Search CVE reports


Toggle filters

21 – 30 of 52191 results

Status is adjusted based on your filters.


CVE-2026-55708

Medium priority
Needs evaluation

In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, the 'view_local_data' and 'view_local_datas' commands of 'unbound-control' create a bare local zones tree for an already configured named view when the view is configured...

1 affected package

unbound

Package 16.04 LTS
unbound Needs evaluation
Show less packages

CVE-2026-54478

Medium priority
Needs evaluation

In NLnet Labs Unbound 1.18.0 up to and including 1.25.1, when Unbound listens on a 'proxy-protocol-port' interface with 'answer-cookie: yes', the RFC 9018 server-cookie SipHash is computed over the proxy's wire address instead of...

1 affected package

unbound

Package 16.04 LTS
unbound Needs evaluation
Show less packages

CVE-2026-53910

Medium priority
Needs evaluation

diff3 tool from GNU diffutils is vulnerable to a heap‑based buffer overflow due to multiple signed integer overflows in line‑mapping calculations. Incorrect arithmetic in mapping line ranges can result in corrupted values being...

1 affected package

diffutils

Package 16.04 LTS
diffutils Needs evaluation
Show less packages

CVE-2026-52863

Medium priority
Needs evaluation

In NLnet Labs Unbound 1.25.0 up to and including 1.25.1, a fix that makes the 'respip' and 'dns64' modules work together, creates a shallow copy of the view name in effect that could lead to memory corruption if the owner of the...

1 affected package

unbound

Package 16.04 LTS
unbound Needs evaluation
Show less packages

CVE-2026-50252

Medium priority
Needs evaluation

In NLnet Labs Unbound 1.4.22 up to and including 1.25.1, UDP source port is randomized and intended to serve as a secret value that increases the entropy of DNS transactions. When resolver load balancing policies depend on the...

1 affected package

unbound

Package 16.04 LTS
unbound Needs evaluation
Show less packages

CVE-2026-50251

Medium priority
Needs evaluation

In NLnet Labs Unbound up to and including version 1.25.1, when 'unwanted-reply-threshold' is enabled (set to any value greater than zero), glue records of 0.0.0.0/::0 can short-circuit Unbound, on systems that can direct such...

1 affected package

unbound

Package 16.04 LTS
unbound Needs evaluation
Show less packages

CVE-2026-50248

Medium priority
Needs evaluation

In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when an auth/rpz zone has a configured primary hostname that resolves to BOGUS A/AAAA, it is still considered as a possible XFR endpoint. A malicious actor that can spoof the...

1 affected package

unbound

Package 16.04 LTS
unbound Needs evaluation
Show less packages

CVE-2026-50243

Medium priority
Needs evaluation

In NLnet Labs Unbound 1.6.2 up to and including 1.25.1, when Unbound is configured with the 'respip' module in front of the validator together with a 'response-ip' redirect rule or an RPZ file with an RPZ-IP trigger, the rewriting...

1 affected package

unbound

Package 16.04 LTS
unbound Needs evaluation
Show less packages

CVE-2026-50046

Medium priority
Needs evaluation

In NLnet Labs Unbound 1.15.0 up to and including 1.25.1, the TLS server name used for DNS-over-TLS (DoT) forwarded queries is tied to a struct's ('serviced_query') lifetime but also referenced by another struct ('waiting_tcp')....

1 affected package

unbound

Package 16.04 LTS
unbound Needs evaluation
Show less packages

CVE-2026-50045

Medium priority
Needs evaluation

In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a single client query for a deeply nested name under a DNSSEC-signed parent can cause Unbound to send more upstream packets per client query than the...

1 affected package

unbound

Package 16.04 LTS
unbound Needs evaluation
Show less packages