← Back

Nlnetlabs

nlnetlabs

72 CVEs • 7 products

Products (7)

Click to collapse
Toggle
Unbound
unbound
Routinator
routinator
Ldns
ldns
Nsd
nsd
Krill
krill
Bcder
bcder

CVEs (72)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Nlnetlabs
1Ldns
May 13, 2026
Nov 17, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A double-free vulnerability in parse.c in ldns 1.7.0 have unspecified impact and attack vectors.
1Nlnetlabs
1Nsd
May 13, 2026
Feb 9, 2017
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
NSD before 4.1.11 allows remote DNS master servers to cause a denial of service (/tmp disk consumption and slave server crash) via a zone transfer with unlimited data.
3Canonical
DebianNlnetlabs
3Debian Linux
Ubuntu LinuxUnbound
May 6, 2026
Dec 11, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
iterator.c in NLnet Labs Unbound before 1.5.1 does not limit delegation chaining, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a large or infinite number of referrals.
1Nlnetlabs
1Ldns
May 6, 2026
Nov 16, 2014
N/A· v4
N/A· v3
2.1 LOW· v2
The ldns-keygen tool in ldns 1.6.x uses the current umask to set the privileges of the private key, which might allow local users to obtain the private key by reading the file.
1Nlnetlabs
1Nsd
Apr 29, 2026
Jul 27, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
query.c in NSD 3.0.x through 3.0.8, 3.1.x through 3.1.1, and 3.2.x before 3.2.12 allows remote attackers to cause a denial of service (NULL pointer dereference and child process crash) via a crafted DNS packet.
1Nlnetlabs
1Ldns
Apr 29, 2026
Nov 4, 2011
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Heap-based buffer overflow in the ldns_rr_new_frm_str_internal function in ldns before 1.6.11 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a Resource Record (RR) wi...Show more
Heap-based buffer overflow in the ldns_rr_new_frm_str_internal function in ldns before 1.6.11 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a Resource Record (RR) with an unknown type containing input that is longer than a specified length.Show less
1Nlnetlabs
1Unbound
Apr 29, 2026
Jun 2, 2011
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Unbound before 1.4.4 does not send responses for signed zones after mishandling an unspecified query, which allows remote attackers to cause a denial of service (DNSSEC outage) via a crafted query.
1Nlnetlabs
1Unbound
Apr 29, 2026
May 31, 2011
N/A· v4
N/A· v3
4.3 MEDIUM· v2
daemon/worker.c in Unbound 1.x before 1.4.10, when debugging functionality and the interface-automatic option are enabled, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a cr...Show more
daemon/worker.c in Unbound 1.x before 1.4.10, when debugging functionality and the interface-automatic option are enabled, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted DNS request that triggers improper error handling.Show less
1Nlnetlabs
1Unbound
Apr 29, 2026
Mar 16, 2010
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Unbound before 1.4.3 does not properly align structures on 64-bit platforms, which allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors.
1Nlnetlabs
1Unbound
Apr 23, 2026
Oct 13, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Unbound before 1.3.4 does not properly verify signatures for NSEC3 records, which allows remote attackers to cause secure delegations to be downgraded via DNS spoofing or other DNS-related attacks in conjunction with cra...Show more
Unbound before 1.3.4 does not properly verify signatures for NSEC3 records, which allows remote attackers to cause secure delegations to be downgraded via DNS spoofing or other DNS-related attacks in conjunction with crafted delegation responses.Show less
1Nlnetlabs
1Nsd
Apr 23, 2026
May 22, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Off-by-one error in the packet_read_query_section function in packet.c in nsd 3.2.1, and process_query_section in query.c in nsd 2.3.7, allows remote attackers to cause a denial of service (crash) and possibly execute ar...Show more
Off-by-one error in the packet_read_query_section function in packet.c in nsd 3.2.1, and process_query_section in query.c in nsd 2.3.7, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors that trigger a buffer overflow.Show less
1Nlnetlabs
1Ldns
Apr 23, 2026
Mar 25, 2009
N/A· v4
N/A· v3
6.4 MEDIUM· v2
Heap-based buffer overflow in the ldns_rr_new_frm_str_internal function in ldns 1.4.x allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via a DNS resource record...Show more
Heap-based buffer overflow in the ldns_rr_new_frm_str_internal function in ldns 1.4.x allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via a DNS resource record (RR) with a long (1) class field (clas variable) and possibly (2) TTL field.Show less