CVE Browser
Search and filter CVEs by severity, ecosystem, EPSS score, and more.
Page 1 (more results available)
NSEC3 insecure-referral proof can use unrelated cached NSEC3 RRsets
Message parser retains every identical singleton RDATA, enabling wire-to-work amplification
Resource Exhaustion via Excessive DNSSEC Cryptographic Material Matching
Unauthenticated IXFR deltas are applied to the live zone before TSIG verification
Validating resolver can abort while caching a mismatched NOQNAME proof
named aborts on a TKEY query when the user configuration has no global options statement
Use-after-free in query_addnoqnameproof() via the DNS64 filter64 path
SVCB AliasMode additional-data error leaks qpcache references
Out-of-zone database nodes can become authoritative zone cuts
Unauthenticated remote crash of named via a single DoH SIG(0) request
checkwildcard() accepts an out-of-zone NSEC as a wildcard-nonexistence proof
qpcache NOQNAME proof use-after-free crashes recursive resolver
Remote assertion failure via 16-bit length truncation in `dns_ncache_add()`
Remote CPU denial of service through cached SVCB/HTTPS AliasMode trees
DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field
Unexpected exit in certain situations with NSEC and NSEC3 both present
Record ordering based unexpected exit with CNAME or DNAME
Cache poisoning possible with label count discrepancy, RRSIG, and wildcards
Potential memory usage beyond configured limits
Unnecessary validation of DNSSEC signed records
Potential wildcard CNAME RPZ policy bypass
Key Record using PRIVATEDNS algorithm may lead to unexpected exit
Incorrect acceptance of NSEC3 records
Unbounded resend loop in BIND 9 resolver
SIG(0) validation during query flood may lead to undefined behavior
Showing 1 to 25 CVEs · page 1 (more available)