Vulnerabilities > Powerdns > Recursor > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-04-04 CVE-2023-26437 Unspecified vulnerability in Powerdns Recursor
Denial of service vulnerability in PowerDNS Recursor allows authoritative servers to be marked unavailable.This issue affects Recursor: through 4.6.5, through 4.7.4 , through 4.8.3.
network
low complexity
powerdns
5.3
2022-08-23 CVE-2022-37428 Incomplete Cleanup vulnerability in multiple products
PowerDNS Recursor up to and including 4.5.9, 4.6.2 and 4.7.1, when protobuf logging is enabled, has Improper Cleanup upon a Thrown Exception, leading to a denial of service (daemon crash) via a DNS query that leads to an answer with specific properties.
network
low complexity
powerdns fedoraproject CWE-459
6.5
2020-07-01 CVE-2020-14196 Incorrect Authorization vulnerability in Powerdns Recursor
In PowerDNS Recursor versions up to and including 4.3.1, 4.2.2 and 4.1.16, the ACL restricting access to the internal web server is not properly enforced.
network
low complexity
powerdns CWE-863
5.3
2018-11-09 CVE-2018-14644 Improper Input Validation vulnerability in Powerdns Recursor
An issue has been found in PowerDNS Recursor from 4.0.0 up to and including 4.1.4.
network
high complexity
powerdns CWE-20
5.9
2018-09-11 CVE-2016-7074 Improper Input Validation vulnerability in multiple products
An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 4.0.4, allowing an attacker in position of man-in-the-middle to alter the content of an AXFR because of insufficient validation of TSIG signatures.
network
high complexity
powerdns debian CWE-20
5.9
2018-09-11 CVE-2016-7073 Improper Input Validation vulnerability in multiple products
An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 4.0.4, allowing an attacker in position of man-in-the-middle to alter the content of an AXFR because of insufficient validation of TSIG signatures.
network
high complexity
powerdns debian CWE-20
5.9
2018-01-23 CVE-2017-15094 Missing Release of Resource after Effective Lifetime vulnerability in Powerdns Recursor
An issue has been found in the DNSSEC parsing code of PowerDNS Recursor from 4.0.0 up to and including 4.0.6 leading to a memory leak when parsing specially crafted DNSSEC ECDSA keys.
network
high complexity
powerdns CWE-772
5.9
2018-01-23 CVE-2017-15093 Improper Input Validation vulnerability in Powerdns Recursor
When api-config-dir is set to a non-empty value, which is not the case by default, the API in PowerDNS Recursor 4.x up to and including 4.0.6 and 3.x up to and including 3.7.4 allows an authorized user to update the Recursor's ACL by adding and removing netmasks, and to configure forward zones.
network
high complexity
powerdns CWE-20
5.3
2018-01-23 CVE-2017-15092 Cross-site Scripting vulnerability in Powerdns Recursor
A cross-site scripting issue has been found in the web interface of PowerDNS Recursor from 4.0.0 up to and including 4.0.6, where the qname of DNS queries was displayed without any escaping, allowing a remote attacker to inject HTML and Javascript code into the web interface, altering the content.
network
low complexity
powerdns CWE-79
6.1
2018-01-23 CVE-2017-15090 Improper Verification of Cryptographic Signature vulnerability in Powerdns Recursor
An issue has been found in the DNSSEC validation component of PowerDNS Recursor from 4.0.0 and up to and including 4.0.6, where the signatures might have been accepted as valid even if the signed data was not in bailiwick of the DNSKEY used to sign it.
network
high complexity
powerdns CWE-347
5.9