Vulnerabilidades en NLnet Labs

77 resultados
Análisis Vexday

NLnet Labs apresenta volume elevado de vulnerabilidades recentes (20 das 40 CVEs nos últimos 90 dias), com 2 críticas catalogadas, mas nenhuma sob exploração ativa conhecida. A fraqueza dominante (CWE-349) concentra os riscos em uma classe específica, sugerindo problemas sistemáticos que demandam remediação priorizada nos componentes afetados.

CVE-2026-42923MEDIUMDegradation of service with unbounded NSEC3 hash calculationsEPSS 0.4%CVE-2026-32792MEDIUMPacket of death with DNSCryptEPSS 0.4%CVE-2026-41637LOWDegradation of resolution service from improperly accounted client-terminated DNS-over-QUIC queriesEPSS 0.4%CVE-2026-50046MEDIUMPossible heap use-after-free in an error path when a DoT forwarded query is jostled outEPSS 0.4%CVE-2026-55717MEDIUM'serve-expired-client-timeout' and 'response-ip' CNAME redirect could lead to a crashEPSS 0.4%CVE-2026-82720MEDIUMUse-after-free in DoH stream cleanup code pathEPSS 0.4%CVE-2026-55991MEDIUMRemote DNS-over-QUIC (DoQ) flow-control assertion failure in libngtcp2EPSS 0.4%CVE-2026-52863MEDIUMMemory corruption could lead to crash and denial of serviceEPSS 0.4%CVE-2026-56444MEDIUMDegradation of resolution service when 'discard-timeout' and 'serve-expired-client-timeout' are combined in unusual configurationEPSS 0.4%CVE-2026-55990MEDIUMPacket of death for a DNSCrypt misconfigured UnboundEPSS 0.4%CVE-2026-44621MEDIUMLibunbound applications configured with 'unwanted-reply-threshold' could eventually be abruptly terminatedEPSS 0.4%CVE-2026-78227MEDIUMUse-after-free in DoQ stream output buffer on reset re-transmissionEPSS 0.3%CVE-2026-49234HIGHRoutinator crashes on specifically crafted ASN strings in the APIEPSS 0.3%CVE-2025-11411MEDIUMPossible domain hijacking via promiscuous records in the authority sectionEPSS 0.3%CVE-2026-44687LOWOff-by-one error in 'harden-below-nxdomain' logic can shadow a stub/forward zone by a legitimate parent's NXDOMAINEPSS 0.3%CVE-2026-77860LOW'serve-expired' can bypass Unbound 'wait-limit'EPSS 0.3%CVE-2026-44608MEDIUMUse after free and crash under special conditions in RPZ codeEPSS 0.3%CVE-2026-19401HIGHRemote UDP DoS by sending multiple DNS Cookie optionsEPSS 0.3%CVE-2026-18916MEDIUMRemote TCP DoS by throttling the TCP receive windowEPSS 0.3%CVE-2026-42955LOWExtra fix for CVE-2026-40622 to also clamp the TTL of A/AAAA records disallowing a one-time 'ghost domain' delegation renewal via glue recordsEPSS 0.3%