Totd Project maintains a DNS translation daemon with a focused vulnerability footprint centered on cryptographic and randomness initialization. The observed weakness classes—insufficient entropy and use of insufficiently random values—reflect the security-sensitive role of DNS operations and the demands of proper nonce and key generation in protocol implementations. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Totd Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-34294CRITICAL totd 1.5.3 uses a fixed UDP source port in upstream queries sent to DNS resolvers. This allows DNS cache poisoning because there is not enough entropy to prevent traffic injection | Aug 15, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-34295MEDIUM totd before 1.5.3 does not properly randomize mesg IDs. | Jun 23, 2022 | 6.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Totd Project.
Media articles that mention a CVE ID that affects a product developed by Totd Project — matched by CVE ID, not by vendor name.