Записи NIC
18 опубликованных записей вендора nic.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 77,8 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-20 Improper Input Validation6
- CWE-290 Authentication Bypass by Spoofing2
- CWE-407 Inefficient Algorithmic Complexity2
- CWE-770 Allocation of Resources Without Limits or Throttling2
- CWE-306 Missing Authentication for Critical Function1
- CWE-617 Reachable Assertion1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
18 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
60На этой неделе | CVE-2023-50387Proof of concept | Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of serredhat · enterprise linux · CWE-770 | Высокая7,5 | — | 100,0 % | 14 февр. 2024 г. |
39Наблюдать | CVE-2021-3346Эксплойта нет | Foris before 101.1.1, as used in Turris OS, lacks certain HTML escaping in the login template.nic · foris | Критическая9,8 | — | 1,6 % | 29 янв. 2021 г. |
31Наблюдать | CVE-2014-0486Эксплойта нет | Knot DNS before 1.5.2 allows remote attackers to cause a denial of service (application crash) via a crafted DNS message.nic · knot cms · CWE-20 | Высокая7,5 | — | 3,3 % | 27 мар. 2018 г. |
31Наблюдать | CVE-2019-16159Эксплойта нет | BIRD Internet Routing Daemon 1.6.x through 1.6.7 and 2.x through 2.0.5 has a stack-based buffer overflow.nic · bird · CWE-787 | Высокая7,5 | — | 3,2 % | 9 сент. 2019 г. |
31Наблюдать | CVE-2020-12667Эксплойта нет | Knot Resolver before 5.1.1 allows traffic amplification via a crafted DNS answer from an attacker-controlled server, aka an "NXNSAttack" issnic · knot resolver · CWE-400 | Высокая7,5 | — | 2,5 % | 19 мая 2020 г. |
31Наблюдать | CVE-2019-19331Эксплойта нет | knot-resolver before version 4.3.0 is vulnerable to denial of service through high CPU utilization.nic · knot resolver · CWE-407 | Высокая7,5 | — | 2,2 % | 16 дек. 2019 г. |
31Наблюдать | CVE-2019-10190Эксплойта нет | A vulnerability was discovered in DNS resolver component of knot resolver through version 3.2.0 before 4.1.0 which allows remote attackers tnic · knot resolver · CWE-20 | Высокая7,5 | — | 2,0 % | 16 июл. 2019 г. |
31Наблюдать | CVE-2019-10191Эксплойта нет | A vulnerability was discovered in DNS resolver of knot resolver before version 4.1.0 which allows remote attackers to downgrade DNSSEC-securnic · knot resolver · CWE-20 | Высокая7,5 | — | 1,9 % | 16 июл. 2019 г. |
31Наблюдать | CVE-2022-40188Эксплойта нет | Knot Resolver before 5.5.3 allows remote attackers to cause a denial of service (CPU consumption) because of algorithmic complexity.nic · knot resolver · CWE-407 | Высокая7,5 | — | 1,9 % | 23 сент. 2022 г. |
30Наблюдать | CVE-2021-40083Эксплойта нет | Knot Resolver before 5.3.2 is prone to an assertion failure, triggerable by a remote attacker in an edge case (NSEC3 with too many iterationnic · knot resolver · CWE-617 | Высокая7,5 | — | 1,4 % | 24 авг. 2021 г. |
30Наблюдать | CVE-2018-1110Эксплойта нет | A flaw was found in knot-resolver before version 2.3.0.nic · knot resolver · CWE-20 | Высокая7,5 | — | 1,1 % | 29 мар. 2021 г. |
30Наблюдать | CVE-2023-26249Эксплойта нет | Knot Resolver before 5.6.0 enables attackers to consume its resources, launching amplification attacks and potentially causing a denial of snic · knot resolver · CWE-770 | Высокая7,5 | — | 0,7 % | 20 февр. 2023 г. |
30Наблюдать | CVE-2023-46317Эксплойта нет | Knot Resolver before 5.7.0 performs many TCP reconnections upon receiving certain nonsensical responses from servers.nic · knot resolver | Высокая7,5 | — | 0,6 % | 22 окт. 2023 г. |
28Наблюдать | CVE-2018-10920Proof of concept | Improper input validation bug in DNS resolver component of Knot Resolver before 2.4.1 allows remote attacker to poison cache.nic · knot resolver · CWE-20 | Средняя6,8 | — | 3,2 % | 2 авг. 2018 г. |
27Наблюдать | CVE-2021-26928Эксплойта нет | BIRD through 2.0.7 does not provide functionality for password authentication of BGP peers.nic · bird · CWE-306 | Средняя6,8 | — | 1,0 % | 4 июн. 2021 г. |
24Наблюдать | CVE-2013-5661Эксплойта нет | Cache Poisoning issue exists in DNS Response Rate Limiting.isc · bind · CWE-290 | Средняя5,9 | — | 3,5 % | 5 нояб. 2019 г. |
21Наблюдать | CVE-2022-32983Эксплойта нет | Knot Resolver through 5.5.1 may allow DNS cache poisoning when there is an attempt to limit forwarding actions by filters.nic · knot resolver · CWE-290 | Средняя5,3 | — | 0,7 % | 20 июн. 2022 г. |
14Наблюдать | CVE-2018-1000002Эксплойта нет | Improper input validation bugs in DNSSEC validators components in Knot Resolver (prior version 1.5.2) allow attacker in man-in-the-middle ponic · knot resolver · CWE-20 | Низкая3,7 | — | 1,1 % | 22 янв. 2018 г. |
- CVE-2023-5038760На этой неделе
Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of ser
ВысокаяCVSS 7,5Proof of conceptEPSS 100 %redhat · enterprise linux14 февр. 2024 г.
- CVE-2021-334639Наблюдать
Foris before 101.1.1, as used in Turris OS, lacks certain HTML escaping in the login template.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %nic · foris29 янв. 2021 г.
- CVE-2014-048631Наблюдать
Knot DNS before 1.5.2 allows remote attackers to cause a denial of service (application crash) via a crafted DNS message.
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %nic · knot cms27 мар. 2018 г.
- CVE-2019-1615931Наблюдать
BIRD Internet Routing Daemon 1.6.x through 1.6.7 and 2.x through 2.0.5 has a stack-based buffer overflow.
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %nic · bird9 сент. 2019 г.
- CVE-2020-1266731Наблюдать
Knot Resolver before 5.1.1 allows traffic amplification via a crafted DNS answer from an attacker-controlled server, aka an "NXNSAttack" iss
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %nic · knot resolver19 мая 2020 г.
- CVE-2019-1933131Наблюдать
knot-resolver before version 4.3.0 is vulnerable to denial of service through high CPU utilization.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %nic · knot resolver16 дек. 2019 г.
- CVE-2019-1019031Наблюдать
A vulnerability was discovered in DNS resolver component of knot resolver through version 3.2.0 before 4.1.0 which allows remote attackers t
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %nic · knot resolver16 июл. 2019 г.
- CVE-2019-1019131Наблюдать
A vulnerability was discovered in DNS resolver of knot resolver before version 4.1.0 which allows remote attackers to downgrade DNSSEC-secur
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %nic · knot resolver16 июл. 2019 г.
- CVE-2022-4018831Наблюдать
Knot Resolver before 5.5.3 allows remote attackers to cause a denial of service (CPU consumption) because of algorithmic complexity.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %nic · knot resolver23 сент. 2022 г.
- CVE-2021-4008330Наблюдать
Knot Resolver before 5.3.2 is prone to an assertion failure, triggerable by a remote attacker in an edge case (NSEC3 with too many iteration
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %nic · knot resolver24 авг. 2021 г.
- CVE-2018-111030Наблюдать
A flaw was found in knot-resolver before version 2.3.0.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %nic · knot resolver29 мар. 2021 г.
- CVE-2023-2624930Наблюдать
Knot Resolver before 5.6.0 enables attackers to consume its resources, launching amplification attacks and potentially causing a denial of s
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %nic · knot resolver20 февр. 2023 г.
- CVE-2023-4631730Наблюдать
Knot Resolver before 5.7.0 performs many TCP reconnections upon receiving certain nonsensical responses from servers.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %nic · knot resolver22 окт. 2023 г.
- CVE-2018-1092028Наблюдать
Improper input validation bug in DNS resolver component of Knot Resolver before 2.4.1 allows remote attacker to poison cache.
СредняяCVSS 6,8Proof of conceptEPSS 3 %nic · knot resolver2 авг. 2018 г.
- CVE-2021-2692827Наблюдать
BIRD through 2.0.7 does not provide functionality for password authentication of BGP peers.
СредняяCVSS 6,8Эксплойта нетEPSS 1 %nic · bird4 июн. 2021 г.
- CVE-2013-566124Наблюдать
Cache Poisoning issue exists in DNS Response Rate Limiting.
СредняяCVSS 5,9Эксплойта нетEPSS 3 %isc · bind5 нояб. 2019 г.
- CVE-2022-3298321Наблюдать
Knot Resolver through 5.5.1 may allow DNS cache poisoning when there is an attempt to limit forwarding actions by filters.
СредняяCVSS 5,3Эксплойта нетEPSS 1 %nic · knot resolver20 июн. 2022 г.
- CVE-2018-100000214Наблюдать
Improper input validation bugs in DNSSEC validators components in Knot Resolver (prior version 1.5.2) allow attacker in man-in-the-middle po
НизкаяCVSS 3,7Эксплойта нетEPSS 1 %nic · knot resolver22 янв. 2018 г.