The DNS Sync Project maintains a narrowly scoped DNS synchronization tool that serves a specialized network-infrastructure use case, with its disclosed vulnerabilities concentrated in a single product. Live severity, exploitation, and exposure details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dns Sync Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-9682HIGH The dns-sync module before 0.1.1 for node.js allows context-dependent attackers to execute arbitrary commands via shell metacharacters in the first argument to the resolve API func | Feb 28, 2015 | 10.0 | 30 | NO | NO |
CVE-2017-16100CRITICAL dns-sync is a sync/blocking dns resolver. If untrusted user input is allowed into the resolve() method then command injection is possible. | Jun 7, 2018 | 9.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dns Sync Project.
Media articles that mention a CVE ID that affects a product developed by Dns Sync Project — matched by CVE ID, not by vendor name.