powerdns kayıtları
powerdns üreticisine ait 108 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 6
- Düzeltme kaydı olan
- %99,1
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-20 Improper Input Validation15
- CWE-770 Allocation of Resources Without Limits or Throttling10
- CWE-400 Uncontrolled Resource Consumption9
- CWE-399 Resource Management Errors7
- CWE-476 NULL Pointer Dereference4
- CWE-125 Out-of-bounds Read4
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
108 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
60Bu hafta | CVE-2023-50387Kavram kanıtı | Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of serredhat · enterprise linux · CWE-770 | Yüksek7,5 | — | %100,0 | 14 Şub 2024 |
56Planlayın | CVE-2015-1868İstismar yok | The label decompression functionality in PowerDNS Recursor 3.5.x, 3.6.x before 3.6.3, and 3.7.x before 3.7.2 and Authoritative (Auth) Serverpowerdns · authoritative · CWE-399 | Yüksek7,8 | — | %81,7 | 18 May 2015 |
55Planlayın | CVE-2023-50868Kavram kanıtı | The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a dennetapp · hci baseboard management controller · CWE-400 | Yüksek7,5 | — | %81,7 | 14 Şub 2024 |
49Planlayın | CVE-2021-36754Kavram kanıtı | PowerDNS Authoritative Server 4.5.0 before 4.5.1 allows anybody to crash the process by sending a specific query (QTYPE 65535) that causes apowerdns · authoritative server · CWE-119 | Yüksek7,5 | — | %64,9 | 30 Tem 2021 |
49Planlayın | CVE-2016-5427İstismar yok | PowerDNS (aka pdns) Authoritative Server before 3.4.10 does not properly handle a .powerdns · authoritative · CWE-399 | Yüksek7,5 | — | %63,0 | 21 Eyl 2016 |
48Planlayın | CVE-2018-16855İstismar yok | An issue has been found in PowerDNS Recursor before version 4.1.8 where a remote attacker sending a DNS query can trigger an out-of-bounds mpowerdns · recursor · CWE-125 | Yüksek7,5 | — | %58,6 | 3 Ara 2018 |
46Planlayın | CVE-2017-15120Kavram kanıtı | An issue has been found in the parsing of authoritative answers in PowerDNS Recursor before 4.0.8, leading to a NULL pointer dereference whepowerdns · recursor · CWE-476 | Yüksek7,5 | — | %51,8 | 27 Tem 2018 |
45Planlayın | CVE-2009-4009İstismar yok | Buffer overflow in PowerDNS Recursor before 3.1.7.2 allows remote attackers to cause a denial of service (daemon crash) or possibly execute powerdns · recursor · CWE-119 | Kritik10,0 | — | %17,6 | 8 Oca 2010 |
42Planlayın | CVE-2020-10030İstismar yok | An issue has been found in PowerDNS Recursor 4.1.0 up to and including 4.3.0.powerdns · recursor · CWE-125 | Yüksek8,8 | — | %23,9 | 19 May 2020 |
41Planlayın | CVE-2014-8601İstismar yok | PowerDNS Recursor before 3.6.2 does not limit delegation chaining, which allows remote attackers to cause a denial of service ("performance powerdns · recursor · CWE-399 | Orta5,0 | — | %68,9 | 10 Ara 2014 |
40Planlayın | CVE-2015-5311İstismar yok | PowerDNS (aka pdns) Authoritative Server 3.4.4 before 3.4.7 allows remote attackers to cause a denial of service (assertion failure and servpowerdns · authoritative · CWE-20 | Orta5,0 | — | %67,5 | 17 Kas 2015 |
40Planlayın | CVE-2020-24698İstismar yok | An issue was discovered in PowerDNS Authoritative through 4.3.0 when --enable-experimental-gss-tsig is used.powerdns · authoritative · CWE-415 | Kritik9,8 | — | %3,2 | 2 Eki 2020 |
39İzleyin | CVE-2016-5426İstismar yok | PowerDNS (aka pdns) Authoritative Server before 3.4.10 allows remote attackers to cause a denial of service (backend CPU consumption) via a powerdns · authoritative · CWE-399 | Yüksek7,5 | — | %30,6 | 21 Eyl 2016 |
39İzleyin | CVE-2019-3871İstismar yok | A vulnerability was found in PowerDNS Authoritative Server before 4.0.7 and before 4.1.7.powerdns · authoritative server · CWE-20 | Yüksek8,8 | — | %12,6 | 21 Mar 2019 |
39İzleyin | CVE-2026-33608İstismar yok | Incomplete domain name sanitization duringpowerdns · authoritative · CWE-94 | Kritik9,8 | — | %0,6 | 22 Nis 2026 |
39İzleyin | CVE-2019-3807İstismar yok | An issue has been found in PowerDNS Recursor versions 4.1.x before 4.1.9 where records in the answer section of responses received from authpowerdns · recursor · CWE-345 | Kritik9,8 | — | %0,4 | 29 Oca 2019 |
37İzleyin | CVE-2026-33598İstismar yok | Out-of-bounds read in cache inspection via Luapowerdns · dnsdist · CWE-125 | Kritik9,1 | — | %2,8 | 22 Nis 2026 |
35İzleyin | CVE-2017-7557İstismar yok | dnsdist version 1.1.0 is vulnerable to a flaw in authentication mechanism for REST API potentially allowing CSRF attack.powerdns · dnsdist · CWE-287 | Yüksek8,8 | — | %0,8 | 22 Ağu 2017 |
34İzleyin | CVE-2015-5470İstismar yok | The label decompression functionality in PowerDNS Recursor before 3.6.4 and 3.7.x before 3.7.3 and Authoritative (Auth) Server before 3.3.3 powerdns · authoritative · CWE-399 | Yüksek7,8 | — | %11,3 | 2 Kas 2015 |
34İzleyin | CVE-2026-42000İstismar yok | Insufficient Validation of Names During AXFRpowerdns · authoritative · CWE-77 | Yüksek8,6 | — | %0,5 | 21 May 2026 |
33İzleyin | CVE-2009-4010İstismar yok | Unspecified vulnerability in PowerDNS Recursor before 3.1.7.2 allows remote attackers to spoof DNS data via crafted zones.powerdns · recursor | Yüksek7,5 | — | %10,3 | 8 Oca 2010 |
33İzleyin | CVE-2015-5230İstismar yok | The DNS packet parsing/generation code in PowerDNS (aka pdns) Authoritative Server 3.4.x before 3.4.6 allows remote attackers to cause a denpowerdns · authoritative · CWE-20 | Yüksek7,5 | — | %9,0 | 15 Oca 2020 |
33İzleyin | CVE-2006-4251İstismar yok | Buffer overflow in PowerDNS Recursor 3.1.3 and earlier might allow remote attackers to execute arbitrary code via a malformed TCP DNS query powerdns · recursor | Yüksek7,5 | — | %8,5 | 14 Kas 2006 |
32İzleyin | CVE-2023-22617İstismar yok | A remote attacker might be able to cause infinite recursion in PowerDNS Recursor 4.8.0 via a DNS query that retrieves DS records for a miscopowerdns · recursor · CWE-674 | Yüksek7,5 | — | %7,3 | 21 Oca 2023 |
32İzleyin | CVE-2016-7068İstismar yok | An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 3.7.4 and 4.0.4, allowing a remote, unauthenticatepowerdns · authoritative · CWE-20 | Yüksek7,5 | — | %7,3 | 11 Eyl 2018 |
- CVE-2023-5038760Bu hafta
Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of ser
YüksekCVSS 7,5Kavram kanıtıEPSS %100redhat · enterprise linux14 Şub 2024
- CVE-2015-186856Planlayın
The label decompression functionality in PowerDNS Recursor 3.5.x, 3.6.x before 3.6.3, and 3.7.x before 3.7.2 and Authoritative (Auth) Server
YüksekCVSS 7,8İstismar yokEPSS %82powerdns · authoritative18 May 2015
- CVE-2023-5086855Planlayın
The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a den
YüksekCVSS 7,5Kavram kanıtıEPSS %82netapp · hci baseboard management controller14 Şub 2024
- CVE-2021-3675449Planlayın
PowerDNS Authoritative Server 4.5.0 before 4.5.1 allows anybody to crash the process by sending a specific query (QTYPE 65535) that causes a
YüksekCVSS 7,5Kavram kanıtıEPSS %65powerdns · authoritative server30 Tem 2021
- CVE-2016-542749Planlayın
PowerDNS (aka pdns) Authoritative Server before 3.4.10 does not properly handle a .
YüksekCVSS 7,5İstismar yokEPSS %63powerdns · authoritative21 Eyl 2016
- CVE-2018-1685548Planlayın
An issue has been found in PowerDNS Recursor before version 4.1.8 where a remote attacker sending a DNS query can trigger an out-of-bounds m
YüksekCVSS 7,5İstismar yokEPSS %59powerdns · recursor3 Ara 2018
- CVE-2017-1512046Planlayın
An issue has been found in the parsing of authoritative answers in PowerDNS Recursor before 4.0.8, leading to a NULL pointer dereference whe
YüksekCVSS 7,5Kavram kanıtıEPSS %52powerdns · recursor27 Tem 2018
- CVE-2009-400945Planlayın
Buffer overflow in PowerDNS Recursor before 3.1.7.2 allows remote attackers to cause a denial of service (daemon crash) or possibly execute
KritikCVSS 10,0İstismar yokEPSS %18powerdns · recursor8 Oca 2010
- CVE-2020-1003042Planlayın
An issue has been found in PowerDNS Recursor 4.1.0 up to and including 4.3.0.
YüksekCVSS 8,8İstismar yokEPSS %24powerdns · recursor19 May 2020
- CVE-2014-860141Planlayın
PowerDNS Recursor before 3.6.2 does not limit delegation chaining, which allows remote attackers to cause a denial of service ("performance
OrtaCVSS 5,0İstismar yokEPSS %69powerdns · recursor10 Ara 2014
- CVE-2015-531140Planlayın
PowerDNS (aka pdns) Authoritative Server 3.4.4 before 3.4.7 allows remote attackers to cause a denial of service (assertion failure and serv
OrtaCVSS 5,0İstismar yokEPSS %67powerdns · authoritative17 Kas 2015
- CVE-2020-2469840Planlayın
An issue was discovered in PowerDNS Authoritative through 4.3.0 when --enable-experimental-gss-tsig is used.
KritikCVSS 9,8İstismar yokEPSS %3powerdns · authoritative2 Eki 2020
- CVE-2016-542639İzleyin
PowerDNS (aka pdns) Authoritative Server before 3.4.10 allows remote attackers to cause a denial of service (backend CPU consumption) via a
YüksekCVSS 7,5İstismar yokEPSS %31powerdns · authoritative21 Eyl 2016
- CVE-2019-387139İzleyin
A vulnerability was found in PowerDNS Authoritative Server before 4.0.7 and before 4.1.7.
YüksekCVSS 8,8İstismar yokEPSS %13powerdns · authoritative server21 Mar 2019
- CVE-2026-3360839İzleyin
Incomplete domain name sanitization during
KritikCVSS 9,8İstismar yokEPSS %1powerdns · authoritative22 Nis 2026
- CVE-2019-380739İzleyin
An issue has been found in PowerDNS Recursor versions 4.1.x before 4.1.9 where records in the answer section of responses received from auth
KritikCVSS 9,8İstismar yokEPSS %0powerdns · recursor29 Oca 2019
- CVE-2026-3359837İzleyin
Out-of-bounds read in cache inspection via Lua
KritikCVSS 9,1İstismar yokEPSS %3powerdns · dnsdist22 Nis 2026
- CVE-2017-755735İzleyin
dnsdist version 1.1.0 is vulnerable to a flaw in authentication mechanism for REST API potentially allowing CSRF attack.
YüksekCVSS 8,8İstismar yokEPSS %1powerdns · dnsdist22 Ağu 2017
- CVE-2015-547034İzleyin
The label decompression functionality in PowerDNS Recursor before 3.6.4 and 3.7.x before 3.7.3 and Authoritative (Auth) Server before 3.3.3
YüksekCVSS 7,8İstismar yokEPSS %11powerdns · authoritative2 Kas 2015
- CVE-2026-4200034İzleyin
Insufficient Validation of Names During AXFR
YüksekCVSS 8,6İstismar yokEPSS %1powerdns · authoritative21 May 2026
- CVE-2009-401033İzleyin
Unspecified vulnerability in PowerDNS Recursor before 3.1.7.2 allows remote attackers to spoof DNS data via crafted zones.
YüksekCVSS 7,5İstismar yokEPSS %10powerdns · recursor8 Oca 2010
- CVE-2015-523033İzleyin
The DNS packet parsing/generation code in PowerDNS (aka pdns) Authoritative Server 3.4.x before 3.4.6 allows remote attackers to cause a den
YüksekCVSS 7,5İstismar yokEPSS %9powerdns · authoritative15 Oca 2020
- CVE-2006-425133İzleyin
Buffer overflow in PowerDNS Recursor 3.1.3 and earlier might allow remote attackers to execute arbitrary code via a malformed TCP DNS query
YüksekCVSS 7,5İstismar yokEPSS %8powerdns · recursor14 Kas 2006
- CVE-2023-2261732İzleyin
A remote attacker might be able to cause infinite recursion in PowerDNS Recursor 4.8.0 via a DNS query that retrieves DS records for a misco
YüksekCVSS 7,5İstismar yokEPSS %7powerdns · recursor21 Oca 2023
- CVE-2016-706832İzleyin
An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 3.7.4 and 4.0.4, allowing a remote, unauthenticate
YüksekCVSS 7,5İstismar yokEPSS %7powerdns · authoritative11 Eyl 2018