VYPR

by PowerDNS

CVEs (26)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2025-59023Hig0.538.20.00Feb 9, 2026Crafted delegations or IP fragments can poison cached delegations in Recursor.
CVE-2025-59024Med0.426.50.00Feb 9, 2026Crafted delegations or IP fragments can poison cached delegations in Recursor.
CVE-2026-33262Med0.385.90.00Apr 22, 2026An attacker can send replies that result in a null pointer dereference, caused by a missing consistency check and leading to a denial of service. Cookies are disabled by default.
CVE-2026-33261Med0.385.90.00Apr 22, 2026A zone transition from NSEC to NSEC3 might trigger an internal inconsistency and cause a denial of service.
CVE-2026-33260Med0.345.30.00Apr 22, 2026An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default.
CVE-2026-33258Med0.345.30.00Apr 22, 2026By publishing and querying a crafted zone an attacker can cause allocation of large entries in the negative and aggressive NSEC(3) caches.
CVE-2026-33257Med0.345.30.00Apr 22, 2026An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default.
CVE-2026-33256Med0.345.30.00Apr 22, 2026An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default.
CVE-2026-24027Med0.345.30.00Feb 9, 2026Crafted zones can lead to increased incoming network traffic.
CVE-2026-0398Med0.345.30.00Feb 9, 2026Crafted zones can lead to increased resource usage and crafted CNAME chains can lead to cache poisoning in Recursor.
CVE-2026-33259Med0.335.00.00Apr 22, 2026Having many concurrent transfers of the same RPZ can lead to inconsistent RPZ data, use after free and/or a crash of the recursor. Normally concurrent transfers of the same RPZ zone can only occur with a malfunctioning RPZ provider.
CVE-2026-33601Med0.294.40.00Apr 22, 2026If you use the zoneToCache function with a malicious authoritative server, an attacker can send a zone that result in a null pointer dereference, caused by a missing consistency check and leading to a denial of service.
CVE-2026-33600Med0.294.40.00Apr 22, 2026An RPZ sent by a malicious authoritative server can result in a null pointer dereference, caused by a missing consistency check and leading to a denial of service.
CVE-2025-590290.000.00Dec 9, 2025An attacker can trigger an assertion failure by requesting crafted DNS records, waiting for them to be inserted into the records cache, then send a query with qtype set to ANY.
CVE-2025-590300.000.00Dec 9, 2025An attacker can trigger the removal of cached records by sending a NOTIFY query over TCP.
CVE-2023-264370.000.00Apr 4, 2023Denial of service vulnerability in PowerDNS Recursor allows authoritative servers to be marked unavailable.This issue affects Recursor: through 4.6.5, through 4.7.4 , through 4.8.3.
CVE-2015-18680.000.01May 18, 2015The label decompression functionality in PowerDNS Recursor 3.5.x, 3.6.x before 3.6.3, and 3.7.x before 3.7.2 and Authoritative (Auth) Server 3.2.x, 3.3.x before 3.3.2, and 3.4.x before 3.4.4 allows remote attackers to cause a denial of service (CPU consumption or crash) via a request with a name that refers to itself.
CVE-2014-86010.000.01Dec 10, 2014PowerDNS Recursor before 3.6.2 does not limit delegation chaining, which allows remote attackers to cause a denial of service ("performance degradations") via a large or infinite number of referrals, as demonstrated by resolving domains hosted by ezdns.it.
CVE-2014-36140.000.00Sep 19, 2014Unspecified vulnerability in PowerDNS Recursor (aka pdns_recursor) 3.6.x before 3.6.1 allows remote attackers to cause a denial of service (crash) via an unknown sequence of malformed packets.
CVE-2012-11930.000.00Feb 17, 2012The resolver in PowerDNS Recursor (aka pdns_recursor) 3.3 overwrites cached server names and TTL values in NS records during the processing of a response to an A record query, which allows remote attackers to trigger continued resolvability of revoked domain names via a "ghost domain names" attack.

Page 1 of 2