Search CVE reports


Toggle filters

11 – 20 of 38 results


CVE-2022-30698

Medium priority

Some fixes available 8 of 10

NLnet Labs Unbound, up to and including version 1.16.1 is vulnerable to a novel type of the "ghost domain names" attack. The vulnerability works by targeting an Unbound instance. Unbound is queried for a subdomain of a rogue...

1 affected package

unbound

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
unbound Fixed Fixed Fixed Fixed Vulnerable
Show less packages

CVE-2019-25042

Medium priority
Fixed

** DISPUTED ** Unbound before 1.9.5 allows an out-of-bounds write via a compressed name in rdata_copy. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation...

1 affected package

unbound

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
unbound Not affected Not affected Fixed Fixed Not affected
Show less packages

CVE-2019-25041

Medium priority
Fixed

** DISPUTED ** Unbound before 1.9.5 allows an assertion failure via a compressed name in dname_pkt_copy. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation...

1 affected package

unbound

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
unbound Not affected Not affected Fixed Fixed Not affected
Show less packages

CVE-2019-25040

Medium priority
Fixed

** DISPUTED ** Unbound before 1.9.5 allows an infinite loop via a compressed name in dname_pkt_copy. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation...

1 affected package

unbound

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
unbound Not affected Not affected Fixed Fixed Not affected
Show less packages

CVE-2019-25039

Medium priority
Fixed

** DISPUTED ** Unbound before 1.9.5 allows an integer overflow in a size calculation in respip/respip.c. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation...

1 affected package

unbound

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
unbound Not affected Not affected Fixed Fixed Not affected
Show less packages

CVE-2019-25038

Medium priority
Fixed

** DISPUTED ** Unbound before 1.9.5 allows an integer overflow in a size calculation in dnscrypt/dnscrypt.c. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running...

1 affected package

unbound

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
unbound Not affected Not affected Fixed Fixed Not affected
Show less packages

CVE-2019-25037

Medium priority
Fixed

** DISPUTED ** Unbound before 1.9.5 allows an assertion failure and denial of service in dname_pkt_copy via an invalid packet. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running...

1 affected package

unbound

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
unbound Not affected Not affected Fixed Fixed Not affected
Show less packages

CVE-2019-25036

Medium priority
Fixed

** DISPUTED ** Unbound before 1.9.5 allows an assertion failure and denial of service in synth_cname. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation...

1 affected package

unbound

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
unbound Not affected Not affected Fixed Fixed Not affected
Show less packages

CVE-2019-25035

Medium priority
Fixed

** DISPUTED ** Unbound before 1.9.5 allows an out-of-bounds write in sldns_bget_token_par. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be...

1 affected package

unbound

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
unbound Not affected Not affected Fixed Fixed Not affected
Show less packages

CVE-2019-25034

Medium priority
Fixed

** DISPUTED ** Unbound before 1.9.5 allows an integer overflow in sldns_str2wire_dname_buf_origin, leading to an out-of-bounds write. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a...

1 affected package

unbound

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
unbound Not affected Not affected Fixed Fixed Not affected
Show less packages