Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 22

Количество 22

rocky логотип

RLSA-2026:18931

2 месяца назад

Moderate: unbound security update

EPSS: Низкий
rocky логотип

RLSA-2026:18556

2 месяца назад

Moderate: unbound security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-18931

около 2 месяцев назад

ELSA-2026-18931: unbound security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-18556

25 дней назад

ELSA-2026-18556: unbound security update (MODERATE)

EPSS: Низкий
ubuntu логотип

CVE-2024-33655

около 2 лет назад

The DNS protocol in RFC 1035 and updates allows remote attackers to cause a denial of service (resource consumption) by arranging for DNS queries to be accumulated for seconds, such that responses are later sent in a pulsing burst (which can be considered traffic amplification in some cases), aka the "DNSBomb" issue.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2024-33655

около 2 лет назад

The DNS protocol in RFC 1035 and updates allows remote attackers to cause a denial of service (resource consumption) by arranging for DNS queries to be accumulated for seconds, such that responses are later sent in a pulsing burst (which can be considered traffic amplification in some cases), aka the "DNSBomb" issue.

CVSS3: 3.7
EPSS: Низкий
nvd логотип

CVE-2024-33655

около 2 лет назад

The DNS protocol in RFC 1035 and updates allows remote attackers to cause a denial of service (resource consumption) by arranging for DNS queries to be accumulated for seconds, such that responses are later sent in a pulsing burst (which can be considered traffic amplification in some cases), aka the "DNSBomb" issue.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2024-33655

почти 2 года назад

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2024-33655

около 2 лет назад

The DNS protocol in RFC 1035 and updates allows remote attackers to ca ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2025-11411

9 месяцев назад

NLnet Labs Unbound up to and including version 1.24.1 is vulnerable to possible domain hijack attacks. Promiscuous NS RRSets that complement positive DNS replies in the authority section can be used to trick resolvers to update their delegation information for the zone. Usually these RRSets are used to update the resolver's knowledge of the zone's name servers. A malicious actor can exploit the possible poisonous effect by injecting NS RRSets (and possibly their respective address records) in a reply. This could be done for example by trying to spoof a packet or fragmentation attacks. Unbound would then proceed to update the NS RRSet data it already has since the new data has enough trust for it, i.e., in-zone data for the delegation point. Unbound 1.24.1 includes a fix that scrubs unsolicited NS RRSets (and their respective address records) from replies mitigating the possible poison effect. Unbound 1.24.2 includes an additional fix that scrubs unsolicited NS RRSets (and their resp...

EPSS: Низкий
redhat логотип

CVE-2025-11411

9 месяцев назад

NLnet Labs Unbound up to and including version 1.24.1 is vulnerable to possible domain hijack attacks. Promiscuous NS RRSets that complement positive DNS replies in the authority section can be used to trick resolvers to update their delegation information for the zone. Usually these RRSets are used to update the resolver's knowledge of the zone's name servers. A malicious actor can exploit the possible poisonous effect by injecting NS RRSets (and possibly their respective address records) in a reply. This could be done for example by trying to spoof a packet or fragmentation attacks. Unbound would then proceed to update the NS RRSet data it already has since the new data has enough trust for it, i.e., in-zone data for the delegation point. Unbound 1.24.1 includes a fix that scrubs unsolicited NS RRSets (and their respective address records) from replies mitigating the possible poison effect. Unbound 1.24.2 includes an additional fix that scrubs unsolicited NS RRSets (and their resp...

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2025-11411

9 месяцев назад

NLnet Labs Unbound up to and including version 1.24.1 is vulnerable to possible domain hijack attacks. Promiscuous NS RRSets that complement positive DNS replies in the authority section can be used to trick resolvers to update their delegation information for the zone. Usually these RRSets are used to update the resolver's knowledge of the zone's name servers. A malicious actor can exploit the possible poisonous effect by injecting NS RRSets (and possibly their respective address records) in a reply. This could be done for example by trying to spoof a packet or fragmentation attacks. Unbound would then proceed to update the NS RRSet data it already has since the new data has enough trust for it, i.e., in-zone data for the delegation point. Unbound 1.24.1 includes a fix that scrubs unsolicited NS RRSets (and their respective address records) from replies mitigating the possible poison effect. Unbound 1.24.2 includes an additional fix that scrubs unsolicited NS RRSets (and their respect

EPSS: Низкий
msrc логотип

CVE-2025-11411

9 месяцев назад

Possible domain hijacking via promiscuous records in the authority section

EPSS: Низкий
debian логотип

CVE-2025-11411

9 месяцев назад

NLnet Labs Unbound up to and including version 1.24.1 is vulnerable to ...

EPSS: Низкий
github логотип

GHSA-2xh4-pf7v-vh6h

около 2 лет назад

The DNS protocol in RFC 1035 and updates allows remote attackers to cause a denial of service (resource consumption) by arranging for DNS queries to be accumulated for seconds, such that responses are later sent in a pulsing burst (which can be considered traffic amplification in some cases), aka the "DNSBomb" issue.

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2024-04004

около 2 лет назад

Уязвимость DNS-сервера Unbound, связанная с возможностью формирования импульсного потока большого количества запросов к серверу с использованием ответов от DNS-резолверов, позволяющая нарушителю реализовать DDoS-атаку с использованием DNS-трафика

CVSS3: 5.9
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20139-1

6 месяцев назад

Security update for unbound

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:4134-1

9 месяцев назад

Security update for unbound

EPSS: Низкий
github логотип

GHSA-6w73-x38p-26g5

9 месяцев назад

NLnet Labs Unbound up to and including version 1.24.0 is vulnerable to possible domain hijack attacks. Promiscuous NS RRSets that complement positive DNS replies in the authority section can be used to trick resolvers to update their delegation information for the zone. Usually these RRSets are used to update the resolver's knowledge of the zone's name servers. A malicious actor can exploit the possible poisonous effect by injecting NS RRSets (and possibly their respective address records) in a reply. This could be done for example by trying to spoof a packet or fragmentation attacks. Unbound would then proceed to update the NS RRSet data it already has since the new data has enough trust for it, i.e., in-zone data for the delegation point. Unbound 1.24.1 includes a fix that scrubs unsolicited NS RRSets (and their respective address records) from replies mitigating the possible poison effect.

EPSS: Низкий
fstec логотип

BDU:2026-03595

9 месяцев назад

Уязвимость DNS-сервера unbound, связанная с загрузкой внешних ненадёжных данных вместе с надёжными данными, позволяющая нарушителю выполнить произвольный код

CVSS3: 7.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
rocky логотип
RLSA-2026:18931

Moderate: unbound security update

2 месяца назад
rocky логотип
RLSA-2026:18556

Moderate: unbound security update

2 месяца назад
oracle-oval логотип
ELSA-2026-18931

ELSA-2026-18931: unbound security update (MODERATE)

около 2 месяцев назад
oracle-oval логотип
ELSA-2026-18556

ELSA-2026-18556: unbound security update (MODERATE)

25 дней назад
ubuntu логотип
CVE-2024-33655

The DNS protocol in RFC 1035 and updates allows remote attackers to cause a denial of service (resource consumption) by arranging for DNS queries to be accumulated for seconds, such that responses are later sent in a pulsing burst (which can be considered traffic amplification in some cases), aka the "DNSBomb" issue.

CVSS3: 7.5
2%
Низкий
около 2 лет назад
redhat логотип
CVE-2024-33655

The DNS protocol in RFC 1035 and updates allows remote attackers to cause a denial of service (resource consumption) by arranging for DNS queries to be accumulated for seconds, such that responses are later sent in a pulsing burst (which can be considered traffic amplification in some cases), aka the "DNSBomb" issue.

CVSS3: 3.7
2%
Низкий
около 2 лет назад
nvd логотип
CVE-2024-33655

The DNS protocol in RFC 1035 and updates allows remote attackers to cause a denial of service (resource consumption) by arranging for DNS queries to be accumulated for seconds, such that responses are later sent in a pulsing burst (which can be considered traffic amplification in some cases), aka the "DNSBomb" issue.

CVSS3: 7.5
2%
Низкий
около 2 лет назад
msrc логотип
CVSS3: 7.5
2%
Низкий
почти 2 года назад
debian логотип
CVE-2024-33655

The DNS protocol in RFC 1035 and updates allows remote attackers to ca ...

CVSS3: 7.5
2%
Низкий
около 2 лет назад
ubuntu логотип
CVE-2025-11411

NLnet Labs Unbound up to and including version 1.24.1 is vulnerable to possible domain hijack attacks. Promiscuous NS RRSets that complement positive DNS replies in the authority section can be used to trick resolvers to update their delegation information for the zone. Usually these RRSets are used to update the resolver's knowledge of the zone's name servers. A malicious actor can exploit the possible poisonous effect by injecting NS RRSets (and possibly their respective address records) in a reply. This could be done for example by trying to spoof a packet or fragmentation attacks. Unbound would then proceed to update the NS RRSet data it already has since the new data has enough trust for it, i.e., in-zone data for the delegation point. Unbound 1.24.1 includes a fix that scrubs unsolicited NS RRSets (and their respective address records) from replies mitigating the possible poison effect. Unbound 1.24.2 includes an additional fix that scrubs unsolicited NS RRSets (and their resp...

0%
Низкий
9 месяцев назад
redhat логотип
CVE-2025-11411

NLnet Labs Unbound up to and including version 1.24.1 is vulnerable to possible domain hijack attacks. Promiscuous NS RRSets that complement positive DNS replies in the authority section can be used to trick resolvers to update their delegation information for the zone. Usually these RRSets are used to update the resolver's knowledge of the zone's name servers. A malicious actor can exploit the possible poisonous effect by injecting NS RRSets (and possibly their respective address records) in a reply. This could be done for example by trying to spoof a packet or fragmentation attacks. Unbound would then proceed to update the NS RRSet data it already has since the new data has enough trust for it, i.e., in-zone data for the delegation point. Unbound 1.24.1 includes a fix that scrubs unsolicited NS RRSets (and their respective address records) from replies mitigating the possible poison effect. Unbound 1.24.2 includes an additional fix that scrubs unsolicited NS RRSets (and their resp...

CVSS3: 6.1
0%
Низкий
9 месяцев назад
nvd логотип
CVE-2025-11411

NLnet Labs Unbound up to and including version 1.24.1 is vulnerable to possible domain hijack attacks. Promiscuous NS RRSets that complement positive DNS replies in the authority section can be used to trick resolvers to update their delegation information for the zone. Usually these RRSets are used to update the resolver's knowledge of the zone's name servers. A malicious actor can exploit the possible poisonous effect by injecting NS RRSets (and possibly their respective address records) in a reply. This could be done for example by trying to spoof a packet or fragmentation attacks. Unbound would then proceed to update the NS RRSet data it already has since the new data has enough trust for it, i.e., in-zone data for the delegation point. Unbound 1.24.1 includes a fix that scrubs unsolicited NS RRSets (and their respective address records) from replies mitigating the possible poison effect. Unbound 1.24.2 includes an additional fix that scrubs unsolicited NS RRSets (and their respect

0%
Низкий
9 месяцев назад
msrc логотип
CVE-2025-11411

Possible domain hijacking via promiscuous records in the authority section

0%
Низкий
9 месяцев назад
debian логотип
CVE-2025-11411

NLnet Labs Unbound up to and including version 1.24.1 is vulnerable to ...

0%
Низкий
9 месяцев назад
github логотип
GHSA-2xh4-pf7v-vh6h

The DNS protocol in RFC 1035 and updates allows remote attackers to cause a denial of service (resource consumption) by arranging for DNS queries to be accumulated for seconds, such that responses are later sent in a pulsing burst (which can be considered traffic amplification in some cases), aka the "DNSBomb" issue.

CVSS3: 7.5
2%
Низкий
около 2 лет назад
fstec логотип
BDU:2024-04004

Уязвимость DNS-сервера Unbound, связанная с возможностью формирования импульсного потока большого количества запросов к серверу с использованием ответов от DNS-резолверов, позволяющая нарушителю реализовать DDoS-атаку с использованием DNS-трафика

CVSS3: 5.9
2%
Низкий
около 2 лет назад
suse-cvrf логотип
openSUSE-SU-2026:20139-1

Security update for unbound

0%
Низкий
6 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:4134-1

Security update for unbound

0%
Низкий
9 месяцев назад
github логотип
GHSA-6w73-x38p-26g5

NLnet Labs Unbound up to and including version 1.24.0 is vulnerable to possible domain hijack attacks. Promiscuous NS RRSets that complement positive DNS replies in the authority section can be used to trick resolvers to update their delegation information for the zone. Usually these RRSets are used to update the resolver's knowledge of the zone's name servers. A malicious actor can exploit the possible poisonous effect by injecting NS RRSets (and possibly their respective address records) in a reply. This could be done for example by trying to spoof a packet or fragmentation attacks. Unbound would then proceed to update the NS RRSet data it already has since the new data has enough trust for it, i.e., in-zone data for the delegation point. Unbound 1.24.1 includes a fix that scrubs unsolicited NS RRSets (and their respective address records) from replies mitigating the possible poison effect.

0%
Низкий
9 месяцев назад
fstec логотип
BDU:2026-03595

Уязвимость DNS-сервера unbound, связанная с загрузкой внешних ненадёжных данных вместе с надёжными данными, позволяющая нарушителю выполнить произвольный код

CVSS3: 7.4
0%
Низкий
9 месяцев назад

Уязвимостей на страницу