|
222231
|
7.5 |
HIGH
Network
|
nlnetlabs debian
|
unbound debian_linux
|
Unbound before 1.9.5 allows an infinite loop via a compressed name in dname_pkt_copy. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound in…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2019-25040
|
2024-11-21 13:39 |
2021-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222232
|
9.8 |
CRITICAL
Network
|
nlnetlabs debian
|
unbound debian_linux
|
Unbound before 1.9.5 allows an integer overflow in a size calculation in respip/respip.c. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unboun…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-25039
|
2024-11-21 13:39 |
2021-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222233
|
9.8 |
CRITICAL
Network
|
nlnetlabs debian
|
unbound debian_linux
|
Unbound before 1.9.5 allows an integer overflow in a size calculation in dnscrypt/dnscrypt.c. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Un…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-25038
|
2024-11-21 13:39 |
2021-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222234
|
7.5 |
HIGH
Network
|
nlnetlabs debian
|
unbound debian_linux
|
Unbound before 1.9.5 allows an assertion failure and denial of service in dname_pkt_copy via an invalid packet. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulner…
|
CWE-617
Reachable Assertion
|
CVE-2019-25037
|
2024-11-21 13:39 |
2021-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222235
|
7.5 |
HIGH
Network
|
nlnetlabs debian
|
unbound debian_linux
|
Unbound before 1.9.5 allows an assertion failure and denial of service in synth_cname. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound i…
|
CWE-617
Reachable Assertion
|
CVE-2019-25036
|
2024-11-21 13:39 |
2021-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222236
|
9.8 |
CRITICAL
Network
|
nlnetlabs debian
|
unbound debian_linux
|
Unbound before 1.9.5 allows an out-of-bounds write in sldns_bget_token_par. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-25035
|
2024-11-21 13:39 |
2021-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222237
|
9.8 |
CRITICAL
Network
|
nlnetlabs debian
|
unbound debian_linux
|
Unbound before 1.9.5 allows an integer overflow in sldns_str2wire_dname_buf_origin, leading to an out-of-bounds write. NOTE: The vendor disputes that this is a vulnerability. Although the code may be…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-25034
|
2024-11-21 13:39 |
2021-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222238
|
9.8 |
CRITICAL
Network
|
nlnetlabs debian
|
unbound debian_linux
|
Unbound before 1.9.5 allows an integer overflow in the regional allocator via the ALIGN_UP macro. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a runnin…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-25033
|
2024-11-21 13:39 |
2021-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222239
|
9.8 |
CRITICAL
Network
|
nlnetlabs debian
|
unbound debian_linux
|
Unbound before 1.9.5 allows an integer overflow in the regional allocator via regional_alloc. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Un…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-25032
|
2024-11-21 13:39 |
2021-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222240
|
5.9 |
MEDIUM
Network
|
nlnetlabs debian
|
unbound debian_linux
|
Unbound before 1.9.5 allows configuration injection in create_unbound_ad_servers.sh upon a successful man-in-the-middle attack against a cleartext HTTP session. NOTE: The vendor does not consider thi…
|
CWE-74
Injection
|
CVE-2019-25031
|
2024-11-21 13:39 |
2021-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|