Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
38 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.9) | 1.2% | — | Powerdns AuthoritativePowerdns RecursorDebian Linux | 11/9/2018 | 17/6/2026 | An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 4.0.4, allowing an attacker in position of man-in-the-middle to alter the content of an AXFR because of insufficient validation of TSIG signatures. A missing check that the TSIG record is the last one, leading to the possibility… | |
| Modificada | Media (5.9) | 1.2% | — | Powerdns AuthoritativePowerdns RecursorDebian Linux | 11/9/2018 | 17/6/2026 | An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 4.0.4, allowing an attacker in position of man-in-the-middle to alter the content of an AXFR because of insufficient validation of TSIG signatures. A missing check of the TSIG time and fudge values was found in AXFRRetriever,… | |
| Modificada | Alta (7.5) | 7.3% | — | Powerdns AuthoritativePowerdns RecursorDebian Linux | 11/9/2018 | 17/6/2026 | An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 3.7.4 and 4.0.4, allowing a remote, unauthenticated attacker to cause an abnormal CPU usage load on the PowerDNS server by sending crafted DNS queries, which might result in a partial denial of service if the system becomes… | |
| Modificada | Alta (7.5) | 6.2% | — | Powerdns AuthoritativeDebian Linux | 10/9/2018 | 17/6/2026 | An issue has been found in PowerDNS Authoritative Server before 3.4.11 and 4.0.2 allowing a remote, unauthenticated attacker to cause a denial of service by opening a large number of TCP connections to the web server. If the web server runs out of file descriptors, it triggers an exception and terminates the whole… | |
| Modificada | Alta (7.1) | 1.2% | — | Powerdns Authoritative | 23/1/2018 | 17/6/2026 | An issue has been found in the API component of PowerDNS Authoritative 4.x up to and including 4.0.4 and 3.x up to and including 3.4.11, where some operations that have an impact on the state of the server are still allowed even though the API has been configured as read-only via the api-readonly keyword. This missing… | |
| Modificada | Media (6.8) | 3.8% | — | Opensuse LeapOpensusePowerdns Authoritative Server | 26/9/2016 | 17/6/2026 | PowerDNS (aka pdns) Authoritative Server before 4.0.1 allows remote primary DNS servers to cause a denial of service (memory exhaustion and secondary DNS server crash) via a large (1) AXFR or (2) IXFR response. | |
| Modificada | Alta (7.5) | 63% | — | Powerdns Authoritative | 21/9/2016 | 17/6/2026 | PowerDNS (aka pdns) Authoritative Server before 3.4.10 does not properly handle a . (dot) inside labels, which allows remote attackers to cause a denial of service (backend CPU consumption) via a crafted DNS query. | |
| Modificada | Alta (7.5) | 31% | — | Powerdns Authoritative | 21/9/2016 | 17/6/2026 | PowerDNS (aka pdns) Authoritative Server before 3.4.10 allows remote attackers to cause a denial of service (backend CPU consumption) via a long qname. | |
| Modificada | Media (5) | 67% | — | Powerdns Authoritative | 17/11/2015 | 17/6/2026 | PowerDNS (aka pdns) Authoritative Server 3.4.4 before 3.4.7 allows remote attackers to cause a denial of service (assertion failure and server crash) via crafted query packets. | |
| Modificada | Alta (7.8) | 11% | — | Powerdns AuthoritativePowerdns Recursor | 2/11/2015 | 17/6/2026 | The label decompression functionality in PowerDNS Recursor before 3.6.4 and 3.7.x before 3.7.3 and Authoritative (Auth) Server before 3.3.3 and 3.4.x before 3.4.5 allows remote attackers to cause a denial of service (CPU consumption or crash) via a request with a long name that refers to itself. NOTE: this… | |
| Modificada | Alta (7.8) | 82% | — | Powerdns AuthoritativeFedoraproject FedoraPowerdns Recursor | 18/5/2015 | 17/6/2026 | The label decompression functionality in PowerDNS Recursor 3.5.x, 3.6.x before 3.6.3, and 3.7.x before 3.7.2 and Authoritative (Auth) Server 3.2.x, 3.3.x before 3.3.2, and 3.4.x before 3.4.4 allows remote attackers to cause a denial of service (CPU consumption or crash) via a request with a name that refers to itself. | |
| Modificada | Media (5) | 4.8% | — | Powerdns Authoritative Server | 17/2/2012 | 16/6/2026 | common_startup.cc in PowerDNS (aka pdns) Authoritative Server before 2.9.22.5 and 3.x before 3.0.1 allows remote attackers to cause a denial of service (packet loop) via a crafted UDP DNS response. | |
| Modificada | Media (6.4) | 6.1% | — | Powerdns Authoritative ServerPowerdns | 8/8/2008 | 16/6/2026 | PowerDNS Authoritative Server before 2.9.21.1 drops malformed queries, which might make it easier for remote attackers to poison DNS caches of other products running on other servers, a different issue than CVE-2008-1447 and CVE-2008-3217. |