CVE-2016-7074
- EPSS 0%
- Published 11.09.2018 13:29:01
- Last modified 21.11.2024 02:57:24
An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 4.0.4, allowing an attacker in position of man-in-the-middle to alter the content of an AXFR because of insufficient validation of TSIG signatures. A missing ch...
CVE-2016-7073
- EPSS 0.01%
- Published 11.09.2018 13:29:01
- Last modified 21.11.2024 02:57:24
An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 4.0.4, allowing an attacker in position of man-in-the-middle to alter the content of an AXFR because of insufficient validation of TSIG signatures. A missing ch...
CVE-2016-7068
- EPSS 0.09%
- Published 11.09.2018 13:29:00
- Last modified 21.11.2024 02:57:23
An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 3.7.4 and 4.0.4, allowing a remote, unauthenticated attacker to cause an abnormal CPU usage load on the PowerDNS server by sending crafted DNS queries, which mi...
CVE-2016-7072
- EPSS 0.03%
- Published 10.09.2018 17:29:00
- Last modified 21.11.2024 02:57:24
An issue has been found in PowerDNS Authoritative Server before 3.4.11 and 4.0.2 allowing a remote, unauthenticated attacker to cause a denial of service by opening a large number of TCP connections to the web server. If the web server runs out of fi...
CVE-2017-15091
- EPSS 0%
- Published 23.01.2018 15:29:00
- Last modified 21.11.2024 03:14:03
An issue has been found in the API component of PowerDNS Authoritative 4.x up to and including 4.0.4 and 3.x up to and including 3.4.11, where some operations that have an impact on the state of the server are still allowed even though the API has be...
CVE-2016-5427
- EPSS 85.55%
- Published 21.09.2016 14:25:15
- Last modified 12.04.2025 10:46:40
PowerDNS (aka pdns) Authoritative Server before 3.4.10 does not properly handle a . (dot) inside labels, which allows remote attackers to cause a denial of service (backend CPU consumption) via a crafted DNS query.
CVE-2016-5426
- EPSS 33.82%
- Published 21.09.2016 14:25:14
- Last modified 12.04.2025 10:46:40
PowerDNS (aka pdns) Authoritative Server before 3.4.10 allows remote attackers to cause a denial of service (backend CPU consumption) via a long qname.
- EPSS 85.3%
- Published 17.11.2015 15:59:07
- Last modified 12.04.2025 10:46:40
PowerDNS (aka pdns) Authoritative Server 3.4.4 before 3.4.7 allows remote attackers to cause a denial of service (assertion failure and server crash) via crafted query packets.
CVE-2015-5470
- EPSS 2.25%
- Published 02.11.2015 19:59:09
- Last modified 12.04.2025 10:46:40
The label decompression functionality in PowerDNS Recursor before 3.6.4 and 3.7.x before 3.7.3 and Authoritative (Auth) Server before 3.3.3 and 3.4.x before 3.4.5 allows remote attackers to cause a denial of service (CPU consumption or crash) via a r...
CVE-2015-1868
- EPSS 0.35%
- Published 18.05.2015 15:59:05
- Last modified 12.04.2025 10:46:40
The label decompression functionality in PowerDNS Recursor 3.5.x, 3.6.x before 3.6.3, and 3.7.x before 3.7.2 and Authoritative (Auth) Server 3.2.x, 3.3.x before 3.3.2, and 3.4.x before 3.4.4 allows remote attackers to cause a denial of service (CPU c...