Show filters
68 Total Results
Displaying 41-50 of 68
Sort by:
Attacker Value
Unknown
CVE-2017-15092
Disclosure Date: January 23, 2018 (last updated November 26, 2024)
A cross-site scripting issue has been found in the web interface of PowerDNS Recursor from 4.0.0 up to and including 4.0.6, where the qname of DNS queries was displayed without any escaping, allowing a remote attacker to inject HTML and Javascript code into the web interface, altering the content.
0
Attacker Value
Unknown
CVE-2017-15091
Disclosure Date: January 23, 2018 (last updated November 26, 2024)
An issue has been found in the API component of PowerDNS Authoritative 4.x up to and including 4.0.4 and 3.x up to and including 3.4.11, where some operations that have an impact on the state of the server are still allowed even though the API has been configured as read-only via the api-readonly keyword. This missing check allows an attacker with valid API credentials to flush the cache, trigger a zone transfer or send a NOTIFY.
0
Attacker Value
Unknown
CVE-2017-15093
Disclosure Date: January 23, 2018 (last updated November 26, 2024)
When api-config-dir is set to a non-empty value, which is not the case by default, the API in PowerDNS Recursor 4.x up to and including 4.0.6 and 3.x up to and including 3.7.4 allows an authorized user to update the Recursor's ACL by adding and removing netmasks, and to configure forward zones. It was discovered that the new netmask and IP addresses of forwarded zones were not sufficiently validated, allowing an authenticated user to inject new configuration directives into the Recursor's configuration.
0
Attacker Value
Unknown
CVE-2018-1000003
Disclosure Date: January 22, 2018 (last updated November 26, 2024)
Improper input validation bugs in DNSSEC validators components in PowerDNS version 4.1.0 allow attacker in man-in-the-middle position to deny existence of some data in DNS via packet replay.
0
Attacker Value
Unknown
CVE-2017-7557
Disclosure Date: August 22, 2017 (last updated November 26, 2024)
dnsdist version 1.1.0 is vulnerable to a flaw in authentication mechanism for REST API potentially allowing CSRF attack.
0
Attacker Value
Unknown
CVE-2016-6172
Disclosure Date: September 26, 2016 (last updated November 25, 2024)
PowerDNS (aka pdns) Authoritative Server before 4.0.1 allows remote primary DNS servers to cause a denial of service (memory exhaustion and secondary DNS server crash) via a large (1) AXFR or (2) IXFR response.
0
Attacker Value
Unknown
CVE-2016-5426
Disclosure Date: September 21, 2016 (last updated November 25, 2024)
PowerDNS (aka pdns) Authoritative Server before 3.4.10 allows remote attackers to cause a denial of service (backend CPU consumption) via a long qname.
0
Attacker Value
Unknown
CVE-2016-5427
Disclosure Date: September 21, 2016 (last updated November 25, 2024)
PowerDNS (aka pdns) Authoritative Server before 3.4.10 does not properly handle a . (dot) inside labels, which allows remote attackers to cause a denial of service (backend CPU consumption) via a crafted DNS query.
0
Attacker Value
Unknown
CVE-2015-5311
Disclosure Date: November 17, 2015 (last updated October 05, 2023)
PowerDNS (aka pdns) Authoritative Server 3.4.4 before 3.4.7 allows remote attackers to cause a denial of service (assertion failure and server crash) via crafted query packets.
0
Attacker Value
Unknown
CVE-2015-5470
Disclosure Date: November 02, 2015 (last updated October 05, 2023)
The label decompression functionality in PowerDNS Recursor before 3.6.4 and 3.7.x before 3.7.3 and Authoritative (Auth) Server before 3.3.3 and 3.4.x before 3.4.5 allows remote attackers to cause a denial of service (CPU consumption or crash) via a request with a long name that refers to itself. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-1868.
0