Nlnetlabs Unbound vulnerabilities
38 known vulnerabilities affecting nlnetlabs/unbound.
Total CVEs
38
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH16MEDIUM14LOW1
Vulnerabilities
Page 2 of 2
CVE-2019-25037HIGHCVSS 7.5fixed in 1.9.52021-04-27
CVE-2019-25037 [HIGH] CWE-617 CVE-2019-25037: Unbound before 1.9.5 allows an assertion failure and denial of service in dname_pkt_copy via an inva
Unbound before 1.9.5 allows an assertion failure and denial of service in dname_pkt_copy via an invalid packet. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited
nvdosv
CVE-2019-25041HIGHCVSS 7.5fixed in 1.9.52021-04-27
CVE-2019-25041 [HIGH] CWE-617 CVE-2019-25041: Unbound before 1.9.5 allows an assertion failure via a compressed name in dname_pkt_copy. NOTE: The
Unbound before 1.9.5 allows an assertion failure via a compressed name in dname_pkt_copy. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited
nvdosv
CVE-2019-25036HIGHCVSS 7.5fixed in 1.9.52021-04-27
CVE-2019-25036 [HIGH] CWE-617 CVE-2019-25036: Unbound before 1.9.5 allows an assertion failure and denial of service in synth_cname. NOTE: The ven
Unbound before 1.9.5 allows an assertion failure and denial of service in synth_cname. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited
nvdosv
CVE-2019-25031MEDIUMCVSS 5.9fixed in 1.9.52021-04-27
CVE-2019-25031 [MEDIUM] CWE-74 CVE-2019-25031: Unbound before 1.9.5 allows configuration injection in create_unbound_ad_servers.sh upon a successfu
Unbound before 1.9.5 allows configuration injection in create_unbound_ad_servers.sh upon a successful man-in-the-middle attack against a cleartext HTTP session. NOTE: The vendor does not consider this a vulnerability of the Unbound software. create_unbound_ad_servers.sh is a contributed script from the community that facilitates automatic configurati
nvdosv
CVE-2020-28935MEDIUMCVSS 5.5fixed in 1.13.02020-12-07
CVE-2020-28935 [MEDIUM] CWE-59 CVE-2020-28935: NLnet Labs Unbound, up to and including version 1.12.0, and NLnet Labs NSD, up to and including vers
NLnet Labs Unbound, up to and including version 1.12.0, and NLnet Labs NSD, up to and including version 4.3.3, contain a local vulnerability that would allow for a local symlink attack. When writing the PID file, Unbound and NSD create the file if it is not there, or open an existing file for writing. In case the file was already present, they would
nvdosv
CVE-2020-10772HIGHCVSS 7.5v1.6.6-5vunbound-1.6.6-5.el7_82020-11-27
CVE-2020-10772 [HIGH] CWE-406 CVE-2020-10772: An incomplete fix for CVE-2020-12662 was shipped for Unbound in Red Hat Enterprise Linux 7, as part
An incomplete fix for CVE-2020-12662 was shipped for Unbound in Red Hat Enterprise Linux 7, as part of erratum RHSA-2020:2414. Vulnerable versions of Unbound could still amplify an incoming query into a large number of queries directed to a target, even with a lower amplification ratio compared to versions of Unbound that shipped before the mentioned e
cvelistv5nvd
CVE-2020-12663HIGHCVSS 7.5fixed in 1.10.12020-05-19
CVE-2020-12663 [HIGH] CWE-835 CVE-2020-12663: Unbound before 1.10.1 has an infinite loop via malformed DNS answers received from upstream servers.
Unbound before 1.10.1 has an infinite loop via malformed DNS answers received from upstream servers.
nvdosv
CVE-2020-12662HIGHCVSS 7.5fixed in 1.10.12020-05-19
CVE-2020-12662 [HIGH] CWE-400 CVE-2020-12662: Unbound before 1.10.1 has Insufficient Control of Network Message Volume, aka an "NXNSAttack" issue.
Unbound before 1.10.1 has Insufficient Control of Network Message Volume, aka an "NXNSAttack" issue. This is triggered by random subdomains in the NSDNAME in NS records.
nvdosv
CVE-2019-18934HIGHCVSS 7.3≥ 1.6.4, ≤ 1.9.42019-11-19
CVE-2019-18934 [HIGH] CWE-78 CVE-2019-18934: Unbound 1.6.4 through 1.9.4 contain a vulnerability in the ipsec module that can cause shell code ex
Unbound 1.6.4 through 1.9.4 contain a vulnerability in the ipsec module that can cause shell code execution after receiving a specially crafted answer. This issue can only be triggered if unbound was compiled with `--enable-ipsecmod` support, and ipsecmod is enabled and used in the configuration.
nvdosv
CVE-2019-16866HIGHCVSS 7.5fixed in 1.9.42019-10-03
CVE-2019-16866 [HIGH] CWE-755 CVE-2019-16866: Unbound before 1.9.4 accesses uninitialized memory, which allows remote attackers to trigger a crash
Unbound before 1.9.4 accesses uninitialized memory, which allows remote attackers to trigger a crash via a crafted NOTIFY query. The source IP address of the query must match an access-control rule.
nvdosv
CVE-2017-15105MEDIUMCVSS 5.3fixed in 1.6.82018-01-23
CVE-2017-15105 [MEDIUM] CWE-358 CVE-2017-15105: A flaw was found in the way unbound before 1.6.8 validated wildcard-synthesized NSEC records. An imp
A flaw was found in the way unbound before 1.6.8 validated wildcard-synthesized NSEC records. An improperly validated wildcard NSEC record could be used to prove the non-existence (NXDOMAIN answer) of an existing wildcard record, or trick unbound into accepting a NODATA proof.
nvdosv
CVE-2014-8602MEDIUMCVSS 4.3≤ 1.5.02014-12-11
CVE-2014-8602 [MEDIUM] CWE-399 CVE-2014-8602: iterator.c in NLnet Labs Unbound before 1.5.1 does not limit delegation chaining, which allows remot
iterator.c in NLnet Labs Unbound before 1.5.1 does not limit delegation chaining, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a large or infinite number of referrals.
nvdosv
CVE-2011-4528MEDIUMCVSS 5.0≥ 0, < 1.4.14-12011-12-20
CVE-2011-4528 [MEDIUM] CVE-2011-4528: Unbound before 1
Unbound before 1.4.13p2 attempts to free unallocated memory during processing of duplicate CNAME records in a signed zone, which allows remote DNS servers to cause a denial of service (daemon crash) via a crafted response.
osv
CVE-2011-4869MEDIUMCVSS 5.0≥ 0, < 1.4.14-12011-12-20
CVE-2011-4869 [MEDIUM] CVE-2011-4869: validator/val_nsec3
validator/val_nsec3.c in Unbound before 1.4.13p2 does not properly perform proof processing for NSEC3-signed zones, which allows remote DNS servers to cause a denial of service (daemon crash) via a malformed response that lacks expected NSEC3 records, a different vulnerability than CVE-2011-4528.
osv
CVE-2009-4008MEDIUMCVSS 5.0≤ 1.4.3v0.0+28 more2011-06-02
CVE-2009-4008 [MEDIUM] CWE-399 CVE-2009-4008: Unbound before 1.4.4 does not send responses for signed zones after mishandling an unspecified query
Unbound before 1.4.4 does not send responses for signed zones after mishandling an unspecified query, which allows remote attackers to cause a denial of service (DNSSEC outage) via a crafted query.
nvdosv
CVE-2011-1922MEDIUMCVSS 4.3v1.0.0v1.0.1+20 more2011-05-31
CVE-2011-1922 [MEDIUM] CWE-399 CVE-2011-1922: daemon/worker.c in Unbound 1.x before 1.4.10, when debugging functionality and the interface-automat
daemon/worker.c in Unbound 1.x before 1.4.10, when debugging functionality and the interface-automatic option are enabled, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted DNS request that triggers improper error handling.
nvdosv
CVE-2010-0969MEDIUMCVSS 5.0≤ 1.4.2v0.0+27 more2010-03-16
CVE-2010-0969 [MEDIUM] CWE-399 CVE-2010-0969: Unbound before 1.4.3 does not properly align structures on 64-bit platforms, which allows remote att
Unbound before 1.4.3 does not properly align structures on 64-bit platforms, which allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors.
nvdosv
CVE-2009-3602HIGHCVSS 7.5≤ 1.3.3v0.0+23 more2009-10-13
CVE-2009-3602 [HIGH] CWE-310 CVE-2009-3602: Unbound before 1.3.4 does not properly verify signatures for NSEC3 records, which allows remote atta
Unbound before 1.3.4 does not properly verify signatures for NSEC3 records, which allows remote attackers to cause secure delegations to be downgraded via DNS spoofing or other DNS-related attacks in conjunction with crafted delegation responses.
nvdosv
← Previous2 / 2