Search CVE reports


Toggle filters

51 – 60 of 88 results


CVE-2018-14644

Medium priority

Some fixes available 2 of 13

An issue has been found in PowerDNS Recursor from 4.0.0 up to and including 4.1.4. A remote attacker sending a DNS query for a meta-type like OPT can lead to a zone being wrongly cached as failing DNSSEC validation. It only arises...

2 affected packages

pdns, pdns-recursor

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pdns Not affected Not affected Not affected Not affected
pdns-recursor Not affected Not affected Not affected Fixed
Show less packages

CVE-2016-2120

Medium priority
Vulnerable

An issue has been found in PowerDNS Authoritative Server versions up to and including 3.4.10, 4.0.1 allowing an authorized user to crash the server by inserting a specially crafted record in a zone under their control then sending...

1 affected package

pdns

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pdns Not affected Not affected Not affected Not affected
Show less packages

CVE-2016-7074

Medium priority
Vulnerable

An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 4.0.4, allowing an attacker in position of man-in-the-middle to alter the content of an AXFR because of insufficient validation of TSIG...

2 affected packages

pdns, pdns-recursor

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pdns Not affected Not affected Not affected Not affected
pdns-recursor Not affected Not affected Not affected Not affected
Show less packages

CVE-2016-7073

Medium priority
Vulnerable

An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 4.0.4, allowing an attacker in position of man-in-the-middle to alter the content of an AXFR because of insufficient validation of TSIG...

2 affected packages

pdns, pdns-recursor

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pdns Not affected Not affected Not affected Not affected
pdns-recursor Not affected Not affected Not affected Not affected
Show less packages

CVE-2016-7068

Low priority

Some fixes available 1 of 9

An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 3.7.4 and 4.0.4, allowing a remote, unauthenticated attacker to cause an abnormal CPU usage load on the PowerDNS server by sending crafted...

2 affected packages

pdns-recursor, pdns

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pdns-recursor Not affected Not affected Not affected Not affected
pdns Not affected Not affected Not affected Not affected
Show less packages

CVE-2016-7072

Medium priority
Vulnerable

An issue has been found in PowerDNS Authoritative Server before 3.4.11 and 4.0.2 allowing a remote, unauthenticated attacker to cause a denial of service by opening a large number of TCP connections to the web server. If the web...

1 affected package

pdns

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pdns Not affected Not affected Not affected Not affected
Show less packages

CVE-2017-15120

Medium priority
Vulnerable

An issue has been found in the parsing of authoritative answers in PowerDNS Recursor before 4.0.8, leading to a NULL pointer dereference when parsing a specially crafted answer containing a CNAME of a different class than IN. An...

1 affected package

pdns-recursor

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pdns-recursor Not affected Not affected Not affected Not affected
Show less packages

CVE-2018-1046

Medium priority

Some fixes available 1 of 11

pdns before version 4.1.2 is vulnerable to a buffer overflow in dnsreplay. In the dnsreplay tool provided with PowerDNS Authoritative, replaying a specially crafted PCAP file can trigger a stack-based buffer overflow, leading to a...

1 affected package

pdns

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pdns Not affected Not affected Not affected Fixed
Show less packages

CVE-2017-15094

Low priority
Vulnerable

An issue has been found in the DNSSEC parsing code of PowerDNS Recursor from 4.0.0 up to and including 4.0.6 leading to a memory leak when parsing specially crafted DNSSEC ECDSA keys. These keys are only parsed when validation is...

1 affected package

pdns-recursor

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pdns-recursor Not affected Not affected Not affected Not affected
Show less packages

CVE-2017-15093

Medium priority
Vulnerable

When api-config-dir is set to a non-empty value, which is not the case by default, the API in PowerDNS Recursor 4.x up to and including 4.0.6 and 3.x up to and including 3.7.4 allows an authorized user to update the Recursor's ACL...

1 affected package

pdns-recursor

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pdns-recursor Not affected Not affected Not affected Not affected
Show less packages