Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
87 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.21% | — | UnboundAI | 16/7/2025 | 17/6/2026 | A multi-vendor cache poisoning vulnerability named 'Rebirthday Attack' has been discovered in caching resolvers that support EDNS Client Subnet (ECS). Unbound is also vulnerable when compiled with ECS support, i.e., '--enable-subnet', AND configured to send ECS information along with queries to upstream name servers,… | |
| Analizada | Media (5.3) | 0.80% | — | Nlnetlabs UnboundDebian Linux | 3/10/2024 | 17/6/2026 | NLnet Labs Unbound up to and including version 1.21.0 contains a vulnerability when handling replies with very large RRsets that it needs to perform name compression for. Malicious upstreams responses with very large RRsets can cause Unbound to spend a considerable time applying name compression to downstream replies.… | |
| Aplazada | Media (4.8) | 0.31% | — | Nlnetlabs UnboundAI | 12/8/2024 | 17/6/2026 | DISPUTE NOTE: this issue does not pose a security risk as it (according to analysis by the original software developer, NLnet Labs) falls within the expected functionality and security controls of the application. Red Hat has made a claim that there is a security risk within Red Hat products. NLnet Labs has no further… | |
| Aplazada | Baja (2.8) | 0.39% | — | Nlnetlabs UnboundAI | 12/8/2024 | 17/6/2026 | DISPUTE NOTE: this issue does not pose a security risk as it (according to analysis by the original software developer, NLnet Labs) falls within the expected functionality and security controls of the application. Red Hat has made a claim that there is a security risk within Red Hat products. NLnet Labs has no further… | |
| Analizada | Alta (7.5) | 2.5% | — | Nlnetlabs UnboundFedoraproject Fedora | 7/3/2024 | 17/6/2026 | NLnet Labs Unbound version 1.18.0 up to and including version 1.19.1 contain a vulnerability that can cause denial of service by a certain code path that can lead to an infinite loop. Unbound 1.18.0 introduced a feature that removes EDE records from responses with size higher than the client's advertised buffer size.… | |
| Modificada | Alta (7.3) | 0.32% | — | Fedoraproject UnboundRedhat Codeready Linux BuilderRedhat Codeready Linux Builder EUSRedhat Codeready Linux Builder EUS FOR Power Little Endian+15 | 15/2/2024 | 6/8/2026 | A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to modify the unbound runtime configuration. If a process can connect over localhost to port 8953, it can alter the configuration of unbound.service. This flaw allows an unprivileged attacker to… | |
| Modificada | Alta (7.5) | 100% | 💥 PoC | Redhat Enterprise LinuxMicrosoft Windows Server 2008Microsoft Windows Server 2012Microsoft Windows Server 2016+9 | 14/2/2024 | 17/6/2026 | Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the "KeyTrap" issue. One of the concerns is that, when there is a zone with many DNSKEY and RRSIG records, the… | |
| Modificada | Alta (7.5) | 1.6% | — | Nlnetlabs UnboundFedoraproject Fedora | 26/9/2022 | 17/6/2026 | A vulnerability named 'Non-Responsive Delegation Attack' (NRDelegation Attack) has been discovered in various DNS resolving software. The NRDelegation Attack works by having a malicious delegation with a considerable number of non responsive nameservers. The attack starts by querying a resolver for a record that… | |
| Modificada | Media (6.5) | 1.1% | — | Nlnetlabs UnboundFedoraproject Fedora | 1/8/2022 | 17/6/2026 | NLnet Labs Unbound, up to and including version 1.16.1, is vulnerable to a novel type of the "ghost domain names" attack. The vulnerability works by targeting an Unbound instance. Unbound is queried for a rogue domain name when the cached delegation information is about to expire. The rogue nameserver delays the… | |
| Modificada | Media (6.5) | 1.1% | — | Nlnetlabs UnboundFedoraproject Fedora | 1/8/2022 | 17/6/2026 | NLnet Labs Unbound, up to and including version 1.16.1 is vulnerable to a novel type of the "ghost domain names" attack. The vulnerability works by targeting an Unbound instance. Unbound is queried for a subdomain of a rogue domain name. The rogue nameserver returns delegation information for the subdomain that… | |
| Modificada | Crítica (9.8) | 2.1% | — | Nlnetlabs UnboundDebian Linux | 27/4/2021 | 17/6/2026 | Unbound before 1.9.5 allows an out-of-bounds write via a compressed name in rdata_copy. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited | |
| Modificada | Alta (7.5) | 2.2% | — | Nlnetlabs UnboundDebian Linux | 27/4/2021 | 17/6/2026 | Unbound before 1.9.5 allows an assertion failure via a compressed name in dname_pkt_copy. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited | |
| Modificada | Alta (7.5) | 2.1% | — | Nlnetlabs UnboundDebian Linux | 27/4/2021 | 17/6/2026 | Unbound before 1.9.5 allows an infinite loop via a compressed name in dname_pkt_copy. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited | |
| Modificada | Crítica (9.8) | 2.1% | — | Nlnetlabs UnboundDebian Linux | 27/4/2021 | 17/6/2026 | Unbound before 1.9.5 allows an integer overflow in a size calculation in respip/respip.c. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited | |
| Modificada | Crítica (9.8) | 2.1% | — | Nlnetlabs UnboundDebian Linux | 27/4/2021 | 17/6/2026 | Unbound before 1.9.5 allows an integer overflow in a size calculation in dnscrypt/dnscrypt.c. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited | |
| Modificada | Alta (7.5) | 2.2% | — | Nlnetlabs UnboundDebian Linux | 27/4/2021 | 17/6/2026 | Unbound before 1.9.5 allows an assertion failure and denial of service in dname_pkt_copy via an invalid packet. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited | |
| Modificada | Alta (7.5) | 2.1% | — | Nlnetlabs UnboundDebian Linux | 27/4/2021 | 17/6/2026 | Unbound before 1.9.5 allows an assertion failure and denial of service in synth_cname. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited | |
| Modificada | Crítica (9.8) | 2.1% | — | Nlnetlabs UnboundDebian Linux | 27/4/2021 | 17/6/2026 | Unbound before 1.9.5 allows an out-of-bounds write in sldns_bget_token_par. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited | |
| Modificada | Crítica (9.8) | 2.1% | — | Nlnetlabs UnboundDebian Linux | 27/4/2021 | 17/6/2026 | Unbound before 1.9.5 allows an integer overflow in sldns_str2wire_dname_buf_origin, leading to an out-of-bounds write. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited | |
| Modificada | Crítica (9.8) | 1.8% | — | Nlnetlabs UnboundDebian Linux | 27/4/2021 | 17/6/2026 | Unbound before 1.9.5 allows an integer overflow in the regional allocator via the ALIGN_UP macro. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited | |
| Modificada | Crítica (9.8) | 2.1% | — | Nlnetlabs UnboundDebian Linux | 27/4/2021 | 17/6/2026 | Unbound before 1.9.5 allows an integer overflow in the regional allocator via regional_alloc. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited | |
| Analizada | Media (5.9) | 1.3% | — | Nlnetlabs UnboundDebian Linux | 27/4/2021 | 25/8/2026 | Unbound before 1.9.5 allows configuration injection in create_unbound_ad_servers.sh upon a successful man-in-the-middle attack against a cleartext HTTP session. NOTE: The vendor does not consider this a vulnerability of the Unbound software. create_unbound_ad_servers.sh is a contributed script from the community that… | |
| Modificada | Media (5.5) | 0.49% | — | Nlnetlabs Name Server DaemonNlnetlabs UnboundDebian Linux | 7/12/2020 | 17/6/2026 | NLnet Labs Unbound, up to and including version 1.12.0, and NLnet Labs NSD, up to and including version 4.3.3, contain a local vulnerability that would allow for a local symlink attack. When writing the PID file, Unbound and NSD create the file if it is not there, or open an existing file for writing. In case the file… | |
| Modificada | Alta (7.5) | 1.3% | — | Nlnetlabs Unbound | 27/11/2020 | 17/6/2026 | An incomplete fix for CVE-2020-12662 was shipped for Unbound in Red Hat Enterprise Linux 7, as part of erratum RHSA-2020:2414. Vulnerable versions of Unbound could still amplify an incoming query into a large number of queries directed to a target, even with a lower amplification ratio compared to versions of Unbound… | |
| Modificada | Alta (7.5) | 3.6% | — | Nlnetlabs UnboundDebian LinuxOpensuse LeapCanonical Ubuntu Linux+1 | 19/5/2020 | 17/6/2026 | Unbound before 1.10.1 has an infinite loop via malformed DNS answers received from upstream servers. |