VYPR
Vendor

Knot DNS

Products
1
CVEs
4
Across products
4
Status
Private

Products

1

Recent CVEs

4
  • CVE-2016-6171HigFeb 9, 2017
    risk 0.56cvss 8.6epss 0.03

    Knot DNS before 2.3.0 allows remote DNS servers to cause a denial of service (memory exhaustion and slave server crash) via a large zone transfer for (1) DDNS, (2) AXFR, or (3) IXFR.

  • CVE-2014-0486HigMar 27, 2018
    risk 0.49cvss 7.5epss 0.03

    Knot DNS before 1.5.2 allows remote attackers to cause a denial of service (application crash) via a crafted DNS message.

  • CVE-2026-39155MedJul 23, 2026
    risk 0.42cvss 6.5epss 0.00

    Knot DNS before 3.4.10 and 3.5.x before 3.5.4 contains a vulnerability in mod-onlinesign where the next NSEC owner name can be computed incorrectly. This can create an overly broad authenticated denial interval, allowing downstream validating resolvers using aggressive negative…

  • CVE-2017-11104MedJul 8, 2017
    risk 0.39cvss 5.9epss 0.03

    Knot DNS before 2.4.5 and 2.5.x before 2.5.2 contains a flaw within the TSIG protocol implementation that would allow an attacker with a valid key name and algorithm to bypass TSIG authentication if no additional ACL restrictions are set, because of an improper TSIG validity…