Skip to main content

Vendor/product archive

nic / knot_resolver CVEs

Beta · best-effort

14 CVEs tagged to nic / knot_resolver0 Critical, 10 High, 3 Medium, 1 Low, 0 Unrated.

CVE-2023-50387

Published Feb 14, 2024

Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5

CVE-2023-46317

Published Oct 22, 2023

Knot Resolver before 5.7.0 performs many TCP reconnections upon receiving certain nonsensical responses from servers.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-26249

Published Feb 21, 2023

Knot Resolver before 5.6.0 enables attackers to consume its resources, launching amplification attacks and potentially causing a denial of service. Specifically, a single client q…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-32983

Published Jun 20, 2022

Knot Resolver through 5.5.1 may allow DNS cache poisoning when there is an attempt to limit forwarding actions by filters.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-40083

Published Aug 25, 2021

Knot Resolver before 5.3.2 is prone to an assertion failure, triggerable by a remote attacker in an edge case (NSEC3 with too many iterations used for a positive wildcard proof).

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1110

Published Mar 30, 2021

A flaw was found in knot-resolver before version 2.3.0. Malformed DNS messages may cause denial of service.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-12667

Published May 19, 2020

Knot Resolver before 5.1.1 allows traffic amplification via a crafted DNS answer from an attacker-controlled server, aka an "NXNSAttack" issue. This is triggered by random subdoma…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2019-10191

Published Jul 16, 2019

A vulnerability was discovered in DNS resolver of knot resolver before version 4.1.0 which allows remote attackers to downgrade DNSSEC-secure domains to DNSSEC-insecure state, ope…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-10190

Published Jul 16, 2019

A vulnerability was discovered in DNS resolver component of knot resolver through version 3.2.0 before 4.1.0 which allows remote attackers to bypass DNSSEC validation for non-exis…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-10920

Published Aug 2, 2018

Improper input validation bug in DNS resolver component of Knot Resolver before 2.4.1 allows remote attacker to poison cache.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000002

Published Jan 22, 2018

Improper input validation bugs in DNSSEC validators components in Knot Resolver (prior version 1.5.2) allow attacker in man-in-the-middle position to deny existence of some data i…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort
Showing 1-14 of 14 CVEsPage 1 of 1