CVEs (7)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Fedoraproject Powerdns3Authoritative Server FedoraRecursorJun 17, 2026 Mar 25, 2022 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 In PowerDNS Authoritative Server before 4.4.3, 4.5.x before 4.5.4, and 4.6.x before 4.6.1 and PowerDNS Recursor before 4.4.8, 4.5.x before 4.5.8, and 4.6.x before 4.6.1, insufficient validation of an IXFR end condition c...Show more |
1Powerdns 1Authoritative Server Jun 17, 2026 Jul 30, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 PowerDNS Authoritative Server 4.5.0 before 4.5.1 allows anybody to crash the process by sending a specific query (QTYPE 65535) that causes an out-of-bounds exception. |
1Powerdns 1Authoritative Server Jun 17, 2026 Nov 22, 2019 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 PowerDNS Authoritative daemon , pdns versions 4.0.x before 4.0.9, 4.1.x before 4.1.11, exiting when encountering a serial between 2^31 and 2^32-1 while trying to notify a slave leads to DoS. |
2Fedoraproject Powerdns2Authoritative Server FedoraJun 17, 2026 Mar 21, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A vulnerability was found in PowerDNS Authoritative Server before 4.0.7 and before 4.1.7. An insufficient validation of data coming from the user when building a HTTP request from a DNS query in the HTTP Connector of the...Show more |
2Opensuse Powerdns3Authoritative Server LeapOpensuseMay 6, 2026 Sep 26, 2016 N/A· v4 6.8 MEDIUM· v3 7.1 HIGH· v2 PowerDNS (aka pdns) Authoritative Server before 4.0.1 allows remote primary DNS servers to cause a denial of service (memory exhaustion and secondary DNS server crash) via a large (1) AXFR or (2) IXFR response. |
common_startup.cc in PowerDNS (aka pdns) Authoritative Server before 2.9.22.5 and 3.x before 3.0.1 allows remote attackers to cause a denial of service (packet loop) via a crafted UDP DNS response. |
1Powerdns 2Authoritative Server PowerdnsApr 23, 2026 Aug 8, 2008 N/A· v4 N/A· v3 6.4 MEDIUM· v2 PowerDNS Authoritative Server before 2.9.21.1 drops malformed queries, which might make it easier for remote attackers to poison DNS caches of other products running on other servers, a different issue than CVE-2008-1447...Show more |