VendorsNLnet Labsnsdall versions
Vulnerabilities

NLnet Labs NSD

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

12CVEs
CVE-2026-18664
Wrong interpretation of ACL ranges
Published 2026-08-26 · Analyzed
9.1EPSS 0.003
CVE-2026-12244
Heap overflow and crash with crafted SVCB RR
Published 2026-06-25 · Analyzed
8.8EPSS 0.005
CVE-2026-12245
Denial of DNS over TLS service by any DoT client
Published 2026-06-25 · Analyzed
8.7EPSS 0.005
CVE-2026-19401
Remote UDP DoS by sending multiple DNS Cookie options
Published 2026-08-26 · Analyzed
8.2EPSS 0.003
CVE-2026-19538
Bypass of BLOCKED ACL items on proxy protocol port over TCP or TLS
Published 2026-08-26 · Analyzed
8.2EPSS 0.002
CVE-2026-12490
Bypass of client certificate verification with transfer over TLS
Published 2026-06-25 · Analyzed
8.2EPSS 0.002
CVE-2026-12246
Out of bounds stack write with crafted APL RR
Published 2026-06-25 · Analyzed
8.1EPSS 0.004
CVE-2016-6173
NSD before 4.1.11 allows remote DNS master servers to cause a denial of service (/tmp disk consumption and slave server crash) via a zone transfer with unlimited data.
Published 2017-02-09 · Modified
7.8EPSS 0.029
CVE-2026-18916
Remote TCP DoS by throttling the TCP receive window
Published 2026-08-26 · Analyzed
7.5EPSS 0.003
CVE-2013-5661
Cache Poisoning issue exists in DNS Response Rate Limiting.
Published 2019-11-05 · Modified
5.9EPSS 0.035
CVE-2012-2978
query.c in NSD 3.0.x through 3.0.8, 3.1.x through 3.1.1, and 3.2.x before 3.2.12 allows remote attackers to cause a denial of service (NULL pointer dereference and child process crash) via a crafted DNS packet.
Published 2012-07-27 · Modified
5.0EPSS 0.092
CVE-2009-1755
Off-by-one error in the packet_read_query_section function in packet.c in nsd 3.2.1, and process_query_section in query.c in nsd 2.3.7, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors that trigger a buffer overflow.
Published 2009-05-22 · Modified
5.0EPSS 0.032