![](/assets/img/cve_300x82_sin_bg.png)
CVE-2019-16866 – Ubuntu Security Notice USN-4149-1
https://notcve.org/view.php?id=CVE-2019-16866
03 Oct 2019 — Unbound before 1.9.4 accesses uninitialized memory, which allows remote attackers to trigger a crash via a crafted NOTIFY query. The source IP address of the query must match an access-control rule. Unbound versiones anteriores a 1.9.4, accede a la memoria no inicializada, lo que permite a atacantes remotos desencadenar un bloqueo por medio de una consulta NOTIFY diseñada. La dirección IP del origen de la consulta debe coincidir con una regla de control de acceso. X41 D-Sec discovered that unbound, a valida... • https://github.com/NLnetLabs/unbound/blob/release-1.9.4/doc/Changelog • CWE-755: Improper Handling of Exceptional Conditions CWE-908: Use of Uninitialized Resource •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2017-15105 – Ubuntu Security Notice USN-3673-1
https://notcve.org/view.php?id=CVE-2017-15105
23 Jan 2018 — A flaw was found in the way unbound before 1.6.8 validated wildcard-synthesized NSEC records. An improperly validated wildcard NSEC record could be used to prove the non-existence (NXDOMAIN answer) of an existing wildcard record, or trick unbound into accepting a NODATA proof. Se ha encontrado un error en la forma en la que unbound, en versiones anteriores a la 1.6.8, validaba los registros NSEC sintetizados con caracteres comodín. Un registro con caracteres comodín NSEC validado incorrectamente podría empl... • http://www.securityfocus.com/bid/102817 • CWE-20: Improper Input Validation CWE-358: Improperly Implemented Security Check for Standard •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2014-8602 – unbound: specially crafted request can lead to denial of service
https://notcve.org/view.php?id=CVE-2014-8602
11 Dec 2014 — iterator.c in NLnet Labs Unbound before 1.5.1 does not limit delegation chaining, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a large or infinite number of referrals. iterator.c en NLnet Labs Unbound anterior a 1.5.1 no limita el encadenamiento de la delegación, lo que permite a atacantes remotos causar una denegación de servicio (consumo de memoria y CPU) a través de un número grande o infinito de remisiones. A denial of service flaw was found in unbound that... • http://cert.ssi.gouv.fr/site/CERTFR-2014-AVI-512/index.html • CWE-399: Resource Management Errors CWE-770: Allocation of Resources Without Limits or Throttling •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2012-1192
https://notcve.org/view.php?id=CVE-2012-1192
17 Feb 2012 — The resolver in Unbound before 1.4.11 overwrites cached server names and TTL values in NS records during the processing of a response to an A record query, which allows remote attackers to trigger continued resolvability of revoked domain names via a "ghost domain names" attack. El resolver en Unbound anterior a v1.4.11 sobrescribe los nombres de caché del servidor y los valores TTL en los registros NS durante la tramitación de una respuesta a una consulta de registro A, permitiendo a atacantes remotos prov... • https://www.isc.org/files/imce/ghostdomain_camera.pdf •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2011-4528 – Gentoo Linux Security Advisory 201311-18
https://notcve.org/view.php?id=CVE-2011-4528
20 Dec 2011 — Unbound before 1.4.13p2 attempts to free unallocated memory during processing of duplicate CNAME records in a signed zone, which allows remote DNS servers to cause a denial of service (daemon crash) via a crafted response. Unbound antes de v1.4.13p2 intenta liberar memoria sin asignar durante el procesado de registros CNAME duplicados, lo que permite a servidores DNS remotos provocar una denegación de servicio (caída del demonio) a través de una respuesta modificada. Multiple Denial of Service vulnerabiliti... • http://lists.fedoraproject.org/pipermail/package-announce/2012-January/071525.html • CWE-399: Resource Management Errors •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2011-4869 – Gentoo Linux Security Advisory 201311-18
https://notcve.org/view.php?id=CVE-2011-4869
20 Dec 2011 — validator/val_nsec3.c in Unbound before 1.4.13p2 does not properly perform proof processing for NSEC3-signed zones, which allows remote DNS servers to cause a denial of service (daemon crash) via a malformed response that lacks expected NSEC3 records, a different vulnerability than CVE-2011-4528. validator/val_nsec3.c en Unbound antes de v1.4.13p2, no realiza adecuadamente el postprocesamiento de la prueba para zonas NSEC3-signed, lo que permite a servidores DNS remotos provocar una denegación de servicio (... • http://lists.fedoraproject.org/pipermail/package-announce/2012-January/071525.html • CWE-399: Resource Management Errors •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2011-1922
https://notcve.org/view.php?id=CVE-2011-1922
31 May 2011 — daemon/worker.c in Unbound 1.x before 1.4.10, when debugging functionality and the interface-automatic option are enabled, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted DNS request that triggers improper error handling. daemon/worker.c de Unbound 1.x anteriores a 1.4.10, cuando la funcionalidad de depuración de errores ("debugging") y la opción de "interface-automatic" están activadas, permite a atacantes remotos provocar una denegación de servicio (f... • http://lists.fedoraproject.org/pipermail/package-announce/2011-June/061243.html • CWE-399: Resource Management Errors •