NIC kayıtları
nic üreticisine ait 18 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %77,8
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-20 Improper Input Validation6
- CWE-290 Authentication Bypass by Spoofing2
- CWE-407 Inefficient Algorithmic Complexity2
- CWE-770 Allocation of Resources Without Limits or Throttling2
- CWE-306 Missing Authentication for Critical Function1
- CWE-617 Reachable Assertion1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
18 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
60Bu hafta | CVE-2023-50387Kavram kanıtı | Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of serredhat · enterprise linux · CWE-770 | Yüksek7,5 | — | %100,0 | 14 Şub 2024 |
39İzleyin | CVE-2021-3346İstismar yok | Foris before 101.1.1, as used in Turris OS, lacks certain HTML escaping in the login template.nic · foris | Kritik9,8 | — | %1,6 | 29 Oca 2021 |
31İzleyin | CVE-2014-0486İstismar yok | Knot DNS before 1.5.2 allows remote attackers to cause a denial of service (application crash) via a crafted DNS message.nic · knot cms · CWE-20 | Yüksek7,5 | — | %3,3 | 27 Mar 2018 |
31İzleyin | CVE-2019-16159İstismar yok | BIRD Internet Routing Daemon 1.6.x through 1.6.7 and 2.x through 2.0.5 has a stack-based buffer overflow.nic · bird · CWE-787 | Yüksek7,5 | — | %3,2 | 9 Eyl 2019 |
31İzleyin | CVE-2020-12667İstismar yok | Knot Resolver before 5.1.1 allows traffic amplification via a crafted DNS answer from an attacker-controlled server, aka an "NXNSAttack" issnic · knot resolver · CWE-400 | Yüksek7,5 | — | %2,5 | 19 May 2020 |
31İzleyin | CVE-2019-19331İstismar yok | knot-resolver before version 4.3.0 is vulnerable to denial of service through high CPU utilization.nic · knot resolver · CWE-407 | Yüksek7,5 | — | %2,2 | 16 Ara 2019 |
31İzleyin | CVE-2019-10190İstismar yok | A vulnerability was discovered in DNS resolver component of knot resolver through version 3.2.0 before 4.1.0 which allows remote attackers tnic · knot resolver · CWE-20 | Yüksek7,5 | — | %2,0 | 16 Tem 2019 |
31İzleyin | CVE-2019-10191İstismar yok | A vulnerability was discovered in DNS resolver of knot resolver before version 4.1.0 which allows remote attackers to downgrade DNSSEC-securnic · knot resolver · CWE-20 | Yüksek7,5 | — | %1,9 | 16 Tem 2019 |
31İzleyin | CVE-2022-40188İstismar yok | Knot Resolver before 5.5.3 allows remote attackers to cause a denial of service (CPU consumption) because of algorithmic complexity.nic · knot resolver · CWE-407 | Yüksek7,5 | — | %1,9 | 23 Eyl 2022 |
30İzleyin | CVE-2021-40083İstismar yok | Knot Resolver before 5.3.2 is prone to an assertion failure, triggerable by a remote attacker in an edge case (NSEC3 with too many iterationnic · knot resolver · CWE-617 | Yüksek7,5 | — | %1,4 | 24 Ağu 2021 |
30İzleyin | CVE-2018-1110İstismar yok | A flaw was found in knot-resolver before version 2.3.0.nic · knot resolver · CWE-20 | Yüksek7,5 | — | %1,1 | 29 Mar 2021 |
30İzleyin | CVE-2023-26249İstismar yok | Knot Resolver before 5.6.0 enables attackers to consume its resources, launching amplification attacks and potentially causing a denial of snic · knot resolver · CWE-770 | Yüksek7,5 | — | %0,7 | 20 Şub 2023 |
30İzleyin | CVE-2023-46317İstismar yok | Knot Resolver before 5.7.0 performs many TCP reconnections upon receiving certain nonsensical responses from servers.nic · knot resolver | Yüksek7,5 | — | %0,6 | 22 Eki 2023 |
28İzleyin | CVE-2018-10920Kavram kanıtı | Improper input validation bug in DNS resolver component of Knot Resolver before 2.4.1 allows remote attacker to poison cache.nic · knot resolver · CWE-20 | Orta6,8 | — | %3,2 | 2 Ağu 2018 |
27İzleyin | CVE-2021-26928İstismar yok | BIRD through 2.0.7 does not provide functionality for password authentication of BGP peers.nic · bird · CWE-306 | Orta6,8 | — | %1,0 | 4 Haz 2021 |
24İzleyin | CVE-2013-5661İstismar yok | Cache Poisoning issue exists in DNS Response Rate Limiting.isc · bind · CWE-290 | Orta5,9 | — | %3,5 | 5 Kas 2019 |
21İzleyin | CVE-2022-32983İstismar yok | Knot Resolver through 5.5.1 may allow DNS cache poisoning when there is an attempt to limit forwarding actions by filters.nic · knot resolver · CWE-290 | Orta5,3 | — | %0,7 | 20 Haz 2022 |
14İzleyin | CVE-2018-1000002İstismar yok | Improper input validation bugs in DNSSEC validators components in Knot Resolver (prior version 1.5.2) allow attacker in man-in-the-middle ponic · knot resolver · CWE-20 | Düşük3,7 | — | %1,1 | 22 Oca 2018 |
- CVE-2023-5038760Bu hafta
Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of ser
YüksekCVSS 7,5Kavram kanıtıEPSS %100redhat · enterprise linux14 Şub 2024
- CVE-2021-334639İzleyin
Foris before 101.1.1, as used in Turris OS, lacks certain HTML escaping in the login template.
KritikCVSS 9,8İstismar yokEPSS %2nic · foris29 Oca 2021
- CVE-2014-048631İzleyin
Knot DNS before 1.5.2 allows remote attackers to cause a denial of service (application crash) via a crafted DNS message.
YüksekCVSS 7,5İstismar yokEPSS %3nic · knot cms27 Mar 2018
- CVE-2019-1615931İzleyin
BIRD Internet Routing Daemon 1.6.x through 1.6.7 and 2.x through 2.0.5 has a stack-based buffer overflow.
YüksekCVSS 7,5İstismar yokEPSS %3nic · bird9 Eyl 2019
- CVE-2020-1266731İzleyin
Knot Resolver before 5.1.1 allows traffic amplification via a crafted DNS answer from an attacker-controlled server, aka an "NXNSAttack" iss
YüksekCVSS 7,5İstismar yokEPSS %3nic · knot resolver19 May 2020
- CVE-2019-1933131İzleyin
knot-resolver before version 4.3.0 is vulnerable to denial of service through high CPU utilization.
YüksekCVSS 7,5İstismar yokEPSS %2nic · knot resolver16 Ara 2019
- CVE-2019-1019031İzleyin
A vulnerability was discovered in DNS resolver component of knot resolver through version 3.2.0 before 4.1.0 which allows remote attackers t
YüksekCVSS 7,5İstismar yokEPSS %2nic · knot resolver16 Tem 2019
- CVE-2019-1019131İzleyin
A vulnerability was discovered in DNS resolver of knot resolver before version 4.1.0 which allows remote attackers to downgrade DNSSEC-secur
YüksekCVSS 7,5İstismar yokEPSS %2nic · knot resolver16 Tem 2019
- CVE-2022-4018831İzleyin
Knot Resolver before 5.5.3 allows remote attackers to cause a denial of service (CPU consumption) because of algorithmic complexity.
YüksekCVSS 7,5İstismar yokEPSS %2nic · knot resolver23 Eyl 2022
- CVE-2021-4008330İzleyin
Knot Resolver before 5.3.2 is prone to an assertion failure, triggerable by a remote attacker in an edge case (NSEC3 with too many iteration
YüksekCVSS 7,5İstismar yokEPSS %1nic · knot resolver24 Ağu 2021
- CVE-2018-111030İzleyin
A flaw was found in knot-resolver before version 2.3.0.
YüksekCVSS 7,5İstismar yokEPSS %1nic · knot resolver29 Mar 2021
- CVE-2023-2624930İzleyin
Knot Resolver before 5.6.0 enables attackers to consume its resources, launching amplification attacks and potentially causing a denial of s
YüksekCVSS 7,5İstismar yokEPSS %1nic · knot resolver20 Şub 2023
- CVE-2023-4631730İzleyin
Knot Resolver before 5.7.0 performs many TCP reconnections upon receiving certain nonsensical responses from servers.
YüksekCVSS 7,5İstismar yokEPSS %1nic · knot resolver22 Eki 2023
- CVE-2018-1092028İzleyin
Improper input validation bug in DNS resolver component of Knot Resolver before 2.4.1 allows remote attacker to poison cache.
OrtaCVSS 6,8Kavram kanıtıEPSS %3nic · knot resolver2 Ağu 2018
- CVE-2021-2692827İzleyin
BIRD through 2.0.7 does not provide functionality for password authentication of BGP peers.
OrtaCVSS 6,8İstismar yokEPSS %1nic · bird4 Haz 2021
- CVE-2013-566124İzleyin
Cache Poisoning issue exists in DNS Response Rate Limiting.
OrtaCVSS 5,9İstismar yokEPSS %3isc · bind5 Kas 2019
- CVE-2022-3298321İzleyin
Knot Resolver through 5.5.1 may allow DNS cache poisoning when there is an attempt to limit forwarding actions by filters.
OrtaCVSS 5,3İstismar yokEPSS %1nic · knot resolver20 Haz 2022
- CVE-2018-100000214İzleyin
Improper input validation bugs in DNSSEC validators components in Knot Resolver (prior version 1.5.2) allow attacker in man-in-the-middle po
DüşükCVSS 3,7İstismar yokEPSS %1nic · knot resolver22 Oca 2018