← Back

Powerdns

powerdns

106 CVEs • 7 products

Products (7)

Click to collapse
Toggle
Recursor
recursor
Authoritative
authoritative
Dnsdist
dnsdist
Powerdns
powerdns
Pdns
pdns

CVEs (106)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Powerdns
1Recursor
Nov 21, 2024
Jan 23, 2018
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
An issue has been found in the DNSSEC validation component of PowerDNS Recursor from 4.0.0 and up to and including 4.0.6, where the signatures might have been accepted as valid even if the signed data was not in bailiwic...Show more
An issue has been found in the DNSSEC validation component of PowerDNS Recursor from 4.0.0 and up to and including 4.0.6, where the signatures might have been accepted as valid even if the signed data was not in bailiwick of the DNSKEY used to sign it. This allows an attacker in position of man-in-the-middle to alter the content of records by issuing a valid signature for the crafted records.Show less
1Powerdns
1Recursor
Nov 21, 2024
Jan 22, 2018
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
Improper input validation bugs in DNSSEC validators components in PowerDNS version 4.1.0 allow attacker in man-in-the-middle position to deny existence of some data in DNS via packet replay.
1Powerdns
1Dnsdist
May 13, 2026
Aug 22, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
dnsdist version 1.1.0 is vulnerable to a flaw in authentication mechanism for REST API potentially allowing CSRF attack.
2Opensuse
Powerdns
3Authoritative Server
LeapOpensuse
May 6, 2026
Sep 26, 2016
N/A· v4
6.8 MEDIUM· v3
7.1 HIGH· v2
PowerDNS (aka pdns) Authoritative Server before 4.0.1 allows remote primary DNS servers to cause a denial of service (memory exhaustion and secondary DNS server crash) via a large (1) AXFR or (2) IXFR response.
1Powerdns
1Authoritative
May 6, 2026
Sep 21, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
PowerDNS (aka pdns) Authoritative Server before 3.4.10 does not properly handle a . (dot) inside labels, which allows remote attackers to cause a denial of service (backend CPU consumption) via a crafted DNS query.
1Powerdns
1Authoritative
May 6, 2026
Sep 21, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
PowerDNS (aka pdns) Authoritative Server before 3.4.10 allows remote attackers to cause a denial of service (backend CPU consumption) via a long qname.
1Powerdns
1Authoritative
May 6, 2026
Nov 17, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
PowerDNS (aka pdns) Authoritative Server 3.4.4 before 3.4.7 allows remote attackers to cause a denial of service (assertion failure and server crash) via crafted query packets.
1Powerdns
2Authoritative
Recursor
May 6, 2026
Nov 2, 2015
N/A· v4
N/A· v3
7.8 HIGH· v2
The label decompression functionality in PowerDNS Recursor before 3.6.4 and 3.7.x before 3.7.3 and Authoritative (Auth) Server before 3.3.3 and 3.4.x before 3.4.5 allows remote attackers to cause a denial of service (CPU...Show more
The label decompression functionality in PowerDNS Recursor before 3.6.4 and 3.7.x before 3.7.3 and Authoritative (Auth) Server before 3.3.3 and 3.4.x before 3.4.5 allows remote attackers to cause a denial of service (CPU consumption or crash) via a request with a long name that refers to itself. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-1868.Show less
2Fedoraproject
Powerdns
3Authoritative
FedoraRecursor
May 6, 2026
May 18, 2015
N/A· v4
N/A· v3
7.8 HIGH· v2
The label decompression functionality in PowerDNS Recursor 3.5.x, 3.6.x before 3.6.3, and 3.7.x before 3.7.2 and Authoritative (Auth) Server 3.2.x, 3.3.x before 3.3.2, and 3.4.x before 3.4.4 allows remote attackers to ca...Show more
The label decompression functionality in PowerDNS Recursor 3.5.x, 3.6.x before 3.6.3, and 3.7.x before 3.7.2 and Authoritative (Auth) Server 3.2.x, 3.3.x before 3.3.2, and 3.4.x before 3.4.4 allows remote attackers to cause a denial of service (CPU consumption or crash) via a request with a name that refers to itself.Show less
2Debian
Powerdns
2Debian Linux
Recursor
May 6, 2026
Dec 10, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
PowerDNS Recursor before 3.6.2 does not limit delegation chaining, which allows remote attackers to cause a denial of service ("performance degradations") via a large or infinite number of referrals, as demonstrated by r...Show more
PowerDNS Recursor before 3.6.2 does not limit delegation chaining, which allows remote attackers to cause a denial of service ("performance degradations") via a large or infinite number of referrals, as demonstrated by resolving domains hosted by ezdns.it.Show less
1Powerdns
1Powerdns Recursor
May 6, 2026
Sep 19, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Unspecified vulnerability in PowerDNS Recursor (aka pdns_recursor) 3.6.x before 3.6.1 allows remote attackers to cause a denial of service (crash) via an unknown sequence of malformed packets.
1Powerdns
1Powerdns Recursor
Apr 29, 2026
Feb 17, 2012
N/A· v4
N/A· v3
6.4 MEDIUM· v2
The resolver in PowerDNS Recursor (aka pdns_recursor) 3.3 overwrites cached server names and TTL values in NS records during the processing of a response to an A record query, which allows remote attackers to trigger con...Show more
The resolver in PowerDNS Recursor (aka pdns_recursor) 3.3 overwrites cached server names and TTL values in NS records during the processing of a response to an A record query, which allows remote attackers to trigger continued resolvability of revoked domain names via a "ghost domain names" attack.Show less
1Powerdns
1Authoritative Server
Apr 29, 2026
Feb 17, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
common_startup.cc in PowerDNS (aka pdns) Authoritative Server before 2.9.22.5 and 3.x before 3.0.1 allows remote attackers to cause a denial of service (packet loop) via a crafted UDP DNS response.
1Powerdns
1Recursor
Apr 23, 2026
Jan 8, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
Unspecified vulnerability in PowerDNS Recursor before 3.1.7.2 allows remote attackers to spoof DNS data via crafted zones.
1Powerdns
1Recursor
Apr 23, 2026
Jan 8, 2010
N/A· v4
N/A· v3
10.0 HIGH· v2
Buffer overflow in PowerDNS Recursor before 3.1.7.2 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via crafted packets.
1Powerdns
1Powerdns
Apr 23, 2026
Dec 9, 2008
N/A· v4
N/A· v3
4.3 MEDIUM· v2
PowerDNS before 2.9.21.2 allows remote attackers to cause a denial of service (daemon crash) via a CH HINFO query.
1Powerdns
2Authoritative Server
Powerdns
Apr 23, 2026
Aug 8, 2008
N/A· v4
N/A· v3
6.4 MEDIUM· v2
PowerDNS Authoritative Server before 2.9.21.1 drops malformed queries, which might make it easier for remote attackers to poison DNS caches of other products running on other servers, a different issue than CVE-2008-1447...Show more
PowerDNS Authoritative Server before 2.9.21.1 drops malformed queries, which might make it easier for remote attackers to poison DNS caches of other products running on other servers, a different issue than CVE-2008-1447 and CVE-2008-3217.Show less
1Powerdns
1Recursor
Apr 23, 2026
Jul 18, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
PowerDNS Recursor before 3.1.6 does not always use the strongest random number generator for source port selection, which makes it easier for remote attack vectors to conduct DNS cache poisoning. NOTE: this is related t...Show more
PowerDNS Recursor before 3.1.6 does not always use the strongest random number generator for source port selection, which makes it easier for remote attack vectors to conduct DNS cache poisoning. NOTE: this is related to incomplete integration of security improvements associated with addressing CVE-2008-1637.Show less
1Powerdns
1Recursor
Apr 23, 2026
Apr 2, 2008
N/A· v4
N/A· v3
6.8 MEDIUM· v2
PowerDNS Recursor before 3.1.5 uses insufficient randomness to calculate (1) TRXID values and (2) UDP source port numbers, which makes it easier for remote attackers to poison a DNS cache, related to (a) algorithmic defi...Show more
PowerDNS Recursor before 3.1.5 uses insufficient randomness to calculate (1) TRXID values and (2) UDP source port numbers, which makes it easier for remote attackers to poison a DNS cache, related to (a) algorithmic deficiencies in rand and random functions in external libraries, (b) use of a 32-bit seed value, and (c) choice of the time of day as the sole seeding information.Show less
1Powerdns
1Recursor
Apr 23, 2026
Nov 14, 2006
N/A· v4
N/A· v3
5.0 MEDIUM· v2
PowerDNS Recursor 3.1.3 and earlier allows remote attackers to cause a denial of service (resource exhaustion and application crash) via a CNAME record with a zero TTL, which triggers an infinite loop.