Vulnerability index

Browse CVEs

56 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unbound MEDIUM 5.3
CVE-2026-42923

NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability in the DNSSEC validator where the code path to consult the negative cache f…

Fix: 1.25.1+
Fix from $1,600 2026-05-20
Unbound CRITICAL 9.8
CVE-2026-33278

NLnet Labs Unbound 1.19.1 up to and including version 1.25.0 has a vulnerability in the DNSSEC validator that enables denial of service and possible …

Fix: 1.25.1+
Fix from $2,300 2026-05-20
Unbound HIGH 7.5
CVE-2026-40622

NLnet Labs Unbound 1.16.2 up to and including version 1.25.0 has a vulnerability of the 'ghost domain names' family of attacks that could extend the …

Fix: 1.25.1+
Fix from $1,950 2026-05-20
Unbound MEDIUM 5.3
CVE-2026-32792

NLnet Labs Unbound 1.6.2 up to and including version 1.25.0 has a denial of service vulnerability when compiled with DNSCrypt support ('--enable-dnsc…

Fix: 1.25.1+
Fix from $1,600 2026-05-20
Bcder HIGH 7.5
CVE-2023-39914

NLnet Labs' bcder library up to and including version 0.7.2 panics while decoding certain invalid input data rather than rejecting the data with an e…

Fix: 0.7.3+
Fix from $1,950 2023-09-13
Routinator HIGH 7.5
CVE-2023-39915

NLnet Labs' Routinator up to and including version 0.12.1 may crash when trying to parse certain malformed RPKI objects. This is due to insufficient …

Fix: 0.12.2+
Fix from $1,950 2023-09-13
Routinator MEDIUM 6.5
CVE-2023-39916

NLnet Labs’ Routinator 0.9.0 up to and including 0.12.1 as well as 0.14.0 up to and including 0.14.2 contains a possible path traversal vulnerability…

Fix: 0.12.2+
Fix from $1,600 2023-09-13
Krill HIGH 7.5
CVE-2023-0158

NLnet Labs Krill supports direct access to the RRDP repository content through its built-in web server at the "/rrdp" endpoint. Prior to 0.12.1 a dir…

Fix: 0.12.1+
Fix from $1,950 2023-01-17
Routinator HIGH 7.5
CVE-2022-3029

In NLnet Labs Routinator 0.9.0 up to and including 0.11.2, due to a mistake in error handling, data in RRDP snapshot and delta files that isn’t corre…

Fix: after 0.11.2
Fix from $1,950 2022-09-13
Ldns HIGH 7.5
CVE-2020-19861

When a zone file in ldns 1.7.1 is parsed, the function ldns_nsec3_salt_data is too trusted for the length value obtained from the zone file. When the…

No fix yet
Fix from $1,950 2022-01-21
Ldns MEDIUM 6.5
CVE-2020-19860

When ldns version 1.7.1 verifies a zone file, the ldns_rr_new_frm_str_internal function has a heap out of bounds read vulnerability. An attacker can …

Patch available
Fix from $1,600 2022-01-21
Routinator HIGH 7.5
CVE-2021-43172

NLnet Labs Routinator prior to 0.10.2 happily processes a chain of RRDP repositories of infinite length causing it to never finish a validation run. …

Fix: 0.10.2+
Fix from $1,950 2021-11-09
Routinator HIGH 7.5
CVE-2021-41531

NLnet Labs Routinator prior to 0.10.0 produces invalid RTR payload if an RPKI CA uses too large values in the max-length parameter in a ROA. This wil…

Fix: 0.10.0+
Fix from $1,950 2021-09-21
Unbound HIGH 7.5
CVE-2020-10772

An incomplete fix for CVE-2020-12662 was shipped for Unbound in Red Hat Enterprise Linux 7, as part of erratum RHSA-2020:2414. Vulnerable versions of…

Mitigation only
Fix from $1,950 2020-11-27
Routinator HIGH 7.4
CVE-2020-17366

An issue was discovered in NLnet Labs Routinator 0.1.0 through 0.7.1. It allows remote attackers to bypass intended access restrictions or to cause a…

Fix: after 0.7.1
Fix from $1,950 2020-08-05
Name Server Daemon CRITICAL 9.8
CVE-2019-13207

nsd-checkzone in NLnet Labs NSD 4.2.0 has a Stack-based Buffer Overflow in the dname_concatenate() function in dname.c.

No fix yet
Fix from $2,300 2019-07-03
Ldns CRITICAL 9.8
CVE-2017-1000231

A double-free vulnerability in parse.c in ldns 1.7.0 have unspecified impact and attack vectors.

Patch available
Fix from $2,300 2017-11-17
Ldns CRITICAL 9.8
CVE-2017-1000232

A double-free vulnerability in str2host.c in ldns 1.7.0 have unspecified impact and attack vectors.

No fix yet
Fix from $2,300 2017-11-17
Nsd HIGH 7.5
CVE-2016-6173

NSD before 4.1.11 allows remote DNS master servers to cause a denial of service (/tmp disk consumption and slave server crash) via a zone transfer wi…

Fix: after 4.1.10
Fix from $1,950 2017-02-09
Nsd MEDIUM 5.0
CVE-2012-2978EPSS 9%

query.c in NSD 3.0.x through 3.0.8, 3.1.x through 3.1.1, and 3.2.x before 3.2.12 allows remote attackers to cause a denial of service (NULL pointer d…

Mitigation only
Fix from $1,600 2012-07-27
Ldns MEDIUM 6.8
CVE-2011-3581

Heap-based buffer overflow in the ldns_rr_new_frm_str_internal function in ldns before 1.6.11 allows remote attackers to cause a denial of service (c…

Fix: after 1.6.10
Fix from $1,600 2011-11-04
Unbound MEDIUM 5.0
CVE-2009-4008

Unbound before 1.4.4 does not send responses for signed zones after mishandling an unspecified query, which allows remote attackers to cause a denial…

Fix: after 1.4.3
Fix from $1,600 2011-06-02
Unbound MEDIUM 5.0
CVE-2010-0969

Unbound before 1.4.3 does not properly align structures on 64-bit platforms, which allows remote attackers to cause a denial of service (daemon crash…

Fix: after 1.4.2
Fix from $1,600 2010-03-16
Unbound HIGH 7.5
CVE-2009-3602

Unbound before 1.3.4 does not properly verify signatures for NSEC3 records, which allows remote attackers to cause secure delegations to be downgrade…

Fix: after 1.3.3
Fix from $1,950 2009-10-13
Nsd MEDIUM 5.0
CVE-2009-1755

Off-by-one error in the packet_read_query_section function in packet.c in nsd 3.2.1, and process_query_section in query.c in nsd 2.3.7, allows remote…

Patch available
Fix from $1,600 2009-05-22
Ldns MEDIUM 6.4
CVE-2009-1086

Heap-based buffer overflow in the ldns_rr_new_frm_str_internal function in ldns 1.4.x allows remote attackers to cause a denial of service (memory co…

Mitigation only
Fix from $1,600 2009-03-25