CVE-2023-31137
- EPSS 1.03%
- Veröffentlicht 09.05.2023 14:15:13
- Zuletzt bearbeitet 21.11.2024 08:01:28
MaraDNS is open-source software that implements the Domain Name System (DNS). In version 3.5.0024 and prior, a remotely exploitable integer underflow vulnerability in the DNS packet decompression function allows an attacker to cause a Denial of Servi...
CVE-2022-30256
- EPSS 0.63%
- Veröffentlicht 19.11.2022 00:15:10
- Zuletzt bearbeitet 29.04.2025 15:15:47
An issue was discovered in MaraDNS Deadwood through 3.5.0021 that allows variant V1 of unintended domain name resolution. A revoked domain name can still be resolvable for a long time, including expired domains and taken-down malicious domains. The e...
CVE-2012-1570
- EPSS 0.66%
- Veröffentlicht 28.03.2012 10:55:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
The resolver in MaraDNS before 1.3.0.7.15 and 1.4.x before 1.4.12 overwrites cached server names and TTL values in NS records during the processing of a response to an A record query, which allows remote attackers to trigger continued resolvability o...
- EPSS 0.6%
- Veröffentlicht 08.01.2012 00:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
MaraDNS 1.3.07.12 and 1.4.08 computes hash values for DNS data without properly restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted queri...
CVE-2011-5056
- EPSS 0.08%
- Veröffentlicht 08.01.2012 00:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
The authoritative server in MaraDNS through 2.0.04 computes hash values for DNS data without restricting the ability to trigger hash collisions predictably, which might allow local users to cause a denial of service (CPU consumption) via crafted reco...
CVE-2012-0024
- EPSS 0.76%
- Veröffentlicht 08.01.2012 00:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
MaraDNS before 1.3.07.12 and 1.4.x before 1.4.08 computes hash values for DNS data without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many cr...
CVE-2011-0520
- EPSS 6.84%
- Veröffentlicht 28.01.2011 16:00:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
The compress_add_dlabel_points function in dns/Compress.c in MaraDNS 1.4.03, 1.4.05, and probably other versions allows remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a long DNS hostname wit...
CVE-2010-2444
- EPSS 0.5%
- Veröffentlicht 25.06.2010 18:30:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
parse/Csv2_parse.c in MaraDNS 1.3.03, and other versions before 1.4.03, does not properly handle hostnames that do not end in a "." (dot) character, which allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted c...
- EPSS 1.62%
- Veröffentlicht 03.01.2008 22:46:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
MaraDNS 1.0 before 1.0.41, 1.2 before 1.2.12.08, and 1.3 before 1.3.07.04 allows remote attackers to cause a denial of service via a crafted DNS packet that prevents an authoritative name (CNAME) record from resolving, aka "improper rotation of resou...
- EPSS 1.18%
- Veröffentlicht 07.06.2007 21:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Memory leak in server/MaraDNS.c in MaraDNS before 1.2.12.05, and 1.3.x before 1.3.03, allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors, a different set of affected versions than CVE-2007-3115 and CVE-2...