Vulnerabilidades en NLnet Labs

64 resultados
Análisis Vexday

NLnet Labs apresenta volume elevado de vulnerabilidades recentes (20 das 40 CVEs nos últimos 90 dias), com 2 críticas catalogadas, mas nenhuma sob exploração ativa conhecida. A fraqueza dominante (CWE-349) concentra os riscos em uma classe específica, sugerindo problemas sistemáticos que demandam remediação priorizada nos componentes afetados.

CVE-2026-55990MEDIUMPacket of death for a DNSCrypt misconfigured UnboundEPSS 0.3%CVE-2026-44608MEDIUMUse after free and crash under special conditions in RPZ codeEPSS 0.3%CVE-2026-50251MEDIUMAttacker supplied '0.0.0.0'/'::' glue triggers defensive full-cache flushEPSS 0.3%CVE-2026-42960MEDIUMPossible cache poisoning via promiscuous records for the authority sectionEPSS 0.2%CVE-2026-44621MEDIUMLibunbound applications configured with 'unwanted-reply-threshold' could eventually be abruptly terminatedEPSS 0.2%CVE-2026-56444MEDIUMDegradation of resolution service when 'discard-timeout' and 'serve-expired-client-timeout' are combined in unusual configurationEPSS 0.2%CVE-2026-55991MEDIUMRemote DNS-over-QUIC (DoQ) flow-control assertion failure in libngtcp2EPSS 0.2%CVE-2026-52863MEDIUMMemory corruption could lead to crash and denial of serviceEPSS 0.2%CVE-2026-50046MEDIUMPossible heap use-after-free in an error path when a DoT forwarded query is jostled outEPSS 0.2%CVE-2026-55717MEDIUM'serve-expired-client-timeout' and 'response-ip' CNAME redirect could lead to a crashEPSS 0.2%CVE-2026-44687LOWOff-by-one error in 'harden-below-nxdomain' logic can shadow a stub/forward zone by a legitimate parent's NXDOMAINEPSS 0.2%CVE-2026-42955LOWExtra fix for CVE-2026-40622 to also clamp the TTL of A/AAAA records disallowing a one-time 'ghost domain' delegation renewal via glue recordsEPSS 0.2%CVE-2025-5994HIGHCache poisoning via the ECS-enabled Rebirthday AttackEPSS 0.2%CVE-2026-46582LOWA wildcard replay, as another piece of data, triggers poisoning in the serve expired reply pathEPSS 0.2%CVE-2026-54478LOWDNS Cookie bypass when combined with proxy-protocol useEPSS 0.2%CVE-2026-12490HIGHBypass of client certificate verification with transfer over TLSEPSS 0.2%CVE-2026-55708LOWPrivacy/configuration issue when adding local data in views through 'unbound-control'EPSS 0.1%CVE-2026-10846HIGHInsufficient verification that responses belong to a queryEPSS 0.1%CVE-2026-44690HIGHCross-zone wildcard cache poisoning via RRSIG.labels manipulationEPSS 0.1%CVE-2026-50252MEDIUMPossible cache poisoning attack by mapping source port population per threadEPSS 0.1%