Dproxy Nexgen Project maintains a narrowly focused proxy product that occupies a specialized role in network infrastructure, despite a modest vulnerability footprint. Current severity, exploitation, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dproxy Nexgen Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-33990HIGH Misinterpretation of special domain name characters in dproxy-nexgen (aka dproxy nexgen) leads to cache poisoning because domain names and their associated IP addresses are cached | Aug 15, 2022 | 7.5 | 24 | NO | NO |
CVE-2022-33988HIGH dproxy-nexgen (aka dproxy nexgen) re-uses the DNS transaction id (TXID) value from client queries, which allows attackers (able to send queries to the resolver) to conduct DNS cach | Aug 15, 2022 | 7.5 | 24 | NO | NO |
CVE-2022-33989MEDIUM dproxy-nexgen (aka dproxy nexgen) uses a static UDP source port (selected randomly only at boot time) in upstream queries sent to DNS resolvers. This allows DNS cache poisoning bec | Aug 15, 2022 | 5.3 | 19 | NO | NO |
CVE-2022-33991MEDIUM dproxy-nexgen (aka dproxy nexgen) forwards and caches DNS queries with the CD (aka checking disabled) bit set to 1. This leads to disabling of DNSSEC protection provided by upstrea | Aug 15, 2022 | 5.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dproxy Nexgen Project.
Media articles that mention a CVE ID that affects a product developed by Dproxy Nexgen Project — matched by CVE ID, not by vendor name.