Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
–

115 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)1.3%—Nlnetlabs Ldns21/1/202217/6/2026
When ldns version 1.7.1 verifies a zone file, the ldns_rr_new_frm_str_internal function has a heap out of bounds read vulnerability. An attacker can leak information on the heap by constructing a zone file payload.
ModificadaAlta (7.5)1.2%—Nlnetlabs RoutinatorDebian Linux9/11/202117/6/2026
NLnet Labs Routinator versions 0.9.0 up to and including 0.10.1, support the gzip transfer encoding when querying RRDP repositories. This encoding can be used by an RRDP repository to cause an out-of-memory crash in these versions of Routinator. RRDP uses XML which allows arbitrary amounts of white space in the…
ModificadaAlta (7.5)1.5%—Nlnetlabs RoutinatorDebian Linux9/11/202117/6/2026
In NLnet Labs Routinator prior to 0.10.2, a validation run can be delayed significantly by an RRDP repository by not answering but slowly drip-feeding bytes to keep the connection alive. This can be used to effectively stall validation. While Routinator has a configurable time-out value for RRDP connections, this…
ModificadaAlta (7.5)1.3%—Nlnetlabs Routinator9/11/202117/6/2026
NLnet Labs Routinator prior to 0.10.2 happily processes a chain of RRDP repositories of infinite length causing it to never finish a validation run. In RPKI, a CA can choose the RRDP repository it wishes to publish its data in. By continuously generating a new child CA that only consists of another CA using a…
ModificadaAlta (7.5)0.93%—Nlnetlabs Routinator21/9/202117/6/2026
NLnet Labs Routinator prior to 0.10.0 produces invalid RTR payload if an RPKI CA uses too large values in the max-length parameter in a ROA. This will lead to RTR clients such as routers to reject the RPKI data set, effectively disabling Route Origin Validation.
ModificadaCrítica (9.8)2.1%—Nlnetlabs UnboundDebian Linux27/4/202117/6/2026
Unbound before 1.9.5 allows an out-of-bounds write via a compressed name in rdata_copy. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited
ModificadaAlta (7.5)2.2%—Nlnetlabs UnboundDebian Linux27/4/202117/6/2026
Unbound before 1.9.5 allows an assertion failure via a compressed name in dname_pkt_copy. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited
ModificadaAlta (7.5)2.1%—Nlnetlabs UnboundDebian Linux27/4/202117/6/2026
Unbound before 1.9.5 allows an infinite loop via a compressed name in dname_pkt_copy. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited
ModificadaCrítica (9.8)2.1%—Nlnetlabs UnboundDebian Linux27/4/202117/6/2026
Unbound before 1.9.5 allows an integer overflow in a size calculation in respip/respip.c. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited
ModificadaCrítica (9.8)2.1%—Nlnetlabs UnboundDebian Linux27/4/202117/6/2026
Unbound before 1.9.5 allows an integer overflow in a size calculation in dnscrypt/dnscrypt.c. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited
ModificadaAlta (7.5)2.2%—Nlnetlabs UnboundDebian Linux27/4/202117/6/2026
Unbound before 1.9.5 allows an assertion failure and denial of service in dname_pkt_copy via an invalid packet. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited
ModificadaAlta (7.5)2.1%—Nlnetlabs UnboundDebian Linux27/4/202117/6/2026
Unbound before 1.9.5 allows an assertion failure and denial of service in synth_cname. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited
ModificadaCrítica (9.8)2.1%—Nlnetlabs UnboundDebian Linux27/4/202117/6/2026
Unbound before 1.9.5 allows an out-of-bounds write in sldns_bget_token_par. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited
ModificadaCrítica (9.8)2.1%—Nlnetlabs UnboundDebian Linux27/4/202117/6/2026
Unbound before 1.9.5 allows an integer overflow in sldns_str2wire_dname_buf_origin, leading to an out-of-bounds write. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited
ModificadaCrítica (9.8)1.8%—Nlnetlabs UnboundDebian Linux27/4/202117/6/2026
Unbound before 1.9.5 allows an integer overflow in the regional allocator via the ALIGN_UP macro. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited
ModificadaCrítica (9.8)2.1%—Nlnetlabs UnboundDebian Linux27/4/202117/6/2026
Unbound before 1.9.5 allows an integer overflow in the regional allocator via regional_alloc. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited
AnalizadaMedia (5.9)1.3%—Nlnetlabs UnboundDebian Linux27/4/202125/8/2026
Unbound before 1.9.5 allows configuration injection in create_unbound_ad_servers.sh upon a successful man-in-the-middle attack against a cleartext HTTP session. NOTE: The vendor does not consider this a vulnerability of the Unbound software. create_unbound_ad_servers.sh is a contributed script from the community that…
ModificadaMedia (5.5)0.49%—Nlnetlabs Name Server DaemonNlnetlabs UnboundDebian Linux7/12/202017/6/2026
NLnet Labs Unbound, up to and including version 1.12.0, and NLnet Labs NSD, up to and including version 4.3.3, contain a local vulnerability that would allow for a local symlink attack. When writing the PID file, Unbound and NSD create the file if it is not there, or open an existing file for writing. In case the file…
ModificadaAlta (7.5)1.3%—Nlnetlabs Unbound27/11/202017/6/2026
An incomplete fix for CVE-2020-12662 was shipped for Unbound in Red Hat Enterprise Linux 7, as part of erratum RHSA-2020:2414. Vulnerable versions of Unbound could still amplify an incoming query into a large number of queries directed to a target, even with a lower amplification ratio compared to versions of Unbound…
ModificadaAlta (7.4)0.75%—Nlnetlabs Routinator5/8/202017/6/2026
An issue was discovered in NLnet Labs Routinator 0.1.0 through 0.7.1. It allows remote attackers to bypass intended access restrictions or to cause a denial of service on dependent routing systems by strategically withholding RPKI Route Origin Authorisation ".roa" files or X509 Certificate Revocation List files from…
ModificadaAlta (7.5)3.6%—Nlnetlabs UnboundDebian LinuxOpensuse LeapCanonical Ubuntu Linux+119/5/202017/6/2026
Unbound before 1.10.1 has an infinite loop via malformed DNS answers received from upstream servers.
ModificadaAlta (7.5)3.2%—Nlnetlabs UnboundDebian LinuxOpensuse LeapCanonical Ubuntu Linux+119/5/202017/6/2026
Unbound before 1.10.1 has Insufficient Control of Network Message Volume, aka an "NXNSAttack" issue. This is triggered by random subdomains in the NSDNAME in NS records.
ModificadaAlta (7.3)3.2%—Nlnetlabs UnboundFedoraproject FedoraOpensuse Leap19/11/201917/6/2026
Unbound 1.6.4 through 1.9.4 contain a vulnerability in the ipsec module that can cause shell code execution after receiving a specially crafted answer. This issue can only be triggered if unbound was compiled with `--enable-ipsecmod` support, and ipsecmod is enabled and used in the configuration.
ModificadaMedia (5.9)3.5%—ISC BindNlnetlabs NSDNIC Knot ResolverRedhat Enterprise Linux5/11/201916/6/2026
Cache Poisoning issue exists in DNS Response Rate Limiting.
ModificadaAlta (7.5)3.5%—Nlnetlabs UnboundCanonical Ubuntu Linux3/10/201917/6/2026
Unbound before 1.9.4 accesses uninitialized memory, which allows remote attackers to trigger a crash via a crafted NOTIFY query. The source IP address of the query must match an access-control rule.
Orbitaley — Vulnerabilidades