VYPR

Unbound

by Unbound

Source repositories

CVEs (26)

  • CVE-2011-1922May 31, 2011
    risk 0.01cvss epss 0.07

    daemon/worker.c in Unbound 1.x before 1.4.10, when debugging functionality and the interface-automatic option are enabled, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted DNS request that triggers improper error handling.

  • CVE-2012-1192Feb 17, 2012
    risk 0.00cvss epss 0.01

    The resolver in Unbound before 1.4.11 overwrites cached server names and TTL values in NS records during the processing of a response to an A record query, which allows remote attackers to trigger continued resolvability of revoked domain names via a "ghost domain names" attack.

  • CVE-2011-4869Dec 20, 2011
    risk 0.00cvss epss 0.03

    validator/val_nsec3.c in Unbound before 1.4.13p2 does not properly perform proof processing for NSEC3-signed zones, which allows remote DNS servers to cause a denial of service (daemon crash) via a malformed response that lacks expected NSEC3 records, a different vulnerability…

  • CVE-2011-4528Dec 20, 2011
    risk 0.00cvss epss 0.03

    Unbound before 1.4.13p2 attempts to free unallocated memory during processing of duplicate CNAME records in a signed zone, which allows remote DNS servers to cause a denial of service (daemon crash) via a crafted response.

  • CVE-2010-0969Mar 16, 2010
    risk 0.00cvss epss 0.03

    Unbound before 1.4.3 does not properly align structures on 64-bit platforms, which allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors.

  • CVE-2009-3602Oct 13, 2009
    risk 0.00cvss epss 0.03

    Unbound before 1.3.4 does not properly verify signatures for NSEC3 records, which allows remote attackers to cause secure delegations to be downgraded via DNS spoofing or other DNS-related attacks in conjunction with crafted delegation responses.

Page 2 of 2