Записи PowerDNS
108 опубликованных записей вендора powerdns.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 6
- С записью об исправлении
- 99,1 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-20 Improper Input Validation15
- CWE-770 Allocation of Resources Without Limits or Throttling10
- CWE-400 Uncontrolled Resource Consumption9
- CWE-399 Resource Management Errors7
- CWE-476 NULL Pointer Dereference4
- CWE-125 Out-of-bounds Read4
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
108 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
60На этой неделе | CVE-2023-50387Proof of concept | Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of serredhat · enterprise linux · CWE-770 | Высокая7,5 | — | 100,0 % | 14 февр. 2024 г. |
56В плане | CVE-2015-1868Эксплойта нет | The label decompression functionality in PowerDNS Recursor 3.5.x, 3.6.x before 3.6.3, and 3.7.x before 3.7.2 and Authoritative (Auth) Serverpowerdns · authoritative · CWE-399 | Высокая7,8 | — | 81,7 % | 18 мая 2015 г. |
52В плане | CVE-2023-50868Proof of concept | The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a dennetapp · hci baseboard management controller · CWE-400 | Высокая7,5 | — | 73,7 % | 14 февр. 2024 г. |
49В плане | CVE-2021-36754Proof of concept | PowerDNS Authoritative Server 4.5.0 before 4.5.1 allows anybody to crash the process by sending a specific query (QTYPE 65535) that causes apowerdns · authoritative server · CWE-119 | Высокая7,5 | — | 64,9 % | 30 июл. 2021 г. |
49В плане | CVE-2016-5427Эксплойта нет | PowerDNS (aka pdns) Authoritative Server before 3.4.10 does not properly handle a .powerdns · authoritative · CWE-399 | Высокая7,5 | — | 63,0 % | 21 сент. 2016 г. |
48В плане | CVE-2018-16855Эксплойта нет | An issue has been found in PowerDNS Recursor before version 4.1.8 where a remote attacker sending a DNS query can trigger an out-of-bounds mpowerdns · recursor · CWE-125 | Высокая7,5 | — | 58,6 % | 3 дек. 2018 г. |
46В плане | CVE-2017-15120Proof of concept | An issue has been found in the parsing of authoritative answers in PowerDNS Recursor before 4.0.8, leading to a NULL pointer dereference whepowerdns · recursor · CWE-476 | Высокая7,5 | — | 51,8 % | 27 июл. 2018 г. |
45В плане | CVE-2009-4009Эксплойта нет | Buffer overflow in PowerDNS Recursor before 3.1.7.2 allows remote attackers to cause a denial of service (daemon crash) or possibly execute powerdns · recursor · CWE-119 | Критическая10,0 | — | 17,6 % | 8 янв. 2010 г. |
42В плане | CVE-2020-10030Эксплойта нет | An issue has been found in PowerDNS Recursor 4.1.0 up to and including 4.3.0.powerdns · recursor · CWE-125 | Высокая8,8 | — | 23,9 % | 19 мая 2020 г. |
41В плане | CVE-2014-8601Эксплойта нет | PowerDNS Recursor before 3.6.2 does not limit delegation chaining, which allows remote attackers to cause a denial of service ("performance powerdns · recursor · CWE-399 | Средняя5,0 | — | 68,9 % | 10 дек. 2014 г. |
40В плане | CVE-2015-5311Эксплойта нет | PowerDNS (aka pdns) Authoritative Server 3.4.4 before 3.4.7 allows remote attackers to cause a denial of service (assertion failure and servpowerdns · authoritative · CWE-20 | Средняя5,0 | — | 67,5 % | 17 нояб. 2015 г. |
40В плане | CVE-2020-24698Эксплойта нет | An issue was discovered in PowerDNS Authoritative through 4.3.0 when --enable-experimental-gss-tsig is used.powerdns · authoritative · CWE-415 | Критическая9,8 | — | 3,2 % | 2 окт. 2020 г. |
39Наблюдать | CVE-2016-5426Эксплойта нет | PowerDNS (aka pdns) Authoritative Server before 3.4.10 allows remote attackers to cause a denial of service (backend CPU consumption) via a powerdns · authoritative · CWE-399 | Высокая7,5 | — | 30,6 % | 21 сент. 2016 г. |
39Наблюдать | CVE-2019-3871Эксплойта нет | A vulnerability was found in PowerDNS Authoritative Server before 4.0.7 and before 4.1.7.powerdns · authoritative server · CWE-20 | Высокая8,8 | — | 12,6 % | 21 мар. 2019 г. |
39Наблюдать | CVE-2026-33608Эксплойта нет | Incomplete domain name sanitization duringpowerdns · authoritative · CWE-94 | Критическая9,8 | — | 0,6 % | 22 апр. 2026 г. |
39Наблюдать | CVE-2019-3807Эксплойта нет | An issue has been found in PowerDNS Recursor versions 4.1.x before 4.1.9 where records in the answer section of responses received from authpowerdns · recursor · CWE-345 | Критическая9,8 | — | 0,4 % | 29 янв. 2019 г. |
37Наблюдать | CVE-2026-33598Эксплойта нет | Out-of-bounds read in cache inspection via Luapowerdns · dnsdist · CWE-125 | Критическая9,1 | — | 2,8 % | 22 апр. 2026 г. |
35Наблюдать | CVE-2017-7557Эксплойта нет | dnsdist version 1.1.0 is vulnerable to a flaw in authentication mechanism for REST API potentially allowing CSRF attack.powerdns · dnsdist · CWE-287 | Высокая8,8 | — | 0,8 % | 22 авг. 2017 г. |
34Наблюдать | CVE-2015-5470Эксплойта нет | The label decompression functionality in PowerDNS Recursor before 3.6.4 and 3.7.x before 3.7.3 and Authoritative (Auth) Server before 3.3.3 powerdns · authoritative · CWE-399 | Высокая7,8 | — | 11,3 % | 2 нояб. 2015 г. |
34Наблюдать | CVE-2026-42000Эксплойта нет | Insufficient Validation of Names During AXFRpowerdns · authoritative · CWE-77 | Высокая8,6 | — | 0,5 % | 21 мая 2026 г. |
33Наблюдать | CVE-2009-4010Эксплойта нет | Unspecified vulnerability in PowerDNS Recursor before 3.1.7.2 allows remote attackers to spoof DNS data via crafted zones.powerdns · recursor | Высокая7,5 | — | 10,3 % | 8 янв. 2010 г. |
33Наблюдать | CVE-2015-5230Эксплойта нет | The DNS packet parsing/generation code in PowerDNS (aka pdns) Authoritative Server 3.4.x before 3.4.6 allows remote attackers to cause a denpowerdns · authoritative · CWE-20 | Высокая7,5 | — | 9,0 % | 15 янв. 2020 г. |
33Наблюдать | CVE-2006-4251Эксплойта нет | Buffer overflow in PowerDNS Recursor 3.1.3 and earlier might allow remote attackers to execute arbitrary code via a malformed TCP DNS query powerdns · recursor | Высокая7,5 | — | 8,5 % | 14 нояб. 2006 г. |
32Наблюдать | CVE-2023-22617Эксплойта нет | A remote attacker might be able to cause infinite recursion in PowerDNS Recursor 4.8.0 via a DNS query that retrieves DS records for a miscopowerdns · recursor · CWE-674 | Высокая7,5 | — | 7,3 % | 21 янв. 2023 г. |
32Наблюдать | CVE-2016-7068Эксплойта нет | An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 3.7.4 and 4.0.4, allowing a remote, unauthenticatepowerdns · authoritative · CWE-20 | Высокая7,5 | — | 7,3 % | 11 сент. 2018 г. |
- CVE-2023-5038760На этой неделе
Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of ser
ВысокаяCVSS 7,5Proof of conceptEPSS 100 %redhat · enterprise linux14 февр. 2024 г.
- CVE-2015-186856В плане
The label decompression functionality in PowerDNS Recursor 3.5.x, 3.6.x before 3.6.3, and 3.7.x before 3.7.2 and Authoritative (Auth) Server
ВысокаяCVSS 7,8Эксплойта нетEPSS 82 %powerdns · authoritative18 мая 2015 г.
- CVE-2023-5086852В плане
The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a den
ВысокаяCVSS 7,5Proof of conceptEPSS 74 %netapp · hci baseboard management controller14 февр. 2024 г.
- CVE-2021-3675449В плане
PowerDNS Authoritative Server 4.5.0 before 4.5.1 allows anybody to crash the process by sending a specific query (QTYPE 65535) that causes a
ВысокаяCVSS 7,5Proof of conceptEPSS 65 %powerdns · authoritative server30 июл. 2021 г.
- CVE-2016-542749В плане
PowerDNS (aka pdns) Authoritative Server before 3.4.10 does not properly handle a .
ВысокаяCVSS 7,5Эксплойта нетEPSS 63 %powerdns · authoritative21 сент. 2016 г.
- CVE-2018-1685548В плане
An issue has been found in PowerDNS Recursor before version 4.1.8 where a remote attacker sending a DNS query can trigger an out-of-bounds m
ВысокаяCVSS 7,5Эксплойта нетEPSS 59 %powerdns · recursor3 дек. 2018 г.
- CVE-2017-1512046В плане
An issue has been found in the parsing of authoritative answers in PowerDNS Recursor before 4.0.8, leading to a NULL pointer dereference whe
ВысокаяCVSS 7,5Proof of conceptEPSS 52 %powerdns · recursor27 июл. 2018 г.
- CVE-2009-400945В плане
Buffer overflow in PowerDNS Recursor before 3.1.7.2 allows remote attackers to cause a denial of service (daemon crash) or possibly execute
КритическаяCVSS 10,0Эксплойта нетEPSS 18 %powerdns · recursor8 янв. 2010 г.
- CVE-2020-1003042В плане
An issue has been found in PowerDNS Recursor 4.1.0 up to and including 4.3.0.
ВысокаяCVSS 8,8Эксплойта нетEPSS 24 %powerdns · recursor19 мая 2020 г.
- CVE-2014-860141В плане
PowerDNS Recursor before 3.6.2 does not limit delegation chaining, which allows remote attackers to cause a denial of service ("performance
СредняяCVSS 5,0Эксплойта нетEPSS 69 %powerdns · recursor10 дек. 2014 г.
- CVE-2015-531140В плане
PowerDNS (aka pdns) Authoritative Server 3.4.4 before 3.4.7 allows remote attackers to cause a denial of service (assertion failure and serv
СредняяCVSS 5,0Эксплойта нетEPSS 67 %powerdns · authoritative17 нояб. 2015 г.
- CVE-2020-2469840В плане
An issue was discovered in PowerDNS Authoritative through 4.3.0 when --enable-experimental-gss-tsig is used.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %powerdns · authoritative2 окт. 2020 г.
- CVE-2016-542639Наблюдать
PowerDNS (aka pdns) Authoritative Server before 3.4.10 allows remote attackers to cause a denial of service (backend CPU consumption) via a
ВысокаяCVSS 7,5Эксплойта нетEPSS 31 %powerdns · authoritative21 сент. 2016 г.
- CVE-2019-387139Наблюдать
A vulnerability was found in PowerDNS Authoritative Server before 4.0.7 and before 4.1.7.
ВысокаяCVSS 8,8Эксплойта нетEPSS 13 %powerdns · authoritative server21 мар. 2019 г.
- CVE-2026-3360839Наблюдать
Incomplete domain name sanitization during
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %powerdns · authoritative22 апр. 2026 г.
- CVE-2019-380739Наблюдать
An issue has been found in PowerDNS Recursor versions 4.1.x before 4.1.9 where records in the answer section of responses received from auth
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %powerdns · recursor29 янв. 2019 г.
- CVE-2026-3359837Наблюдать
Out-of-bounds read in cache inspection via Lua
КритическаяCVSS 9,1Эксплойта нетEPSS 3 %powerdns · dnsdist22 апр. 2026 г.
- CVE-2017-755735Наблюдать
dnsdist version 1.1.0 is vulnerable to a flaw in authentication mechanism for REST API potentially allowing CSRF attack.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %powerdns · dnsdist22 авг. 2017 г.
- CVE-2015-547034Наблюдать
The label decompression functionality in PowerDNS Recursor before 3.6.4 and 3.7.x before 3.7.3 and Authoritative (Auth) Server before 3.3.3
ВысокаяCVSS 7,8Эксплойта нетEPSS 11 %powerdns · authoritative2 нояб. 2015 г.
- CVE-2026-4200034Наблюдать
Insufficient Validation of Names During AXFR
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %powerdns · authoritative21 мая 2026 г.
- CVE-2009-401033Наблюдать
Unspecified vulnerability in PowerDNS Recursor before 3.1.7.2 allows remote attackers to spoof DNS data via crafted zones.
ВысокаяCVSS 7,5Эксплойта нетEPSS 10 %powerdns · recursor8 янв. 2010 г.
- CVE-2015-523033Наблюдать
The DNS packet parsing/generation code in PowerDNS (aka pdns) Authoritative Server 3.4.x before 3.4.6 allows remote attackers to cause a den
ВысокаяCVSS 7,5Эксплойта нетEPSS 9 %powerdns · authoritative15 янв. 2020 г.
- CVE-2006-425133Наблюдать
Buffer overflow in PowerDNS Recursor 3.1.3 and earlier might allow remote attackers to execute arbitrary code via a malformed TCP DNS query
ВысокаяCVSS 7,5Эксплойта нетEPSS 8 %powerdns · recursor14 нояб. 2006 г.
- CVE-2023-2261732Наблюдать
A remote attacker might be able to cause infinite recursion in PowerDNS Recursor 4.8.0 via a DNS query that retrieves DS records for a misco
ВысокаяCVSS 7,5Эксплойта нетEPSS 7 %powerdns · recursor21 янв. 2023 г.
- CVE-2016-706832Наблюдать
An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 3.7.4 and 4.0.4, allowing a remote, unauthenticate
ВысокаяCVSS 7,5Эксплойта нетEPSS 7 %powerdns · authoritative11 сент. 2018 г.