Search CVE reports


Toggle filters

61 – 69 of 69 results


CVE-2008-1637

Medium priority

Some fixes available 2 of 5

PowerDNS Recursor before 3.1.5 uses insufficient randomness to calculate (1) TRXID values and (2) UDP source port numbers, which makes it easier for remote attackers to poison a DNS cache, related to (a) algorithmic deficiencies...

1 affected package

pdns-recursor

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pdns-recursor
Show less packages

CVE-2006-4252

Medium priority

Some fixes available 6 of 8

PowerDNS Recursor 3.1.3 and earlier allows remote attackers to cause a denial of service (resource exhaustion and application crash) via a CNAME record with a zero TTL, which triggers an infinite loop.

2 affected packages

pdns, pdns-recursor

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pdns
pdns-recursor
Show less packages

CVE-2006-4251

Medium priority

Some fixes available 6 of 8

Buffer overflow in PowerDNS Recursor 3.1.3 and earlier might allow remote attackers to execute arbitrary code via a malformed TCP DNS query that prevents Recursor from properly calculating the TCP DNS query length.

2 affected packages

pdns, pdns-recursor

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pdns
pdns-recursor
Show less packages

CVE-2006-2077

Medium priority

Some fixes available 7 of 8

Buffer overflow in Paul Rombouts pdnsd before 1.2.4 has unknown impact and attack vectors. NOTE: this issue might be related to the OUSPG PROTOS DNS test suite.

1 affected package

pdnsd

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pdnsd
Show less packages

CVE-2006-2076

Medium priority

Some fixes available 7 of 8

Memory leak in Paul Rombouts pdnsd before 1.2.4 allows remote attackers to cause a denial of service (memory consumption) via a DNS query with an unsupported (1) QTYPE or (2) QCLASS, as demonstrated by the OUSPG PROTOS DNS test suite.

1 affected package

pdnsd

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pdnsd
Show less packages

CVE-2005-2302

Medium priority
Fixed

PowerDNS before 2.9.18, when allowing recursion to a restricted range of IP addresses, does not properly handle questions from clients that are denied recursion, which could cause a "blank out" of answers to those clients that are...

1 affected package

pdns

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pdns
Show less packages

CVE-2005-2301

Medium priority
Fixed

PowerDNS before 2.9.18, when running with an LDAP backend, does not properly escape LDAP queries, which allows remote attackers to cause a denial of service (failure to answer ldap questions) and possibly conduct an LDAP injection attack.

1 affected package

pdns

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pdns
Show less packages

CVE-2005-0428

Medium priority
Fixed

The DNSPacket::expand method in dnspacket.cc in PowerDNS before 2.9.17 allows remote attackers to cause a denial of service by sending a random stream of bytes.

1 affected package

pdns

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pdns
Show less packages

CVE-2005-0038

Medium priority
Not affected

The DNS implementation of PowerDNS 2.9.16 and earlier allows remote attackers to cause a denial of service via a compressed DNS packet with a label length byte with an incorrect offset, which could trigger an infinite loop.

1 affected package

pdns

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pdns
Show less packages