Search CVE reports
81 – 90 of 31565 results
In NLnet Labs Unbound 1.16.2 up to and including 1.25.1, a similar vulnerability as with CVE-2026-40622 in the 'ghost domain names' family of attacks was found in Unbound that could extend the ghost domain window by up to one...
1 affected package
unbound
| Package | 26.04 LTS |
|---|---|
| unbound | Needs evaluation |
In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, client terminated DNS-over-QUIC (DoQ) queries are not accounted properly by Unbound resulting in low-cost inflation of the waiting number of replies for already in-flight...
1 affected package
unbound
| Package | 26.04 LTS |
|---|---|
| unbound | Needs evaluation |
In Unbound 1.9.0 up to and including 1.25.1, when a DNSCrypt query is received over TCP, the routine that encrypts the reply in place fails to bound the reply length against the destination buffer size. The size clamp that...
1 affected package
unbound
| Package | 26.04 LTS |
|---|---|
| unbound | Needs evaluation |
In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, when downstream DNS-over-QUIC (DoQ) is enabled, the first two bidirectional streams on a new QUIC connection (stream_id 0 and 4) bypass the per-stream 'quic-size' gate...
1 affected package
unbound
| Package | 26.04 LTS |
|---|---|
| unbound | Needs evaluation |
A heap-buffer-overflow flaw was found in Directory Server (389-ds-base). When a DN contains a legacy-quoted value, the server won't close the heap allocation allowing another call to refer to the same memory pointer causing a...
1 affected package
389-ds-base
| Package | 26.04 LTS |
|---|---|
| 389-ds-base | Needs evaluation |
In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, in DNS-over-QUIC environments, with high concurrency and under pressure, an assertion in libngtcp2 about monotonic timestamps could trigger and result in server termination...
1 affected package
unbound
| Package | 26.04 LTS |
|---|---|
| unbound | Needs evaluation |
A flaw was found in the sbc library (BlueZ SBC codec). An off-by-one error in the SBC frame decoder allows a crafted audio payload to trigger a one-byte heap out-of-bounds read. This could allow an adjacent attacker streaming...
1 affected package
sbc
| Package | 26.04 LTS |
|---|---|
| sbc | Needs evaluation |
[Heap-Based Buffer Overflow in KMREQ Handling]
1 affected package
srt
| Package | 26.04 LTS |
|---|---|
| srt | Needs evaluation |
[Encryption State Machine Downgrade]
1 affected package
srt
| Package | 26.04 LTS |
|---|---|
| srt | Needs evaluation |
Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and prior to 4.1.135.Final, `OcspClient` does not validate that the `CertificateID` in an OCSP...
1 affected package
netty
| Package | 26.04 LTS |
|---|---|
| netty | Needs evaluation |