Skip to main content

CWE archive

CWE-406 CVEs

Programmatic archive

18 CVEs tagged with CWE-4060 Critical, 12 High, 4 Medium, 2 Low, 0 Unrated.

CVE-2026-54609

Published Jul 28, 2026

QTI Neon is a minimal, game-agnostic, relay-based UDP multiplayer protocol library. In version 1.0.0, the relay's handleReconnectRequest forwards RECONNECT_REQUEST packets to the…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-50045

Published Jul 22, 2026

In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a single client query for a deeply nested name under a DNSSEC-signed parent can cause Unbound to send more upstream packet…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-45557

Published May 19, 2026

Technitium DNS Server aggressively tries to fetch missing RRSIG records or mismatched DNSKEY records. An attacker in control of a domain can cause a vulnerable system to generate…

CVSS 6.9 · Medium
evidence mentions
3
Buzz score
25.4

CVE-2025-58066

Published Aug 29, 2025

nptd-rs is a tool for synchronizing your computer's clock, implementing the NTP and NTS protocols. In versions between 1.2.0 and 1.6.1 inclusive servers which allow non-NTS traffi…

CVSS 5.3 · Medium

CVE-2023-49203

Published Sep 18, 2024

Technitium 11.5.3 allows remote attackers to cause a denial of service (bandwidth amplification) because the DNSBomb manipulation causes accumulation of low-rate DNS queries such…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-28456

Published Sep 18, 2024

An issue was discovered in Technitium through 11.0.2. It enables attackers to launch amplification attacks (3 times more than other "golden model" software like BIND) and cause po…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-28455

Published Sep 18, 2024

An issue was discovered in Technitium through 11.0.2. The forwarding mode enables attackers to create a query loop using Technitium resolvers, launching amplification attacks and…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-125036

Published Jan 2, 2023

A vulnerability, which was classified as problematic, has been found in drybjed ansible-ntp. Affected by this issue is some unknown functionality of the file meta/main.yml. The ma…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-0028

Published Aug 10, 2022

A PAN-OS URL filtering policy misconfiguration could allow a network-based attacker to conduct reflected and amplified TCP denial-of-service (RDoS) attacks. The DoS attack would a…

CVSS 8.6 · High
evidence mentions
3
Buzz score
45.4
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2021-4234

Published Jul 6, 2022

OpenVPN Access Server 2.10 and prior versions are susceptible to resending multiple packets in a response to a reset packet sent from the client which the client again does not re…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-43547

Published May 5, 2022

TwinOaks Computing CoreDX DDS versions prior to 5.9.1 are susceptible to exploitation when an attacker sends a specially crafted packet to flood target devices with unwanted traff…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-38429

Published May 5, 2022

OCI OpenDDS versions prior to 3.18.1 are vulnerable when an attacker sends a specially crafted packet to flood target devices with unwanted traffic, which may result in a denial-o…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-38425

Published May 5, 2022

eProsima Fast DDS versions prior to 2.4.0 (#2269) are susceptible to exploitation when an attacker sends a specially crafted packet to flood a target device with unwanted traffic,…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-18 of 18 CVEsPage 1 of 1