VYPR
Vendor

Nlnetlabs

Products
9
CVEs
105
Across products
109
Status
Private

Products

9

Recent CVEs

105
View all 105 CVEs →
  • CVE-2019-25042CriApr 27, 2021
    risk 0.64cvss 9.8epss 0.02

    Unbound before 1.9.5 allows an out-of-bounds write via a compressed name in rdata_copy. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited

  • CVE-2019-25034CriApr 27, 2021
    risk 0.64cvss 9.8epss 0.02

    Unbound before 1.9.5 allows an integer overflow in sldns_str2wire_dname_buf_origin, leading to an out-of-bounds write. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally…

  • CVE-2019-25033CriApr 27, 2021
    risk 0.64cvss 9.8epss 0.02

    Unbound before 1.9.5 allows an integer overflow in the regional allocator via the ALIGN_UP macro. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited

  • CVE-2019-25032CriApr 27, 2021
    risk 0.64cvss 9.8epss 0.02

    Unbound before 1.9.5 allows an integer overflow in the regional allocator via regional_alloc. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited

  • CVE-2019-13207CriJul 3, 2019
    risk 0.64cvss 9.8epss 0.02

    nsd-checkzone in NLnet Labs NSD 4.2.0 has a Stack-based Buffer Overflow in the dname_concatenate() function in dname.c.

  • CVE-2017-1000232CriNov 17, 2017
    risk 0.64cvss 9.8epss 0.02

    A double-free vulnerability in str2host.c in ldns 1.7.0 have unspecified impact and attack vectors.

  • CVE-2017-1000231CriNov 17, 2017
    risk 0.64cvss 9.8epss 0.03

    A double-free vulnerability in parse.c in ldns 1.7.0 have unspecified impact and attack vectors.

  • CVE-2026-42960CriMay 20, 2026
    risk 0.58cvss 10.0epss 0.00

    NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to poisoning via promiscuous records for the authority section. Promiscuous RRSets that complement DNS replies in the authority section can be used to trick Unbound to cache such records. If an adversary is able…

  • CVE-2026-33278CriMay 20, 2026
    risk 0.57cvss 9.8epss 0.01

    NLnet Labs Unbound 1.19.1 up to and including version 1.25.0 has a vulnerability in the DNSSEC validator that enables denial of service and possible remote code execution as a result of deep copying a data structure and erroneously overwriting a destination pointer. An adversary…

  • CVE-2019-25039CriApr 27, 2021
    risk 0.57cvss 9.8epss 0.02

    Unbound before 1.9.5 allows an integer overflow in a size calculation in respip/respip.c. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited

  • CVE-2019-25038CriApr 27, 2021
    risk 0.57cvss 9.8epss 0.02

    Unbound before 1.9.5 allows an integer overflow in a size calculation in dnscrypt/dnscrypt.c. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited

  • CVE-2019-25035CriApr 27, 2021
    risk 0.57cvss 9.8epss 0.02

    Unbound before 1.9.5 allows an out-of-bounds write in sldns_bget_token_par. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited

  • CVE-2026-50252CriJul 22, 2026
    risk 0.53cvss 9.3epss 0.00

    In NLnet Labs Unbound 1.4.22 up to and including 1.25.1, UDP source port is randomized and intended to serve as a secret value that increases the entropy of DNS transactions. When resolver load balancing policies depend on the source port while their outcome is revealed this…

  • CVE-2023-39916CriSep 13, 2023
    risk 0.53cvss 9.3epss 0.01

    NLnet Labs’ Routinator 0.9.0 up to and including 0.12.1 as well as 0.14.0 up to and including 0.14.2 contains a possible path traversal vulnerability in the optional, off-by-default keep-rrdp-responses feature that allows users to store the content of responses received for…

  • CVE-2024-1488HigFeb 15, 2024
    risk 0.52cvss 8.0epss 0.00

    A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to modify the unbound runtime configuration. If a process can connect over localhost to port 8953, it can alter the configuration of unbound.service. This…

  • CVE-2026-12244HigJun 25, 2026
    risk 0.50cvss 8.8epss 0.00

    If NSD is configured as secondary for a zone, the primary of that zone can crash NSD with an AXFR containing a DNS message with a special crafted SVCB RR with an rdata size of 65512, that let's an (uint16_t) variable that is used to allocate space needed for the RR wrap (because…

  • CVE-2026-49232HigJun 8, 2026
    risk 0.50cvss epss 0.00

    Routinator exits on any error when accepting incoming HTTP or RTR connections, including ones it can recover from such as running out of file descriptors. This condition can be triggered maliciously by an attacker by opening a large number of connections to the HTTP or RTR…

  • CVE-2023-50387HigFeb 14, 2024
    risk 0.50cvss 7.5epss 1.00

    Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the "KeyTrap" issue. One of the concerns is that, when there is a zone with…

  • CVE-2025-0638HigJan 22, 2025
    risk 0.49cvss 7.5epss 0.00

    The initial code parsing the manifest did not check the content of the file names yet later code assumed that it was checked and panicked when encountering illegal characters, resulting in a crash of Routinator.

  • CVE-2024-1931HigMar 7, 2024
    risk 0.49cvss 7.5epss 0.03

    NLnet Labs Unbound version 1.18.0 up to and including version 1.19.1 contain a vulnerability that can cause denial of service by a certain code path that can lead to an infinite loop. Unbound 1.18.0 introduced a feature that removes EDE records from responses with size higher…