Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

115 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)2.0%—Nlnetlabs Name Server Daemon3/7/201917/6/2026
nsd-checkzone in NLnet Labs NSD 4.2.0 has a Stack-based Buffer Overflow in the dname_concatenate() function in dname.c.
ModificadaMedia (5.3)2.6%—Nlnetlabs UnboundDebian LinuxCanonical Ubuntu Linux23/1/201817/6/2026
A flaw was found in the way unbound before 1.6.8 validated wildcard-synthesized NSEC records. An improperly validated wildcard NSEC record could be used to prove the non-existence (NXDOMAIN answer) of an existing wildcard record, or trick unbound into accepting a NODATA proof.
ModificadaCrítica (9.8)2.3%—Nlnetlabs Ldns17/11/201717/6/2026
A double-free vulnerability in str2host.c in ldns 1.7.0 have unspecified impact and attack vectors.
ModificadaCrítica (9.8)2.7%—Nlnetlabs Ldns17/11/201717/6/2026
A double-free vulnerability in parse.c in ldns 1.7.0 have unspecified impact and attack vectors.
ModificadaAlta (7.5)2.9%—Nlnetlabs NSD9/2/201717/6/2026
NSD before 4.1.11 allows remote DNS master servers to cause a denial of service (/tmp disk consumption and slave server crash) via a zone transfer with unlimited data.
ModificadaMedia (4.3)25%—Nlnetlabs UnboundCanonical Ubuntu LinuxDebian Linux11/12/201417/6/2026
iterator.c in NLnet Labs Unbound before 1.5.1 does not limit delegation chaining, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a large or infinite number of referrals.
ModificadaBaja (2.1)0.38%—Nlnetlabs Ldns16/11/201417/6/2026
The ldns-keygen tool in ldns 1.6.x uses the current umask to set the privileges of the private key, which might allow local users to obtain the private key by reading the file.
ModificadaMedia (5)9.2%—Nlnetlabs NSD27/7/201216/6/2026
query.c in NSD 3.0.x through 3.0.8, 3.1.x through 3.1.1, and 3.2.x before 3.2.12 allows remote attackers to cause a denial of service (NULL pointer dereference and child process crash) via a crafted DNS packet.
ModificadaMedia (6.8)4.1%—Nlnetlabs Ldns4/11/201116/6/2026
Heap-based buffer overflow in the ldns_rr_new_frm_str_internal function in ldns before 1.6.11 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a Resource Record (RR) with an unknown type containing input that is longer than a specified length.
ModificadaMedia (5)2.7%—Nlnetlabs Unbound2/6/201116/6/2026
Unbound before 1.4.4 does not send responses for signed zones after mishandling an unspecified query, which allows remote attackers to cause a denial of service (DNSSEC outage) via a crafted query.
ModificadaMedia (4.3)7.1%—Nlnetlabs Unbound31/5/201116/6/2026
daemon/worker.c in Unbound 1.x before 1.4.10, when debugging functionality and the interface-automatic option are enabled, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted DNS request that triggers improper error handling.
ModificadaMedia (5)2.7%—Nlnetlabs Unbound16/3/201016/6/2026
Unbound before 1.4.3 does not properly align structures on 64-bit platforms, which allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors.
ModificadaAlta (7.5)3.0%—Nlnetlabs Unbound13/10/200916/6/2026
Unbound before 1.3.4 does not properly verify signatures for NSEC3 records, which allows remote attackers to cause secure delegations to be downgraded via DNS spoofing or other DNS-related attacks in conjunction with crafted delegation responses.
ModificadaMedia (5)3.2%—Nlnetlabs NSD22/5/200916/6/2026
Off-by-one error in the packet_read_query_section function in packet.c in nsd 3.2.1, and process_query_section in query.c in nsd 2.3.7, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors that trigger a buffer overflow.
ModificadaMedia (6.4)3.5%—Nlnetlabs Ldns25/3/200916/6/2026
Heap-based buffer overflow in the ldns_rr_new_frm_str_internal function in ldns 1.4.x allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via a DNS resource record (RR) with a long (1) class field (clas variable) and possibly (2) TTL field.
Orbitaley — Vulnerabilidades