Vulnerabilidades en NLnet Labs

64 resultados
Análisis Vexday

NLnet Labs apresenta volume elevado de vulnerabilidades recentes (20 das 40 CVEs nos últimos 90 dias), com 2 críticas catalogadas, mas nenhuma sob exploração ativa conhecida. A fraqueza dominante (CWE-349) concentra os riscos em uma classe específica, sugerindo problemas sistemáticos que demandam remediação priorizada nos componentes afetados.

CVE-2023-39916CRITICALPossible path traversal when storing RRDP responsesEPSS 0.5%CVE-2023-39915HIGHCrashes on parsing certain invalid RPKI objectsEPSS 0.5%CVE-2020-28935Local symlink attack in Unbound and NSDEPSS 0.5%CVE-2025-0638HIGHRoutinator crashes when illegal characters are present in manifest file namesEPSS 0.5%CVE-2026-49233HIGHRoutinator cache path traversal using rogue rsync URIsEPSS 0.4%CVE-2026-49235HIGHRoutinator crashes on specifically crafted RRDP XML filesEPSS 0.4%CVE-2026-49232HIGHRoutinator exits when accepting an incoming HTTP or RTR connection failsEPSS 0.3%CVE-2026-42923MEDIUMDegradation of service with unbounded NSEC3 hash calculationsEPSS 0.3%CVE-2026-32792MEDIUMPacket of death with DNSCryptEPSS 0.3%CVE-2026-12244HIGHHeap overflow and crash with crafted SVCB RREPSS 0.3%CVE-2026-12245HIGHDenial of DNS over TLS service by any DoT clientEPSS 0.3%CVE-2025-11411MEDIUMPossible domain hijacking via promiscuous records in the authority sectionEPSS 0.3%CVE-2026-12246HIGHOut of bounds stack write with crafted APL RREPSS 0.3%CVE-2026-40691HIGHPacket of death for DNSCrypt over TCPEPSS 0.3%CVE-2026-55973HIGH'dns-error-reporting: yes' leads to stack buffer overflowEPSS 0.3%CVE-2026-32665HIGHRemote DNS-over-QUIC denial of service due to `quic-size` budget bypassEPSS 0.3%CVE-2026-50045MEDIUM'max-global-quota' reset by DNSSEC validation restartsEPSS 0.3%CVE-2026-14586MEDIUMAssertion in libngtcp2 when under pressure in high concurrency DNS-over-QUIC environmentsEPSS 0.3%CVE-2026-49234HIGHRoutinator crashes on specifically crafted ASN strings in the APIEPSS 0.3%CVE-2026-41637LOWDegradation of resolution service from improperly accounted client-terminated DNS-over-QUIC queriesEPSS 0.3%