« Volver al listado

Nlnetlabs

Nlnetlabs NSD: vulnerabilidades y CVE

Nlnetlabs NSD tiene 12 vulnerabilidades publicadas, 8 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE12
Últimos 12 meses8
Críticas0
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-19538Alta (8.2)0.23%—26 ago 2026
The BLOCKED access control list items that are evaluated to deny access on the the proxy protocol port can be bypassed completely when connecting over TCP or TLS and sending the query twice on connection that is kept…
CVE-2026-19401Alta (8.2)0.28%—26 ago 2026
Any remote client can crash a (debugging/non-release build type) NSD serve child by sending it a special crafted message with a specially tuned number of DNS Cookie options (17 when UDP payload size is 512). By…
CVE-2026-18916Media (6.9)0.28%—26 ago 2026
Any remote client can crash a NSD serve child, by throttling the TCP receive window after a TCP query. By continuously crashing the serve childs, the remote client can denial all TCP service to this NSD instance.
CVE-2026-18664Alta (8.2)0.26%—26 ago 2026
When ranges are used for access control (i.e. of the form 1.2.3.4-1.2.3.25), because NSD wrongly compares the IP address with the range on little endian systems, IPs that were meant to be allowed may be denied, and, IPs…
CVE-2026-12490Alta (8.2)0.22%—25 jun 2026
When a provide-xfr is given with a tls-auth-name, a secondary requesting a transfer should provide a client certificate with that name. However, no client certificate is needed when the request comes in over TLS over…
CVE-2026-12246Alta (7.2)0.44%—25 jun 2026
NSD version 4.14.0 introduced a bug where a specially crafted APL RR, with an adflength larger than permitted for the address family will overwrite the stack when the zone is written to disk, with a maximum of 111…
CVE-2026-12245Alta (8.7)0.46%—25 jun 2026
NSD from version 4.13.0 has a heap use-after-free bug in logging errors on TLS connections, causing a crash of the server process, which can be triggered trivially by sending a DNS query over a DoT connection, and…
CVE-2026-12244Alta (8.7)0.49%—25 jun 2026
If NSD is configured as secondary for a zone, the primary of that zone can crash NSD with an AXFR containing a DNS message with a special crafted SVCB RR with an rdata size of 65512, that let's an (uint16_t) variable…
CVE-2013-5661Media (5.9)3.5%—5 nov 2019
Cache Poisoning issue exists in DNS Response Rate Limiting.
CVE-2016-6173Alta (7.5)2.9%—9 feb 2017
NSD before 4.1.11 allows remote DNS master servers to cause a denial of service (/tmp disk consumption and slave server crash) via a zone transfer with unlimited data.
CVE-2012-2978Media (5)9.2%—27 jul 2012
query.c in NSD 3.0.x through 3.0.8, 3.1.x through 3.1.1, and 3.2.x before 3.2.12 allows remote attackers to cause a denial of service (NULL pointer dereference and child process crash) via a crafted DNS packet.
CVE-2009-1755Media (5)3.2%—22 may 2009
Off-by-one error in the packet_read_query_section function in packet.c in nsd 3.2.1, and process_query_section in query.c in nsd 2.3.7, allows remote attackers to cause a denial of service (crash) and possibly execute…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application5
  2. T1059 Command and Scripting Interpreter2
  3. T1078 Valid Accounts2
  4. T1210 Exploitation of Remote Services2
  5. T1499 Endpoint Denial of Service1
  6. T1499.004 Application or System Exploitation1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Nlnetlabs