Search CVE reports
21 – 30 of 40 results
CVE-2016-7073
Medium priorityAn issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 4.0.4, allowing an attacker in position of man-in-the-middle to alter the content of an AXFR because of insufficient validation of TSIG...
2 affected packages
pdns, pdns-recursor
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
pdns | Not affected | Not affected | Not affected | Not affected | Vulnerable |
pdns-recursor | Not affected | Not affected | Not affected | Not affected | Vulnerable |
CVE-2016-7068
Low prioritySome fixes available 1 of 9
An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 3.7.4 and 4.0.4, allowing a remote, unauthenticated attacker to cause an abnormal CPU usage load on the PowerDNS server by sending crafted...
2 affected packages
pdns, pdns-recursor
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
pdns | Not affected | Not affected | Not affected | Not affected | Vulnerable |
pdns-recursor | Not affected | Not affected | Not affected | Not affected | Vulnerable |
CVE-2017-15120
Medium priorityAn issue has been found in the parsing of authoritative answers in PowerDNS Recursor before 4.0.8, leading to a NULL pointer dereference when parsing a specially crafted answer containing a CNAME of a different class than IN. An...
1 affected package
pdns-recursor
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
pdns-recursor | Not affected | Not affected | Not affected | Not affected | Vulnerable |
CVE-2017-15094
Low priorityAn issue has been found in the DNSSEC parsing code of PowerDNS Recursor from 4.0.0 up to and including 4.0.6 leading to a memory leak when parsing specially crafted DNSSEC ECDSA keys. These keys are only parsed when validation is...
1 affected package
pdns-recursor
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
pdns-recursor | Not affected | Not affected | Not affected | Not affected | Vulnerable |
CVE-2017-15093
Medium priorityWhen api-config-dir is set to a non-empty value, which is not the case by default, the API in PowerDNS Recursor 4.x up to and including 4.0.6 and 3.x up to and including 3.7.4 allows an authorized user to update the Recursor's ACL...
1 affected package
pdns-recursor
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
pdns-recursor | Not affected | Not affected | Not affected | Not affected | Vulnerable |
CVE-2017-15092
Medium priorityA cross-site scripting issue has been found in the web interface of PowerDNS Recursor from 4.0.0 up to and including 4.0.6, where the qname of DNS queries was displayed without any escaping, allowing a remote attacker to inject...
1 affected package
pdns-recursor
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
pdns-recursor | Not affected | Not affected | Not affected | Not affected | Vulnerable |
CVE-2017-15090
Medium priorityAn issue has been found in the DNSSEC validation component of PowerDNS Recursor from 4.0.0 and up to and including 4.0.6, where the signatures might have been accepted as valid even if the signed data was not in bailiwick of the...
1 affected package
pdns-recursor
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
pdns-recursor | Not affected | Not affected | Not affected | Not affected | Vulnerable |
CVE-2018-1000003
Unknown priorityImproper input validation bugs in DNSSEC validators components in PowerDNS version 4.1.0 allow attacker in man-in-the-middle position to deny existence of some data in DNS via packet replay.
1 affected package
pdns-recursor
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
pdns-recursor | — | — | — | Not affected | Not affected |
CVE-2015-5311
Low priorityPowerDNS (aka pdns) Authoritative Server 3.4.4 before 3.4.7 allows remote attackers to cause a denial of service (assertion failure and server crash) via crafted query packets.
2 affected packages
pdns, pdns-recursor
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
pdns | — | — | — | Not affected | Not affected |
pdns-recursor | — | — | — | Not affected | Not affected |
CVE-2015-5470
Low prioritySome fixes available 2 of 5
The label decompression functionality in PowerDNS Recursor before 3.6.4 and 3.7.x before 3.7.3 and Authoritative (Auth) Server before 3.3.3 and 3.4.x before 3.4.5 allows remote attackers to cause a denial of service...
2 affected packages
pdns, pdns-recursor
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
pdns | — | — | — | Not affected | Not affected |
pdns-recursor | — | — | — | Not affected | Not affected |