overflow in the regional allocator via the ALIGN_UP macro. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installatio...Show more |
2Debian Nlnetlabs2Debian Linux UnboundJun 17, 2026 Apr 27, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Unbound before 1.9.5 allows an integer overflow in the regional allocator via regional_alloc. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation ca...Show more |
2Debian Nlnetlabs2Debian Linux UnboundJun 17, 2026 Apr 27, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Unbound before 1.9.5 allows configuration injection in create_unbound_ad_servers.sh upon a successful man-in-the-middle attack against a cleartext HTTP session. NOTE: The vendor does not consider this a vulnerability of...Show more |
2Debian Nlnetlabs3Debian Linux Name Server DaemonUnboundJun 17, 2026 Dec 7, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 NLnet Labs Unbound, up to and including version 1.12.0, and NLnet Labs NSD, up to and including version 4.3.3, contain a local vulnerability that would allow for a local symlink attack. When writing the PID file, Unbound...Show more |
An incomplete fix for CVE-2020-12662 was shipped for Unbound in Red Hat Enterprise Linux 7, as part of erratum RHSA-2020:2414. Vulnerable versions of Unbound could still amplify an incoming query into a large number of q...Show more |
An issue was discovered in NLnet Labs Routinator 0.1.0 through 0.7.1. It allows remote attackers to bypass intended access restrictions or to cause a denial of service on dependent routing systems by strategically withho...Show more |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 May 19, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Unbound before 1.10.1 has an infinite loop via malformed DNS answers received from upstream servers. |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 May 19, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Unbound before 1.10.1 has Insufficient Control of Network Message Volume, aka an "NXNSAttack" issue. This is triggered by random subdomains in the NSDNAME in NS records. |
3Fedoraproject NlnetlabsOpensuse3Fedora LeapUnboundJun 17, 2026 Nov 19, 2019 N/A· v4 7.3 HIGH· v3 6.8 MEDIUM· v2 Unbound 1.6.4 through 1.9.4 contain a vulnerability in the ipsec module that can cause shell code execution after receiving a specially crafted answer. This issue can only be triggered if unbound was compiled with `--ena...Show more |
4Isc NicNlnetlabs+1 more4Bind Enterprise LinuxKnot Resolver+1 moreNov 21, 2024 Nov 5, 2019 N/A· v4 5.9 MEDIUM· v3 2.6 LOW· v2 Cache Poisoning issue exists in DNS Response Rate Limiting. |
2Canonical Nlnetlabs2Ubuntu Linux UnboundJun 17, 2026 Oct 3, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Unbound before 1.9.4 accesses uninitialized memory, which allows remote attackers to trigger a crash via a crafted NOTIFY query. The source IP address of the query must match an access-control rule. |
1Nlnetlabs 1Name Server Daemon Jun 17, 2026 Jul 3, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 nsd-checkzone in NLnet Labs NSD 4.2.0 has a Stack-based Buffer Overflow in the dname_concatenate() function in dname.c. |
3Canonical DebianNlnetlabs3Debian Linux Ubuntu LinuxUnboundNov 21, 2024 Jan 23, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A flaw was found in the way unbound before 1.6.8 validated wildcard-synthesized NSEC records. An improperly validated wildcard NSEC record could be used to prove the non-existence (NXDOMAIN answer) of an existing wildcar...Show more |
A double-free vulnerability in str2host.c in ldns 1.7.0 have unspecified impact and attack vectors. |