Show filters
68 Total Results
Displaying 1-10 of 68
Sort by:
Attacker Value
Very Low

CVE-2020-17482

Disclosure Date: October 02, 2020 (last updated February 22, 2025)
An issue has been found in PowerDNS Authoritative Server before 4.3.1 where an authorized user with the ability to insert crafted records into a zone might be able to leak the content of uninitialized memory.
Attacker Value
Unknown

CVE-2023-50387

Disclosure Date: February 14, 2024 (last updated February 21, 2024)
Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the "KeyTrap" issue. One of the concerns is that, when there is a zone with many DNSKEY and RRSIG records, the protocol specification implies that an algorithm must evaluate all combinations of DNSKEY and RRSIG records.
Attacker Value
Unknown

CVE-2024-25590

Disclosure Date: October 03, 2024 (last updated October 04, 2024)
An attacker can publish a zone containing specific Resource Record Sets. Repeatedly processing and caching results for these sets can lead to a denial of service.
0
Attacker Value
Unknown

CVE-2024-25581

Disclosure Date: May 14, 2024 (last updated February 14, 2025)
When incoming DNS over HTTPS support is enabled using the nghttp2 provider, and queries are routed to a tcp-only or DNS over TLS backend, an attacker can trigger an assertion failure in DNSdist by sending a request for a zone transfer (AXFR or IXFR) over DNS over HTTPS, causing the process to stop and thus leading to a Denial of Service. DNS over HTTPS is not enabled by default, and backends are using plain DNS (Do53) by default.
0
Attacker Value
Unknown

CVE-2024-25583

Disclosure Date: April 25, 2024 (last updated February 14, 2025)
A crafted response from an upstream server the recursor has been configured to forward-recurse to can cause a Denial of Service in the Recursor. The default configuration of the Recursor does not use recursive forwarding and is not affected.
0
Attacker Value
Unknown

CVE-2023-26437

Disclosure Date: April 04, 2023 (last updated February 14, 2025)
Denial of service vulnerability in PowerDNS Recursor allows authoritative servers to be marked unavailable.This issue affects Recursor: through 4.6.5, through 4.7.4 , through 4.8.3.
Attacker Value
Unknown

CVE-2023-22617

Disclosure Date: January 21, 2023 (last updated October 08, 2023)
A remote attacker might be able to cause infinite recursion in PowerDNS Recursor 4.8.0 via a DNS query that retrieves DS records for a misconfigured domain, because QName minimization is used in QM fallback mode. This is fixed in 4.8.1.
Attacker Value
Unknown

CVE-2022-37428

Disclosure Date: August 23, 2022 (last updated November 08, 2023)
PowerDNS Recursor up to and including 4.5.9, 4.6.2 and 4.7.1, when protobuf logging is enabled, has Improper Cleanup upon a Thrown Exception, leading to a denial of service (daemon crash) via a DNS query that leads to an answer with specific properties.
Attacker Value
Unknown

CVE-2022-27227

Disclosure Date: March 25, 2022 (last updated October 07, 2023)
In PowerDNS Authoritative Server before 4.4.3, 4.5.x before 4.5.4, and 4.6.x before 4.6.1 and PowerDNS Recursor before 4.4.8, 4.5.x before 4.5.8, and 4.6.x before 4.6.1, insufficient validation of an IXFR end condition causes incomplete zone transfers to be handled as successful transfers.
Attacker Value
Unknown

CVE-2021-36754

Disclosure Date: July 30, 2021 (last updated November 28, 2024)
PowerDNS Authoritative Server 4.5.0 before 4.5.1 allows anybody to crash the process by sending a specific query (QTYPE 65535) that causes an out-of-bounds exception.