VendorsDproxy-Nexgen Projectdproxy-nexgenall versions
Vulnerabilities

Dproxy-Nexgen Project Dproxy-Nexgen

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2022-33990
Misinterpretation of special domain name characters in dproxy-nexgen (aka dproxy nexgen) leads to cache poisoning because domain names and their associated IP addresses are cached in their misinterpreted form.
Published 2022-08-15 · Modified
7.5EPSS 0.012
CVE-2022-33988
dproxy-nexgen (aka dproxy nexgen) re-uses the DNS transaction id (TXID) value from client queries, which allows attackers (able to send queries to the resolver) to conduct DNS cache-poisoning attacks because the TXID value is known to the attacker.
Published 2022-08-15 · Modified
7.5EPSS 0.011
CVE-2022-33989
dproxy-nexgen (aka dproxy nexgen) uses a static UDP source port (selected randomly only at boot time) in upstream queries sent to DNS resolvers. This allows DNS cache poisoning because there is not enough entropy to prevent traffic injection attacks.
Published 2022-08-15 · Modified
5.3EPSS 0.010
CVE-2022-33991
dproxy-nexgen (aka dproxy nexgen) forwards and caches DNS queries with the CD (aka checking disabled) bit set to 1. This leads to disabling of DNSSEC protection provided by upstream resolvers.
Published 2022-08-15 · Modified
5.3EPSS 0.009