NIC records
18 published records for vendor nic.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 77.8%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-20 Improper Input Validation6
- CWE-290 Authentication Bypass by Spoofing2
- CWE-407 Inefficient Algorithmic Complexity2
- CWE-770 Allocation of Resources Without Limits or Throttling2
- CWE-306 Missing Authentication for Critical Function1
- CWE-617 Reachable Assertion1
The weakness classes this vendor ships most often: where to look.
CWEAll records
18 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
60This week | CVE-2023-50387Proof of concept | Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of serredhat · enterprise linux · CWE-770 | High7.5 | — | 100.0% | Feb 14, 2024 |
39Monitor | CVE-2021-3346No exploit | Foris before 101.1.1, as used in Turris OS, lacks certain HTML escaping in the login template.nic · foris | Critical9.8 | — | 1.6% | Jan 29, 2021 |
31Monitor | CVE-2014-0486No exploit | Knot DNS before 1.5.2 allows remote attackers to cause a denial of service (application crash) via a crafted DNS message.nic · knot cms · CWE-20 | High7.5 | — | 3.3% | Mar 27, 2018 |
31Monitor | CVE-2019-16159No exploit | BIRD Internet Routing Daemon 1.6.x through 1.6.7 and 2.x through 2.0.5 has a stack-based buffer overflow.nic · bird · CWE-787 | High7.5 | — | 3.2% | Sep 9, 2019 |
31Monitor | CVE-2020-12667No exploit | Knot Resolver before 5.1.1 allows traffic amplification via a crafted DNS answer from an attacker-controlled server, aka an "NXNSAttack" issnic · knot resolver · CWE-400 | High7.5 | — | 2.5% | May 19, 2020 |
31Monitor | CVE-2019-19331No exploit | knot-resolver before version 4.3.0 is vulnerable to denial of service through high CPU utilization.nic · knot resolver · CWE-407 | High7.5 | — | 2.2% | Dec 16, 2019 |
31Monitor | CVE-2019-10190No exploit | A vulnerability was discovered in DNS resolver component of knot resolver through version 3.2.0 before 4.1.0 which allows remote attackers tnic · knot resolver · CWE-20 | High7.5 | — | 2.0% | Jul 16, 2019 |
31Monitor | CVE-2019-10191No exploit | A vulnerability was discovered in DNS resolver of knot resolver before version 4.1.0 which allows remote attackers to downgrade DNSSEC-securnic · knot resolver · CWE-20 | High7.5 | — | 1.9% | Jul 16, 2019 |
31Monitor | CVE-2022-40188No exploit | Knot Resolver before 5.5.3 allows remote attackers to cause a denial of service (CPU consumption) because of algorithmic complexity.nic · knot resolver · CWE-407 | High7.5 | — | 1.9% | Sep 23, 2022 |
30Monitor | CVE-2021-40083No exploit | Knot Resolver before 5.3.2 is prone to an assertion failure, triggerable by a remote attacker in an edge case (NSEC3 with too many iterationnic · knot resolver · CWE-617 | High7.5 | — | 1.4% | Aug 24, 2021 |
30Monitor | CVE-2018-1110No exploit | A flaw was found in knot-resolver before version 2.3.0.nic · knot resolver · CWE-20 | High7.5 | — | 1.1% | Mar 29, 2021 |
30Monitor | CVE-2023-26249No exploit | Knot Resolver before 5.6.0 enables attackers to consume its resources, launching amplification attacks and potentially causing a denial of snic · knot resolver · CWE-770 | High7.5 | — | 0.7% | Feb 20, 2023 |
30Monitor | CVE-2023-46317No exploit | Knot Resolver before 5.7.0 performs many TCP reconnections upon receiving certain nonsensical responses from servers.nic · knot resolver | High7.5 | — | 0.6% | Oct 22, 2023 |
28Monitor | CVE-2018-10920Proof of concept | Improper input validation bug in DNS resolver component of Knot Resolver before 2.4.1 allows remote attacker to poison cache.nic · knot resolver · CWE-20 | Medium6.8 | — | 3.2% | Aug 2, 2018 |
27Monitor | CVE-2021-26928No exploit | BIRD through 2.0.7 does not provide functionality for password authentication of BGP peers.nic · bird · CWE-306 | Medium6.8 | — | 1.0% | Jun 4, 2021 |
24Monitor | CVE-2013-5661No exploit | Cache Poisoning issue exists in DNS Response Rate Limiting.isc · bind · CWE-290 | Medium5.9 | — | 3.5% | Nov 5, 2019 |
21Monitor | CVE-2022-32983No exploit | Knot Resolver through 5.5.1 may allow DNS cache poisoning when there is an attempt to limit forwarding actions by filters.nic · knot resolver · CWE-290 | Medium5.3 | — | 0.7% | Jun 20, 2022 |
14Monitor | CVE-2018-1000002No exploit | Improper input validation bugs in DNSSEC validators components in Knot Resolver (prior version 1.5.2) allow attacker in man-in-the-middle ponic · knot resolver · CWE-20 | Low3.7 | — | 1.1% | Jan 22, 2018 |
- CVE-2023-5038760This week
Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of ser
HighCVSS 7.5Proof of conceptEPSS 100%redhat · enterprise linuxFeb 14, 2024
- CVE-2021-334639Monitor
Foris before 101.1.1, as used in Turris OS, lacks certain HTML escaping in the login template.
CriticalCVSS 9.8No exploitEPSS 2%nic · forisJan 29, 2021
- CVE-2014-048631Monitor
Knot DNS before 1.5.2 allows remote attackers to cause a denial of service (application crash) via a crafted DNS message.
HighCVSS 7.5No exploitEPSS 3%nic · knot cmsMar 27, 2018
- CVE-2019-1615931Monitor
BIRD Internet Routing Daemon 1.6.x through 1.6.7 and 2.x through 2.0.5 has a stack-based buffer overflow.
HighCVSS 7.5No exploitEPSS 3%nic · birdSep 9, 2019
- CVE-2020-1266731Monitor
Knot Resolver before 5.1.1 allows traffic amplification via a crafted DNS answer from an attacker-controlled server, aka an "NXNSAttack" iss
HighCVSS 7.5No exploitEPSS 3%nic · knot resolverMay 19, 2020
- CVE-2019-1933131Monitor
knot-resolver before version 4.3.0 is vulnerable to denial of service through high CPU utilization.
HighCVSS 7.5No exploitEPSS 2%nic · knot resolverDec 16, 2019
- CVE-2019-1019031Monitor
A vulnerability was discovered in DNS resolver component of knot resolver through version 3.2.0 before 4.1.0 which allows remote attackers t
HighCVSS 7.5No exploitEPSS 2%nic · knot resolverJul 16, 2019
- CVE-2019-1019131Monitor
A vulnerability was discovered in DNS resolver of knot resolver before version 4.1.0 which allows remote attackers to downgrade DNSSEC-secur
HighCVSS 7.5No exploitEPSS 2%nic · knot resolverJul 16, 2019
- CVE-2022-4018831Monitor
Knot Resolver before 5.5.3 allows remote attackers to cause a denial of service (CPU consumption) because of algorithmic complexity.
HighCVSS 7.5No exploitEPSS 2%nic · knot resolverSep 23, 2022
- CVE-2021-4008330Monitor
Knot Resolver before 5.3.2 is prone to an assertion failure, triggerable by a remote attacker in an edge case (NSEC3 with too many iteration
HighCVSS 7.5No exploitEPSS 1%nic · knot resolverAug 24, 2021
- CVE-2018-111030Monitor
A flaw was found in knot-resolver before version 2.3.0.
HighCVSS 7.5No exploitEPSS 1%nic · knot resolverMar 29, 2021
- CVE-2023-2624930Monitor
Knot Resolver before 5.6.0 enables attackers to consume its resources, launching amplification attacks and potentially causing a denial of s
HighCVSS 7.5No exploitEPSS 1%nic · knot resolverFeb 20, 2023
- CVE-2023-4631730Monitor
Knot Resolver before 5.7.0 performs many TCP reconnections upon receiving certain nonsensical responses from servers.
HighCVSS 7.5No exploitEPSS 1%nic · knot resolverOct 22, 2023
- CVE-2018-1092028Monitor
Improper input validation bug in DNS resolver component of Knot Resolver before 2.4.1 allows remote attacker to poison cache.
MediumCVSS 6.8Proof of conceptEPSS 3%nic · knot resolverAug 2, 2018
- CVE-2021-2692827Monitor
BIRD through 2.0.7 does not provide functionality for password authentication of BGP peers.
MediumCVSS 6.8No exploitEPSS 1%nic · birdJun 4, 2021
- CVE-2013-566124Monitor
Cache Poisoning issue exists in DNS Response Rate Limiting.
MediumCVSS 5.9No exploitEPSS 3%isc · bindNov 5, 2019
- CVE-2022-3298321Monitor
Knot Resolver through 5.5.1 may allow DNS cache poisoning when there is an attempt to limit forwarding actions by filters.
MediumCVSS 5.3No exploitEPSS 1%nic · knot resolverJun 20, 2022
- CVE-2018-100000214Monitor
Improper input validation bugs in DNSSEC validators components in Knot Resolver (prior version 1.5.2) allow attacker in man-in-the-middle po
LowCVSS 3.7No exploitEPSS 1%nic · knot resolverJan 22, 2018