Vulnerabilities > Maradns
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-05-09 | CVE-2023-31137 | Integer Underflow (Wrap or Wraparound) vulnerability in multiple products MaraDNS is open-source software that implements the Domain Name System (DNS). | 7.5 |
2022-11-19 | CVE-2022-30256 | Operation on a Resource after Expiration or Release vulnerability in Maradns An issue was discovered in MaraDNS Deadwood through 3.5.0021 that allows variant V1 of unintended domain name resolution. | 7.5 |
2012-03-28 | CVE-2012-1570 | Unspecified vulnerability in Maradns The resolver in MaraDNS before 1.3.0.7.15 and 1.4.x before 1.4.12 overwrites cached server names and TTL values in NS records during the processing of a response to an A record query, which allows remote attackers to trigger continued resolvability of revoked domain names via a "ghost domain names" attack. network maradns | 4.3 |
2012-01-08 | CVE-2012-0024 | Resource Exhaustion vulnerability in Maradns MaraDNS before 1.3.07.12 and 1.4.x before 1.4.08 computes hash values for DNS data without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted queries with the Recursion Desired (RD) bit set. | 7.8 |
2012-01-08 | CVE-2011-5056 | Resource Exhaustion vulnerability in Maradns The authoritative server in MaraDNS through 2.0.04 computes hash values for DNS data without restricting the ability to trigger hash collisions predictably, which might allow local users to cause a denial of service (CPU consumption) via crafted records in zone files, a different vulnerability than CVE-2012-0024. | 2.1 |
2012-01-08 | CVE-2011-5055 | Improper Input Validation vulnerability in Maradns 1.3.07.012/1.4.08 MaraDNS 1.3.07.12 and 1.4.08 computes hash values for DNS data without properly restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted queries with the Recursion Desired (RD) bit set. | 5.0 |
2011-01-28 | CVE-2011-0520 | Buffer Errors vulnerability in Maradns 1.4.03/1.4.05 The compress_add_dlabel_points function in dns/Compress.c in MaraDNS 1.4.03, 1.4.05, and probably other versions allows remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a long DNS hostname with a large number of labels, which triggers a heap-based buffer overflow. | 7.5 |
2010-06-25 | CVE-2010-2444 | Denial-Of-Service vulnerability in MaraDNS parse/Csv2_parse.c in MaraDNS 1.3.03, and other versions before 1.4.03, does not properly handle hostnames that do not end in a "." (dot) character, which allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted csv2 zone file. network maradns | 4.3 |
2008-01-03 | CVE-2008-0061 | Remote Denial of Service vulnerability in MaraDNS Malformed Packet MaraDNS 1.0 before 1.0.41, 1.2 before 1.2.12.08, and 1.3 before 1.3.07.04 allows remote attackers to cause a denial of service via a crafted DNS packet that prevents an authoritative name (CNAME) record from resolving, aka "improper rotation of resource records." | 5.0 |
2007-06-07 | CVE-2007-3116 | Resource Management Errors vulnerability in Maradns 1.2.12.06/1.3.05 Memory leak in server/MaraDNS.c in MaraDNS 1.2.12.06 and 1.3.05 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors, a different set of affected versions than CVE-2007-3114 and CVE-2007-3115. | 5.0 |