Vulnerabilities (CVE)

Filtered by vendor Unbound Subscribe
Filtered by product Unbound
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2012-1192 1 Unbound 1 Unbound 2024-11-21 6.4 MEDIUM N/A
The resolver in Unbound before 1.4.11 overwrites cached server names and TTL values in NS records during the processing of a response to an A record query, which allows remote attackers to trigger continued resolvability of revoked domain names via a "ghost domain names" attack.
CVE-2011-4869 1 Unbound 1 Unbound 2024-11-21 7.8 HIGH N/A
validator/val_nsec3.c in Unbound before 1.4.13p2 does not properly perform proof processing for NSEC3-signed zones, which allows remote DNS servers to cause a denial of service (daemon crash) via a malformed response that lacks expected NSEC3 records, a different vulnerability than CVE-2011-4528.
CVE-2011-4528 1 Unbound 1 Unbound 2024-11-21 5.0 MEDIUM N/A
Unbound before 1.4.13p2 attempts to free unallocated memory during processing of duplicate CNAME records in a signed zone, which allows remote DNS servers to cause a denial of service (daemon crash) via a crafted response.