Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
dproxy vulnerabilities and exploits
(subscribe to this query)
10
CVSSv2
CVE-2007-1866
Stack-based buffer overflow in the dns_decode_reverse_name function in dns_decode.c in dproxy-nexgen allows remote malicious users to execute arbitrary code by sending a crafted packet to port 53/udp, a different issue than CVE-2007-1465.
Dproxy Dproxy Nexgen
1 EDB exploit
10
CVSSv2
CVE-2007-1465
Stack-based buffer overflow in dproxy.c for dproxy 0.1 up to and including 0.5 allows remote malicious users to execute arbitrary code via a long DNS query packet to UDP port 53.
Dproxy Dproxy 0.5
Dproxy Dproxy 0.3
Dproxy Dproxy 0.4
Dproxy Dproxy 0.1
Dproxy Dproxy 0.2
1 EDB exploit
NA
CVE-2022-33988
dproxy-nexgen (aka dproxy nexgen) re-uses the DNS transaction id (TXID) value from client queries, which allows attackers (able to send queries to the resolver) to conduct DNS cache-poisoning attacks because the TXID value is known to the attacker.
Dproxy-nexgen Project Dproxy-nexgen -
NA
CVE-2022-33990
Misinterpretation of special domain name characters in dproxy-nexgen (aka dproxy nexgen) leads to cache poisoning because domain names and their associated IP addresses are cached in their misinterpreted form.
Dproxy-nexgen Project Dproxy-nexgen -
NA
CVE-2022-33991
dproxy-nexgen (aka dproxy nexgen) forwards and caches DNS queries with the CD (aka checking disabled) bit set to 1. This leads to disabling of DNSSEC protection provided by upstream resolvers.
Dproxy-nexgen Project Dproxy-nexgen -
NA
CVE-2022-33989
dproxy-nexgen (aka dproxy nexgen) uses a static UDP source port (selected randomly only at boot time) in upstream queries sent to DNS resolvers. This allows DNS cache poisoning because there is not enough entropy to prevent traffic injection attacks.
Dproxy-nexgen Project Dproxy-nexgen -
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
deserialization
CVE-2024-4040
cross-site scripting
CVE-2023-25790
CVE-2024-2961
XML external entity
CVE-2024-26926
CVE-2024-32806
CVE-2024-32711
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started