CVE-2025-30187
- EPSS 0.02%
- Published 18.09.2025 09:21:32
- Last modified 18.09.2025 13:43:34
In some circumstances, when DNSdist is configured to use the nghttp2 library to process incoming DNS over HTTPS queries, an attacker might be able to cause a denial of service by crafting a DoH exchange that triggers an unbounded I/O read loop, causi...
CVE-2025-30192
- EPSS 0.02%
- Published 21.07.2025 12:49:31
- Last modified 22.07.2025 13:06:07
An attacker spoofing answers to ECS enabled requests sent out by the Recursor has a chance of success higher than non-ECS enabled queries. The updated version include various mitigations against spoofing attempts of ECS enabled queries by chaining E...
CVE-2025-30193
- EPSS 0.07%
- Published 20.05.2025 11:17:17
- Last modified 21.05.2025 20:25:16
In some circumstances, when DNSdist is configured to allow an unlimited number of queries on a single, incoming TCP connection from a client, an attacker can cause a denial of service by crafting a TCP exchange that triggers an exhaustion of the stac...
CVE-2025-30194
- EPSS 0.06%
- Published 29.04.2025 11:25:47
- Last modified 20.06.2025 16:15:28
When DNSdist is configured to provide DoH via the nghttp2 provider, an attacker can cause a denial of service by crafting a DoH exchange that triggers an illegal memory access (double-free) and crash of DNSdist, causing a denial of service. The reme...
CVE-2025-30195
- EPSS 0.08%
- Published 07.04.2025 13:24:17
- Last modified 07.04.2025 16:15:25
An attacker can publish a zone containing specific Resource Record Sets. Processing and caching results for these sets can lead to an illegal memory accesses and crash of the Recursor, causing a denial of service. The remedy is: upgrade to the patch...
CVE-2024-25590
- EPSS 0.51%
- Published 03.10.2024 16:15:04
- Last modified 21.11.2024 09:01:02
An attacker can publish a zone containing specific Resource Record Sets. Repeatedly processing and caching results for these sets can lead to a denial of service.
CVE-2018-1046
- EPSS 0.01%
- Published 16.07.2018 20:29:00
- Last modified 21.11.2024 03:59:03
pdns before version 4.1.2 is vulnerable to a buffer overflow in dnsreplay. In the dnsreplay tool provided with PowerDNS Authoritative, replaying a specially crafted PCAP file can trigger a stack-based buffer overflow, leading to a crash and potential...