Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
nlnetlabs unbound vulnerabilities and exploits
(subscribe to this query)
6.8
CVSSv2
CVE-2019-18934
Unbound 1.6.4 up to and including 1.9.4 contain a vulnerability in the ipsec module that can cause shell code execution after receiving a specially crafted answer. This issue can only be triggered if unbound was compiled with `--enable-ipsecmod` support, and ipsecmod is enabled a...
Nlnetlabs Unbound
Fedoraproject Fedora 31
Opensuse Leap 15.1
Opensuse Leap 15.2
5
CVSSv2
CVE-2019-16866
Unbound prior to 1.9.4 accesses uninitialized memory, which allows remote malicious users to trigger a crash via a crafted NOTIFY query. The source IP address of the query must match an access-control rule.
Nlnetlabs Unbound
Canonical Ubuntu Linux 19.04
5
CVSSv2
CVE-2017-15105
A flaw was found in the way unbound prior to 1.6.8 validated wildcard-synthesized NSEC records. An improperly validated wildcard NSEC record could be used to prove the non-existence (NXDOMAIN answer) of an existing wildcard record, or trick unbound into accepting a NODATA proof.
Nlnetlabs Unbound
Debian Debian Linux 8.0
Debian Debian Linux 7.0
Canonical Ubuntu Linux 16.04
Canonical Ubuntu Linux 14.04
Canonical Ubuntu Linux 18.04
Canonical Ubuntu Linux 17.10
1 Github repository
4.3
CVSSv2
CVE-2014-8602
iterator.c in NLnet Labs Unbound prior to 1.5.1 does not limit delegation chaining, which allows remote malicious users to cause a denial of service (memory and CPU consumption) via a large or infinite number of referrals.
Nlnetlabs Unbound
Canonical Ubuntu Linux 14.04
Canonical Ubuntu Linux 14.10
Debian Debian Linux 7.0
5
CVSSv2
CVE-2011-4528
Unbound prior to 1.4.13p2 attempts to free unallocated memory during processing of duplicate CNAME records in a signed zone, which allows remote DNS servers to cause a denial of service (daemon crash) via a crafted response.
Unbound Unbound 1.4.6
Unbound Unbound 1.4.5
Unbound Unbound 1.3.3
Unbound Unbound 1.3.2
Unbound Unbound 1.0.2
Unbound Unbound 1.0.1
Unbound Unbound 1.0.0
Unbound Unbound 0.7
Unbound Unbound 0.6
Unbound Unbound 1.4.12
Unbound Unbound
Unbound Unbound 1.4.10
Unbound Unbound 1.4.9
Unbound Unbound 1.4.2
Unbound Unbound 1.4.1
Unbound Unbound 1.2.1
Unbound Unbound 1.2.0
Unbound Unbound 0.09
Unbound Unbound 0.8
Unbound Unbound 0.3
Unbound Unbound 0.2
Unbound Unbound 1.4.8
5
CVSSv2
CVE-2009-4008
Unbound prior to 1.4.4 does not send responses for signed zones after mishandling an unspecified query, which allows remote malicious users to cause a denial of service (DNSSEC outage) via a crafted query.
Nlnetlabs Unbound 1.0.1
Nlnetlabs Unbound 1.0.2
Nlnetlabs Unbound 0.8
Nlnetlabs Unbound 0.7.2
Nlnetlabs Unbound 1.4.1
Nlnetlabs Unbound 1.4.0
Nlnetlabs Unbound 1.3.4
Nlnetlabs Unbound 1.4.2
Nlnetlabs Unbound 1.2.0
Nlnetlabs Unbound 1.0.0
Nlnetlabs Unbound 0.7.1
Nlnetlabs Unbound 1.1.1
Nlnetlabs Unbound 0.6
Nlnetlabs Unbound 0.4
Nlnetlabs Unbound 1.3.0
Nlnetlabs Unbound 1.3.1
Nlnetlabs Unbound 1.3.2
Nlnetlabs Unbound 1.3.3
Nlnetlabs Unbound 0.10
Nlnetlabs Unbound 0.09
Nlnetlabs Unbound 0.2
Nlnetlabs Unbound 0.1
4.3
CVSSv2
CVE-2011-1922
daemon/worker.c in Unbound 1.x prior to 1.4.10, when debugging functionality and the interface-automatic option are enabled, allows remote malicious users to cause a denial of service (assertion failure and daemon exit) via a crafted DNS request that triggers improper error handl...
Nlnetlabs Unbound 1.0.0
Nlnetlabs Unbound 1.3.1
Nlnetlabs Unbound 1.3.2
Nlnetlabs Unbound 1.4.4
Nlnetlabs Unbound 1.4.5
Nlnetlabs Unbound 1.1.0
Nlnetlabs Unbound 1.2.0
Nlnetlabs Unbound 1.4.0
Nlnetlabs Unbound 1.4.1
Nlnetlabs Unbound 1.4.8
Nlnetlabs Unbound 1.4.9
Nlnetlabs Unbound 1.2.1
Nlnetlabs Unbound 1.3.0
Nlnetlabs Unbound 1.4.2
Nlnetlabs Unbound 1.4.3
Nlnetlabs Unbound 1.1.1
Nlnetlabs Unbound 1.0.1
Nlnetlabs Unbound 1.0.2
Nlnetlabs Unbound 1.3.3
Nlnetlabs Unbound 1.3.4
Nlnetlabs Unbound 1.4.6
Nlnetlabs Unbound 1.4.7
5
CVSSv2
CVE-2010-0969
Unbound prior to 1.4.3 does not properly align structures on 64-bit platforms, which allows remote malicious users to cause a denial of service (daemon crash) via unspecified vectors.
Nlnetlabs Unbound 1.3.1
Nlnetlabs Unbound 1.3.2
Nlnetlabs Unbound 1.3.3
Nlnetlabs Unbound 1.1.0
Nlnetlabs Unbound 0.2
Nlnetlabs Unbound 0.1
Nlnetlabs Unbound 0.0
Nlnetlabs Unbound 0.6
Nlnetlabs Unbound 1.0.2
Nlnetlabs Unbound 0.8
Nlnetlabs Unbound 0.7.2
Nlnetlabs Unbound 0.7.1
Nlnetlabs Unbound 1.4.0
Nlnetlabs Unbound 1.3.4
Nlnetlabs Unbound
Nlnetlabs Unbound 1.3.0
Nlnetlabs Unbound 1.2.0
Nlnetlabs Unbound 1.0.0
Nlnetlabs Unbound 1.1.1
Nlnetlabs Unbound 0.10
Nlnetlabs Unbound 0.4
Nlnetlabs Unbound 1.4.1
7.5
CVSSv2
CVE-2009-3602
Unbound prior to 1.3.4 does not properly verify signatures for NSEC3 records, which allows remote malicious users to cause secure delegations to be downgraded via DNS spoofing or other DNS-related attacks in conjunction with crafted delegation responses.
Nlnetlabs Unbound 1.3.2
Nlnetlabs Unbound 1.3.1
Nlnetlabs Unbound 1.0.1
Nlnetlabs Unbound 1.0.0
Nlnetlabs Unbound 0.7
Nlnetlabs Unbound 0.6
Nlnetlabs Unbound 1.2.0
Nlnetlabs Unbound 1.1.1
Nlnetlabs Unbound 0.09
Nlnetlabs Unbound 0.8
Nlnetlabs Unbound 0.3
Nlnetlabs Unbound 0.2
Nlnetlabs Unbound 0.1
Nlnetlabs Unbound
Nlnetlabs Unbound 1.1.0
Nlnetlabs Unbound 1.0.2
Nlnetlabs Unbound 0.7.2
Nlnetlabs Unbound 0.7.1
Nlnetlabs Unbound 0.0
Nlnetlabs Unbound 1.3.0
Nlnetlabs Unbound 1.2.1
Nlnetlabs Unbound 0.11
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-32976
CVE-2024-33557
CVE-2024-36801
CVE-2024-35654
authentication bypass
CVE-2024-24919
CSRF
code execution
CVE-2024-27348
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3