CVE-2022-3204
- EPSS 1.34%
- Veröffentlicht 26.09.2022 14:15:11
- Zuletzt bearbeitet 05.05.2025 16:15:19
A vulnerability named 'Non-Responsive Delegation Attack' (NRDelegation Attack) has been discovered in various DNS resolving software. The NRDelegation Attack works by having a malicious delegation with a considerable number of non responsive nameserv...
CVE-2022-30699
- EPSS 1.05%
- Veröffentlicht 01.08.2022 15:15:09
- Zuletzt bearbeitet 21.11.2024 07:03:11
NLnet Labs Unbound, up to and including version 1.16.1, is vulnerable to a novel type of the "ghost domain names" attack. The vulnerability works by targeting an Unbound instance. Unbound is queried for a rogue domain name when the cached delegation ...
CVE-2022-30698
- EPSS 1.05%
- Veröffentlicht 01.08.2022 15:15:09
- Zuletzt bearbeitet 21.11.2024 07:03:11
NLnet Labs Unbound, up to and including version 1.16.1 is vulnerable to a novel type of the "ghost domain names" attack. The vulnerability works by targeting an Unbound instance. Unbound is queried for a subdomain of a rogue domain name. The rogue na...
CVE-2019-25036
- EPSS 1.99%
- Veröffentlicht 27.04.2021 06:15:07
- Zuletzt bearbeitet 21.11.2024 04:39:47
Unbound before 1.9.5 allows an assertion failure and denial of service in synth_cname. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited
CVE-2019-25031
- EPSS 1.34%
- Veröffentlicht 27.04.2021 06:15:07
- Zuletzt bearbeitet 25.08.2026 10:55:42
Unbound before 1.9.5 allows configuration injection in create_unbound_ad_servers.sh upon a successful man-in-the-middle attack against a cleartext HTTP session. NOTE: The vendor does not consider this a vulnerability of the Unbound software. create_u...
CVE-2019-25032
- EPSS 2.18%
- Veröffentlicht 27.04.2021 06:15:07
- Zuletzt bearbeitet 21.11.2024 04:39:47
Unbound before 1.9.5 allows an integer overflow in the regional allocator via regional_alloc. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally ex...
CVE-2019-25033
- EPSS 1.78%
- Veröffentlicht 27.04.2021 06:15:07
- Zuletzt bearbeitet 21.11.2024 04:39:47
Unbound before 1.9.5 allows an integer overflow in the regional allocator via the ALIGN_UP macro. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locall...
CVE-2019-25034
- EPSS 2.04%
- Veröffentlicht 27.04.2021 06:15:07
- Zuletzt bearbeitet 21.11.2024 04:39:47
Unbound before 1.9.5 allows an integer overflow in sldns_str2wire_dname_buf_origin, leading to an out-of-bounds write. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot ...
CVE-2019-25035
- EPSS 2.04%
- Veröffentlicht 27.04.2021 06:15:07
- Zuletzt bearbeitet 21.11.2024 04:39:47
Unbound before 1.9.5 allows an out-of-bounds write in sldns_bget_token_par. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited
CVE-2019-25037
- EPSS 2.13%
- Veröffentlicht 27.04.2021 06:15:07
- Zuletzt bearbeitet 21.11.2024 04:39:47
Unbound before 1.9.5 allows an assertion failure and denial of service in dname_pkt_copy via an invalid packet. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remo...