Show filters
68 Total Results
Displaying 61-68 of 68
Sort by:
Attacker Value
Unknown
CVE-2008-1637
Disclosure Date: April 02, 2008 (last updated October 04, 2023)
PowerDNS Recursor before 3.1.5 uses insufficient randomness to calculate (1) TRXID values and (2) UDP source port numbers, which makes it easier for remote attackers to poison a DNS cache, related to (a) algorithmic deficiencies in rand and random functions in external libraries, (b) use of a 32-bit seed value, and (c) choice of the time of day as the sole seeding information.
0
Attacker Value
Unknown
CVE-2006-4252
Disclosure Date: November 14, 2006 (last updated October 04, 2023)
PowerDNS Recursor 3.1.3 and earlier allows remote attackers to cause a denial of service (resource exhaustion and application crash) via a CNAME record with a zero TTL, which triggers an infinite loop.
0
Attacker Value
Unknown
CVE-2006-4251
Disclosure Date: November 14, 2006 (last updated October 04, 2023)
Buffer overflow in PowerDNS Recursor 3.1.3 and earlier might allow remote attackers to execute arbitrary code via a malformed TCP DNS query that prevents Recursor from properly calculating the TCP DNS query length.
0
Attacker Value
Unknown
CVE-2006-2069
Disclosure Date: April 27, 2006 (last updated October 04, 2023)
The recursor in PowerDNS before 3.0.1 allows remote attackers to cause a denial of service (application crash) via malformed EDNS0 packets.
0
Attacker Value
Unknown
CVE-2005-0038
Disclosure Date: December 31, 2005 (last updated February 22, 2025)
The DNS implementation of PowerDNS 2.9.16 and earlier allows remote attackers to cause a denial of service via a compressed DNS packet with a label length byte with an incorrect offset, which could trigger an infinite loop.
0
Attacker Value
Unknown
CVE-2005-2302
Disclosure Date: July 19, 2005 (last updated February 22, 2025)
PowerDNS before 2.9.18, when allowing recursion to a restricted range of IP addresses, does not properly handle questions from clients that are denied recursion, which could cause a "blank out" of answers to those clients that are allowed to use recursion.
0
Attacker Value
Unknown
CVE-2005-2301
Disclosure Date: July 19, 2005 (last updated February 22, 2025)
PowerDNS before 2.9.18, when running with an LDAP backend, does not properly escape LDAP queries, which allows remote attackers to cause a denial of service (failure to answer ldap questions) and possibly conduct an LDAP injection attack.
0
Attacker Value
Unknown
CVE-2005-0428
Disclosure Date: May 02, 2005 (last updated February 22, 2025)
The DNSPacket::expand method in dnspacket.cc in PowerDNS before 2.9.17 allows remote attackers to cause a denial of service by sending a random stream of bytes.
0