Search CVE reports


Toggle filters

31 – 40 of 71 results


CVE-2018-16855

Medium priority

Some fixes available 14 of 16

An issue has been found in PowerDNS Recursor before version 4.1.8 where a remote attacker sending a DNS query can trigger an out-of-bounds memory read while computing the hash of the query for a packet cache lookup, possibly...

1 affected package

pdns-recursor

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pdns-recursor Fixed Fixed Fixed Vulnerable
Show less packages

CVE-2018-14626

Medium priority

Some fixes available 3 of 14

PowerDNS Authoritative Server 4.1.0 up to 4.1.4 inclusive and PowerDNS Recursor 4.0.0 up to 4.1.4 inclusive are vulnerable to a packet cache pollution via crafted query that can lead to denial of service.

2 affected packages

pdns-recursor, pdns

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pdns-recursor Not affected Not affected Not affected Fixed
pdns Not affected Not affected Not affected Fixed
Show less packages

CVE-2018-10851

Medium priority

Some fixes available 4 of 15

PowerDNS Authoritative Server 3.3.0 up to 4.1.4 excluding 4.1.5 and 4.0.6, and PowerDNS Recursor 3.2 up to 4.1.4 excluding 4.1.5 and 4.0.9, are vulnerable to a memory leak while parsing malformed records that can lead to remote...

2 affected packages

pdns, pdns-recursor

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pdns Not affected Not affected Not affected Fixed
pdns-recursor Not affected Not affected Not affected Fixed
Show less packages

CVE-2018-14644

Medium priority

Some fixes available 2 of 13

An issue has been found in PowerDNS Recursor from 4.0.0 up to and including 4.1.4. A remote attacker sending a DNS query for a meta-type like OPT can lead to a zone being wrongly cached as failing DNSSEC validation. It only arises...

2 affected packages

pdns, pdns-recursor

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pdns Not affected Not affected Not affected Not affected
pdns-recursor Not affected Not affected Not affected Fixed
Show less packages

CVE-2016-2120

Medium priority
Vulnerable

An issue has been found in PowerDNS Authoritative Server versions up to and including 3.4.10, 4.0.1 allowing an authorized user to crash the server by inserting a specially crafted record in a zone under their control then sending...

1 affected package

pdns

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pdns Not affected Not affected Not affected Not affected
Show less packages

CVE-2016-7074

Medium priority
Vulnerable

An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 4.0.4, allowing an attacker in position of man-in-the-middle to alter the content of an AXFR because of insufficient validation of TSIG...

2 affected packages

pdns, pdns-recursor

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pdns Not affected Not affected Not affected Not affected
pdns-recursor Not affected Not affected Not affected Not affected
Show less packages

CVE-2016-7073

Medium priority
Vulnerable

An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 4.0.4, allowing an attacker in position of man-in-the-middle to alter the content of an AXFR because of insufficient validation of TSIG...

2 affected packages

pdns, pdns-recursor

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pdns Not affected Not affected Not affected Not affected
pdns-recursor Not affected Not affected Not affected Not affected
Show less packages

CVE-2016-7068

Low priority

Some fixes available 1 of 9

An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 3.7.4 and 4.0.4, allowing a remote, unauthenticated attacker to cause an abnormal CPU usage load on the PowerDNS server by sending crafted...

2 affected packages

pdns-recursor, pdns

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pdns-recursor Not affected Not affected Not affected Not affected
pdns Not affected Not affected Not affected Not affected
Show less packages

CVE-2016-7072

Medium priority
Vulnerable

An issue has been found in PowerDNS Authoritative Server before 3.4.11 and 4.0.2 allowing a remote, unauthenticated attacker to cause a denial of service by opening a large number of TCP connections to the web server. If the web...

1 affected package

pdns

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pdns Not affected Not affected Not affected Not affected
Show less packages

CVE-2017-15120

Medium priority
Vulnerable

An issue has been found in the parsing of authoritative answers in PowerDNS Recursor before 4.0.8, leading to a NULL pointer dereference when parsing a specially crafted answer containing a CNAME of a different class than IN. An...

1 affected package

pdns-recursor

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pdns-recursor Not affected Not affected Not affected Not affected
Show less packages