Skip to main content

Vendor archive

nlnetlabs CVEs

Beta · best-effort

95 CVEs tagged to vendor nlnetlabs12 Critical, 39 High, 37 Medium, 7 Low, 0 Unrated.

CVE-2017-1000232

Published Nov 17, 2017

A double-free vulnerability in str2host.c in ldns 1.7.0 have unspecified impact and attack vectors.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-1000231

Published Nov 17, 2017

A double-free vulnerability in parse.c in ldns 1.7.0 have unspecified impact and attack vectors.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-6173

Published Feb 9, 2017

NSD before 4.1.11 allows remote DNS master servers to cause a denial of service (/tmp disk consumption and slave server crash) via a zone transfer with unlimited data.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-3209

Published Nov 16, 2014

The ldns-keygen tool in ldns 1.6.x uses the current umask to set the privileges of the private key, which might allow local users to obtain the private key by reading the file.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-2978

Published Jul 27, 2012

query.c in NSD 3.0.x through 3.0.8, 3.1.x through 3.1.1, and 3.2.x before 3.2.12 allows remote attackers to cause a denial of service (NULL pointer dereference and child process c…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3581

Published Nov 4, 2011

Heap-based buffer overflow in the ldns_rr_new_frm_str_internal function in ldns before 1.6.11 allows remote attackers to cause a denial of service (crash) and possibly execute arb…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4008

Published Jun 2, 2011

Unbound before 1.4.4 does not send responses for signed zones after mishandling an unspecified query, which allows remote attackers to cause a denial of service (DNSSEC outage) vi…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1922

Published May 31, 2011

daemon/worker.c in Unbound 1.x before 1.4.10, when debugging functionality and the interface-automatic option are enabled, allows remote attackers to cause a denial of service (as…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0969

Published Mar 16, 2010

Unbound before 1.4.3 does not properly align structures on 64-bit platforms, which allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-3602

Published Oct 13, 2009

Unbound before 1.3.4 does not properly verify signatures for NSEC3 records, which allows remote attackers to cause secure delegations to be downgraded via DNS spoofing or other DN…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-1755

Published May 22, 2009

Off-by-one error in the packet_read_query_section function in packet.c in nsd 3.2.1, and process_query_section in query.c in nsd 2.3.7, allows remote attackers to cause a denial o…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-1086

Published Mar 25, 2009

Heap-based buffer overflow in the ldns_rr_new_frm_str_internal function in ldns 1.4.x allows remote attackers to cause a denial of service (memory corruption) and possibly execute…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 76-95 of 95 CVEsPage 4 of 4