VYPR

NSD

by NSD

CVEs (4)

  • CVE-2026-18664CriAug 26, 2026
    risk 0.59cvss 9.1epss 0.00

    When ranges are used for access control (i.e. of the form 1.2.3.4-1.2.3.25), because NSD wrongly compares the IP address with the range on little endian systems, IPs that were meant to be allowed may be denied, and, IPs that were meant to be denied access could be allowed. An…

  • CVE-2026-19401HigAug 26, 2026
    risk 0.49cvss 7.5epss 0.00

    Any remote client can crash a (debugging/non-release build type) NSD serve child by sending it a special crafted message with a specially tuned number of DNS Cookie options (17 when UDP payload size is 512). By continuously crashing the serve childs, the remote client can…

  • CVE-2026-18916HigAug 26, 2026
    risk 0.49cvss 7.5epss 0.00

    Any remote client can crash a NSD serve child, by throttling the TCP receive window after a TCP query. By continuously crashing the serve childs, the remote client can denial all TCP service to this NSD instance.

  • CVE-2016-6173HigFeb 9, 2017
    risk 0.49cvss 7.5epss 0.03

    NSD before 4.1.11 allows remote DNS master servers to cause a denial of service (/tmp disk consumption and slave server crash) via a zone transfer with unlimited data.