Known Vulnerabilities for products from Powerdns

Listed below are 20 of the newest known vulnerabilities associated with the vendor "Powerdns".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2021-36754 PowerDNS Authoritative Server 4.5.0 before 4.5.1 allows anybody to crash the process by sending a specific query (QTYPE 65535... 7.5 - HIGH 2021-07-30 2021-08-07
CVE-2020-25829 An issue has been found in PowerDNS Recursor before 4.1.18, 4.2.x before 4.2.5, and 4.3.x before 4.3.5. A remote attacker can... 7.5 - HIGH 2020-10-16 2022-06-15
CVE-2020-24698 An issue was discovered in PowerDNS Authoritative through 4.3.0 when --enable-experimental-gss-tsig is used. A remote, unauth... 9.8 - CRITICAL 2020-10-02 2020-10-08
CVE-2020-24697 An issue was discovered in PowerDNS Authoritative through 4.3.0 when --enable-experimental-gss-tsig is used. A remote, unauth... 7.5 - HIGH 2020-10-02 2020-10-08
CVE-2020-24696 An issue was discovered in PowerDNS Authoritative through 4.3.0 when --enable-experimental-gss-tsig is used. A remote, unauth... 8.1 - HIGH 2020-10-02 2020-10-08
CVE-2020-17482 An issue has been found in PowerDNS Authoritative Server before 4.3.1 where an authorized user with the ability to insert cra... 4.3 - MEDIUM 2020-10-02 2022-01-01
CVE-2020-14196 In PowerDNS Recursor versions up to and including 4.3.1, 4.2.2 and 4.1.16, the ACL restricting access to the internal web ser... 5.3 - MEDIUM 2020-07-01 2023-11-07
CVE-2020-12244 An issue has been found in PowerDNS Recursor 4.1.0 through 4.3.0 where records in the answer section of a NXDOMAIN response l... 7.5 - HIGH 2020-05-19 2023-11-07
CVE-2020-10995 PowerDNS Recursor from 4.1.0 up to and including 4.3.0 does not sufficiently defend against amplification attacks. An issue i... 7.5 - HIGH 2020-05-19 2023-11-07
CVE-2020-10030 An issue has been found in PowerDNS Recursor 4.1.0 up to and including 4.3.0. It allows an attacker (with enough privileges t... 8.8 - HIGH 2020-05-19 2023-11-07
CVE-2019-10203 PowerDNS Authoritative daemon , pdns versions 4.0.x before 4.0.9, 4.1.x before 4.1.11, exiting when encountering a serial bet... 4.3 - MEDIUM 2019-11-22 2022-11-30
CVE-2019-10163 A Vulnerability has been found in PowerDNS Authoritative Server before versions 4.1.9, 4.0.8 allowing a remote, authorized ma... 4.3 - MEDIUM 2019-07-30 2023-02-03
CVE-2019-10162 A vulnerability has been found in PowerDNS Authoritative Server before versions 4.1.10, 4.0.8 allowing an authorized user to ... 7.5 - HIGH 2019-07-30 2020-10-02
CVE-2019-3871 A vulnerability was found in PowerDNS Authoritative Server before 4.0.7 and before 4.1.7. An insufficient validation of data ... 8.8 - HIGH 2019-03-21 2023-11-07
CVE-2019-3807 An issue has been found in PowerDNS Recursor versions 4.1.x before 4.1.9 where records in the answer section of responses rec... 9.8 - CRITICAL 2019-01-29 2019-10-09
CVE-2019-3806 An issue has been found in PowerDNS Recursor versions after 4.1.3 before 4.1.9 where Lua hooks are not properly applied to qu... 8.1 - HIGH 2019-01-29 2020-10-19
CVE-2018-1000003 Improper input validation bugs in DNSSEC validators components in PowerDNS version 4.1.0 allow attacker in man-in-the-middle ... 3.7 - LOW 2018-01-22 2018-02-06
CVE-2018-16855 An issue has been found in PowerDNS Recursor before version 4.1.8 where a remote attacker sending a DNS query can trigger an ... 7.5 - HIGH 2018-12-03 2019-10-09
CVE-2018-14663 An issue has been found in PowerDNS DNSDist before 1.3.3 allowing a remote attacker to craft a DNS query with trailing data s... 5.9 - MEDIUM 2018-11-26 2019-10-09
CVE-2018-14644 An issue has been found in PowerDNS Recursor from 4.0.0 up to and including 4.1.4. A remote attacker sending a DNS query for ... 5.9 - MEDIUM 2018-11-09 2019-10-09

Known software with vulnerabilities from Powerdns

Type Vendor Product Version
ApplicationPowerdnsAuthoritative1.0.0
ApplicationPowerdnsAuthoritative Server2.9.22
ApplicationPowerdnsDnsdist1.0.0
ApplicationPowerdnsPdns4.0.0
ApplicationPowerdnsRecursor3.0