Vulnerabilities > DNS Sync Project

DATE CVE VULNERABILITY TITLE RISK
2018-06-07 CVE-2017-16100 Command Injection vulnerability in Dns-Sync Project Dns-Sync 0.1.0/0.1.1
dns-sync is a sync/blocking dns resolver.
network
low complexity
dns-sync-project CWE-77
critical
10.0
2015-02-28 CVE-2014-9682 Command Injection vulnerability in Dns-Sync Project Dns-Sync 0.1.0
The dns-sync module before 0.1.1 for node.js allows context-dependent attackers to execute arbitrary commands via shell metacharacters in the first argument to the resolve API function.
network
low complexity
dns-sync-project CWE-77
critical
10.0