|
1
|
4.3 |
MEDIUM
Adjacent
|
openbsd
|
openbsd
|
In OpenBSD through 7.8, the slaacd and rad daemons have an infinite loop when they receive a crafted ICMPv6 Neighbor Discovery (ND) option (over a local network) with length zero, because of an "nd_o…
New
|
CWE-1284 CWE-835
Improper Validation of Specified Quantity in Input Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2026-41285
|
2026-04-25 03:59 |
2026-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2
|
5.5 |
MEDIUM
Local
|
uutils
|
coreutils
|
The sort utility in uutils coreutils is vulnerable to a process panic when using the --files0-from option with inputs containing non-UTF-8 filenames. The implementation enforces UTF-8 encoding and ut…
New
|
CWE-248
Uncaught Exception
|
CVE-2026-35348
|
2026-04-25 03:57 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3
|
7.5 |
HIGH
Network
|
powerdns
|
authoritative
|
A rogue primary server may cause file descriptor exhaustion and eventually a denial of service, when a PowerDNS secondary server forwards a DNS update request to it.
New
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-33610
|
2026-04-25 03:53 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4
|
6.5 |
MEDIUM
Network
|
powerdns
|
authoritative
|
Incomplete escaping of LDAP queries when running with 8bit-dns enabled allows users to perform queries of internal domain subtrees.
New
|
CWE-90
LDAP Injection
|
CVE-2026-33609
|
2026-04-25 03:52 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5
|
9.8 |
CRITICAL
Network
|
powerdns
|
authoritative
|
An attacker can send a notify request that causes a new secondary domain to be added to the bind backend, but causes said backend to update its configuration to an invalid one, leading to the backend…
New
|
CWE-94
Code Injection
|
CVE-2026-33608
|
2026-04-25 03:52 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6
|
8.2 |
HIGH
Network
|
powerdns
|
dnsdist
|
A rogue backend can send a crafted UDP response with a query ID off by one related to the maximum configured value, triggering an out-of-bounds write leading to a denial of service.
New
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-33602
|
2026-04-25 03:52 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7
|
8.1 |
HIGH
Adjacent
|
powerdns
|
dnsdist
|
A rogue backend can send a crafted SVCB response to a Discovery of Designated Resolvers request, when requested via either the autoUpgrade (Lua) option to newServer or auto_upgrade (YAML) settings. D…
New
|
CWE-125
Out-of-bounds Read
|
CVE-2026-33599
|
2026-04-25 03:52 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
8
|
9.1 |
CRITICAL
Network
|
powerdns
|
dnsdist
|
A cached crafted response can cause an out-of-bounds read if custom Lua code calls getDomainListByAddress() or getAddressListByDomain() on a packet cache.
New
|
CWE-125
Out-of-bounds Read
|
CVE-2026-33598
|
2026-04-25 03:51 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
9
|
7.5 |
HIGH
Network
|
powerdns
|
dnsdist
|
PRSD detection denial of service
New
|
CWE-116
Improper Encoding or Escaping of Output
|
CVE-2026-33597
|
2026-04-25 03:51 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
10
|
6.5 |
MEDIUM
Adjacent
|
powerdns
|
dnsdist
|
A client might theoretically be able to cause a mismatch between queries sent to a backend and the received responses by sending a flood of perfectly timed queries that are routed to a TCP-only or DN…
New
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2026-33596
|
2026-04-25 03:50 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|