Vulnerabilities > Nlnetlabs > Unbound > High

DATE CVE VULNERABILITY TITLE RISK
2019-10-03 CVE-2019-16866 Use of Uninitialized Resource vulnerability in multiple products
Unbound before 1.9.4 accesses uninitialized memory, which allows remote attackers to trigger a crash via a crafted NOTIFY query.
network
low complexity
nlnetlabs canonical CWE-908
7.5
2009-10-13 CVE-2009-3602 Cryptographic Issues vulnerability in Nlnetlabs Unbound
Unbound before 1.3.4 does not properly verify signatures for NSEC3 records, which allows remote attackers to cause secure delegations to be downgraded via DNS spoofing or other DNS-related attacks in conjunction with crafted delegation responses.
network
low complexity
nlnetlabs CWE-310
7.5