|
224451
|
5.3 |
MEDIUM
Network
|
trustwave
|
modsecurity
|
ModSecurity 3.x before 3.0.4 mishandles key-value pair parsing, as demonstrated by a "string index out of range" error and worker-process crash for a "Cookie: =abc" header.
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2019-25043
|
2024-11-21 13:39 |
2021-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224452
|
9.8 |
CRITICAL
Network
|
nlnetlabs debian
|
unbound debian_linux
|
Unbound before 1.9.5 allows an out-of-bounds write via a compressed name in rdata_copy. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound …
|
CWE-787
Out-of-bounds Write
|
CVE-2019-25042
|
2024-11-21 13:39 |
2021-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224453
|
7.5 |
HIGH
Network
|
nlnetlabs debian
|
unbound debian_linux
|
Unbound before 1.9.5 allows an assertion failure via a compressed name in dname_pkt_copy. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unboun…
|
CWE-617
Reachable Assertion
|
CVE-2019-25041
|
2024-11-21 13:39 |
2021-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224454
|
7.5 |
HIGH
Network
|
nlnetlabs debian
|
unbound debian_linux
|
Unbound before 1.9.5 allows an infinite loop via a compressed name in dname_pkt_copy. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound in…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2019-25040
|
2024-11-21 13:39 |
2021-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224455
|
9.8 |
CRITICAL
Network
|
nlnetlabs debian
|
unbound debian_linux
|
Unbound before 1.9.5 allows an integer overflow in a size calculation in respip/respip.c. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unboun…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-25039
|
2024-11-21 13:39 |
2021-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224456
|
9.8 |
CRITICAL
Network
|
nlnetlabs debian
|
unbound debian_linux
|
Unbound before 1.9.5 allows an integer overflow in a size calculation in dnscrypt/dnscrypt.c. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Un…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-25038
|
2024-11-21 13:39 |
2021-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224457
|
7.5 |
HIGH
Network
|
nlnetlabs debian
|
unbound debian_linux
|
Unbound before 1.9.5 allows an assertion failure and denial of service in dname_pkt_copy via an invalid packet. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulner…
|
CWE-617
Reachable Assertion
|
CVE-2019-25037
|
2024-11-21 13:39 |
2021-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224458
|
7.5 |
HIGH
Network
|
nlnetlabs debian
|
unbound debian_linux
|
Unbound before 1.9.5 allows an assertion failure and denial of service in synth_cname. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound i…
|
CWE-617
Reachable Assertion
|
CVE-2019-25036
|
2024-11-21 13:39 |
2021-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224459
|
9.8 |
CRITICAL
Network
|
nlnetlabs debian
|
unbound debian_linux
|
Unbound before 1.9.5 allows an out-of-bounds write in sldns_bget_token_par. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-25035
|
2024-11-21 13:39 |
2021-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224460
|
9.8 |
CRITICAL
Network
|
nlnetlabs debian
|
unbound debian_linux
|
Unbound before 1.9.5 allows an integer overflow in sldns_str2wire_dname_buf_origin, leading to an out-of-bounds write. NOTE: The vendor disputes that this is a vulnerability. Although the code may be…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-25034
|
2024-11-21 13:39 |
2021-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|