Nsd
by Nlnetlabs
Source repositories
CVEs (11)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-13207 | Cri | 0.64 | 9.8 | 0.02 | Jul 3, 2019 | nsd-checkzone in NLnet Labs NSD 4.2.0 has a Stack-based Buffer Overflow in the dname_concatenate() function in dname.c. | ||
| CVE-2026-12244 | Hig | 0.50 | 8.8 | 0.00 | Jun 25, 2026 | If NSD is configured as secondary for a zone, the primary of that zone can crash NSD with an AXFR containing a DNS message with a special crafted SVCB RR with an rdata size of 65512, that let's an (uint16_t) variable that is used to allocate space needed for the RR wrap (because… | ||
| CVE-2016-6173 | Hig | 0.49 | 7.5 | 0.03 | Feb 9, 2017 | NSD before 4.1.11 allows remote DNS master servers to cause a denial of service (/tmp disk consumption and slave server crash) via a zone transfer with unlimited data. | ||
| CVE-2026-12246 | Hig | 0.46 | 8.1 | 0.00 | Jun 25, 2026 | NSD version 4.14.0 introduced a bug where a specially crafted APL RR, with an adflength larger than permitted for the address family will overwrite the stack when the zone is written to disk, with a maximum of 111 attacker controlled bytes. | ||
| CVE-2026-19538 | Hig | 0.42 | 7.5 | 0.00 | Aug 26, 2026 | The BLOCKED access control list items that are evaluated to deny access on the the proxy protocol port can be bypassed completely when connecting over TCP or TLS and sending the query twice on connection that is kept open. | ||
| CVE-2026-12490 | Hig | 0.42 | 7.5 | 0.00 | Jun 25, 2026 | When a provide-xfr is given with a tls-auth-name, a secondary requesting a transfer should provide a client certificate with that name. However, no client certificate is needed when the request comes in over TLS over the regular tls-port (and not the tls-auth-port) or over over… | ||
| CVE-2026-12245 | Hig | 0.42 | 7.5 | 0.00 | Jun 25, 2026 | NSD from version 4.13.0 has a heap use-after-free bug in logging errors on TLS connections, causing a crash of the server process, which can be triggered trivially by sending a DNS query over a DoT connection, and closing the connection without reading the response. | ||
| CVE-2013-5661 | Med | 0.39 | 5.9 | 0.03 | Nov 5, 2019 | Cache Poisoning issue exists in DNS Response Rate Limiting. | ||
| CVE-2020-28935 | Med | 0.36 | 5.5 | 0.00 | Dec 7, 2020 | NLnet Labs Unbound, up to and including version 1.12.0, and NLnet Labs NSD, up to and including version 4.3.3, contain a local vulnerability that would allow for a local symlink attack. When writing the PID file, Unbound and NSD create the file if it is not there, or open an… | ||
| CVE-2012-2978 | 0.01 | — | 0.09 | Jul 27, 2012 | query.c in NSD 3.0.x through 3.0.8, 3.1.x through 3.1.1, and 3.2.x before 3.2.12 allows remote attackers to cause a denial of service (NULL pointer dereference and child process crash) via a crafted DNS packet. | |||
| CVE-2009-1755 | 0.00 | — | 0.03 | May 22, 2009 | Off-by-one error in the packet_read_query_section function in packet.c in nsd 3.2.1, and process_query_section in query.c in nsd 2.3.7, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors that trigger a buffer… |
- risk 0.64cvss 9.8epss 0.02
nsd-checkzone in NLnet Labs NSD 4.2.0 has a Stack-based Buffer Overflow in the dname_concatenate() function in dname.c.
- risk 0.50cvss 8.8epss 0.00
If NSD is configured as secondary for a zone, the primary of that zone can crash NSD with an AXFR containing a DNS message with a special crafted SVCB RR with an rdata size of 65512, that let's an (uint16_t) variable that is used to allocate space needed for the RR wrap (because…
- risk 0.49cvss 7.5epss 0.03
NSD before 4.1.11 allows remote DNS master servers to cause a denial of service (/tmp disk consumption and slave server crash) via a zone transfer with unlimited data.
- risk 0.46cvss 8.1epss 0.00
NSD version 4.14.0 introduced a bug where a specially crafted APL RR, with an adflength larger than permitted for the address family will overwrite the stack when the zone is written to disk, with a maximum of 111 attacker controlled bytes.
- risk 0.42cvss 7.5epss 0.00
The BLOCKED access control list items that are evaluated to deny access on the the proxy protocol port can be bypassed completely when connecting over TCP or TLS and sending the query twice on connection that is kept open.
- risk 0.42cvss 7.5epss 0.00
When a provide-xfr is given with a tls-auth-name, a secondary requesting a transfer should provide a client certificate with that name. However, no client certificate is needed when the request comes in over TLS over the regular tls-port (and not the tls-auth-port) or over over…
- risk 0.42cvss 7.5epss 0.00
NSD from version 4.13.0 has a heap use-after-free bug in logging errors on TLS connections, causing a crash of the server process, which can be triggered trivially by sending a DNS query over a DoT connection, and closing the connection without reading the response.
- risk 0.39cvss 5.9epss 0.03
Cache Poisoning issue exists in DNS Response Rate Limiting.
- risk 0.36cvss 5.5epss 0.00
NLnet Labs Unbound, up to and including version 1.12.0, and NLnet Labs NSD, up to and including version 4.3.3, contain a local vulnerability that would allow for a local symlink attack. When writing the PID file, Unbound and NSD create the file if it is not there, or open an…
- CVE-2012-2978Jul 27, 2012risk 0.01cvss —epss 0.09
query.c in NSD 3.0.x through 3.0.8, 3.1.x through 3.1.1, and 3.2.x before 3.2.12 allows remote attackers to cause a denial of service (NULL pointer dereference and child process crash) via a crafted DNS packet.
- CVE-2009-1755May 22, 2009risk 0.00cvss —epss 0.03
Off-by-one error in the packet_read_query_section function in packet.c in nsd 3.2.1, and process_query_section in query.c in nsd 2.3.7, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors that trigger a buffer…