Vulnerability index

Browse CVEs

10 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Knot Resolver HIGH 7.5
CVE-2023-46317

Knot Resolver before 5.7.0 performs many TCP reconnections upon receiving certain nonsensical responses from servers.

Fix: 5.7.0+
Fix from $1,950 2023-10-22
Knot Resolver HIGH 7.5
CVE-2023-26249

Knot Resolver before 5.6.0 enables attackers to consume its resources, launching amplification attacks and potentially causing a denial of service. S…

Fix: 5.6.0+
Fix from $1,950 2023-02-21
Knot Resolver MEDIUM 5.3
CVE-2022-32983

Knot Resolver through 5.5.1 may allow DNS cache poisoning when there is an attempt to limit forwarding actions by filters.

Fix: after 5.5.1
Fix from $1,600 2022-06-20
Knot Resolver HIGH 7.5
CVE-2021-40083

Knot Resolver before 5.3.2 is prone to an assertion failure, triggerable by a remote attacker in an edge case (NSEC3 with too many iterations used fo…

Fix: 5.3.2+
Fix from $1,950 2021-08-25
Bird MEDIUM 6.8
CVE-2021-26928

BIRD through 2.0.7 does not provide functionality for password authentication of BGP peers. Because of this, products that use BIRD (which may, for e…

Fix: after 2.0.7
Fix from $1,600 2021-06-04
Knot Resolver HIGH 7.5
CVE-2018-1110

A flaw was found in knot-resolver before version 2.3.0. Malformed DNS messages may cause denial of service.

Fix: 2.3.0+
Fix from $1,950 2021-03-30
Foris CRITICAL 9.8
CVE-2021-3346

Foris before 101.1.1, as used in Turris OS, lacks certain HTML escaping in the login template.

Fix: 101.1+
Fix from $2,300 2021-01-29
Knot Resolver HIGH 7.5
CVE-2020-12667

Knot Resolver before 5.1.1 allows traffic amplification via a crafted DNS answer from an attacker-controlled server, aka an "NXNSAttack" issue. This …

Fix: 5.1.1+
Fix from $1,950 2020-05-19
Knot Resolver MEDIUM 6.8
CVE-2018-10920

Improper input validation bug in DNS resolver component of Knot Resolver before 2.4.1 allows remote attacker to poison cache.

Fix: 2.4.1+
Fix from $1,600 2018-08-02
Knot Cms HIGH 7.5
CVE-2014-0486

Knot DNS before 1.5.2 allows remote attackers to cause a denial of service (application crash) via a crafted DNS message.

Fix: 1.5.2+
Fix from $1,950 2018-03-27