CVE Tools

Stichting-nlnet-labs

12 CVEs tracked since 2021. Since Apr 2021, none of them reached CISA KEV.

Stichting-nlnet-labs CVEs per month

Apr 2021 to Apr 2021. Point at a month, or focus the strip and use the arrow keys.
Stichting-nlnet-labs CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2021-04120

Products

The products that kept showing up in Stichting-nlnet-labs's monthly top three, with their CVEs summed over those months.

  1. Unbound121 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Stichting-nlnet-labs.

  1. CVE-2025-11411Possible domain hijacking via promiscuous records in the authority section7.4
  2. CVE-2025-5994Cache poisoning via the ECS-enabled Rebirthday Attack7.5
  3. CVE-2024-8508Unbounded name compression could lead to Denial of Service5.3
  4. CVE-2024-43168Unbound: heap-buffer-overflow in unbound4.8
  5. CVE-2024-43167Unbound: null pointer dereference in unbound2.8
  6. CVE-2024-33655The DNS protocol in RFC 1035 and updates allows remote attackers to cause a denial of service (resource consumption) by arranging for DNS queries to be accumulated for seconds, such that responses ...7.5
  7. CVE-2024-1931Denial of service when trimming EDE text on positive replies7.5
  8. CVE-2024-1488Unbound: unrestricted reconfiguration enabled to anyone that may lead to local privilege escalation8.0
  9. CVE-2022-3204NRDelegation Attack7.5
  10. CVE-2022-30699Novel "ghost domain names" attack by updating almost expired delegation information6.5
  11. CVE-2022-30698Novel "ghost domain names" attack by introducing subdomain delegations6.5
  12. CVE-2020-19861When a zone file in ldns 1.7.1 is parsed, the function ldns_nsec3_salt_data is too trusted for the length value obtained from the zone file. When the memcpy is copied, the 0xfe - ldns_rdf_size(salt...7.5
  13. CVE-2020-19860When ldns version 1.7.1 verifies a zone file, the ldns_rr_new_frm_str_internal function has a heap out of bounds read vulnerability. An attacker can leak information on the heap by constructing a z...6.5
  14. CVE-2019-25031Unbound before 1.9.5 allows configuration injection in create_unbound_ad_servers.sh upon a successful man-in-the-middle attack against a cleartext HTTP session. NOTE: The vendor does not consider t...5.9
  15. CVE-2019-25032Unbound before 1.9.5 allows an integer overflow in the regional allocator via regional_alloc. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running ...9.8

The record

Peak rank
#51 in Apr 2021
Busiest month shown
Apr 2021, 12 CVEs
Months with a KEV entry
0 since Apr 2021
Monthly snapshots
1 since 2021
Stichting-nlnet-labs's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store