D.J. Bernstein's vulnerability footprint is concentrated in djbdns, a widely used DNS implementation that handles authoritative and recursive DNS queries across many internet-facing deployments. The durable signal centers on input-validation robustness and proper handling of concurrent query processing, reflecting the parser-intensive and multi-threaded demands of DNS server software. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by D.J.Bernstein over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-0858MEDIUM The response_addname function in response.c in Daniel J. Bernstein djbdns 1.05 and earlier does not constrain offsets in the required manner, which allows remote attackers, with co | Mar 9, 2009 | 5.8 | 28 | NO | YES |
CVE-2012-1191MEDIUM The resolver in dnscache in Daniel J. Bernstein djbdns 1.05 overwrites cached server names and TTL values in NS records during the processing of a response to an A record query, wh | Feb 17, 2012 | 6.4 | 22 | NO | NO |
CVE-2008-4392MEDIUM dnscache in Daniel J. Bernstein djbdns 1.05 does not prevent simultaneous identical outbound DNS queries, which makes it easier for remote attackers to spoof DNS responses, as demo | Feb 19, 2009 | 6.4 | 21 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by D.J.Bernstein.
Media articles that mention a CVE ID that affects a product developed by D.J.Bernstein — matched by CVE ID, not by vendor name.