Debian Pdns-Recursor vulnerabilities
48 known vulnerabilities affecting debian/pdns-recursor.
Total CVEs
48
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH20MEDIUM19LOW9
Vulnerabilities
Page 3 of 3
CVE-2017-15092P4MEDIUMCVSS 6.1fixed in pdns-recursor 4.0.7-1 (bookworm)2017
CVE-2017-15092 [MEDIUM] CVE-2017-15092: pdns-recursor - A cross-site scripting issue has been found in the web interface of PowerDNS Rec...
A cross-site scripting issue has been found in the web interface of PowerDNS Recursor from 4.0.0 up to and including 4.0.6, where the qname of DNS queries was displayed without any escaping, allowing a remote attacker to inject HTML and Javascript code into the web interface, altering the content.
Scope: local
bookworm: resolved (fixed in 4.0.7-1)
bullseye:
debian
CVE-2026-0398P4MEDIUMCVSS 5.3fixed in pdns-recursor 5.3.5-1 (forky)2026
CVE-2026-0398 [MEDIUM] CVE-2026-0398: pdns-recursor - Crafted zones can lead to increased resource usage and crafted CNAME chains can ...
Crafted zones can lead to increased resource usage and crafted CNAME chains can lead to cache poisoning in Recursor.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 5.3.5-1)
sid: resolved (fixed in 5.3.5-1)
trixie: resolved (fixed in 5.2.8-0+deb13u1)
debian
CVE-2014-3614P4MEDIUMCVSS 5.0fixed in pdns-recursor 3.6.1-1 (bookworm)2014
CVE-2014-3614 [MEDIUM] CVE-2014-3614: pdns-recursor - Unspecified vulnerability in PowerDNS Recursor (aka pdns_recursor) 3.6.x before ...
Unspecified vulnerability in PowerDNS Recursor (aka pdns_recursor) 3.6.x before 3.6.1 allows remote attackers to cause a denial of service (crash) via an unknown sequence of malformed packets.
Scope: local
bookworm: resolved (fixed in 3.6.1-1)
bullseye: resolved (fixed in 3.6.1-1)
forky: resolved (fixed in 3.6.1-1)
sid: resolved (fixed in 3.6.1-1)
trixie: reso
debian
CVE-2008-3217P4LOWCVSS 6.8fixed in pdns-recursor 3.1.7-1 (bookworm)2008
CVE-2008-3217 [MEDIUM] CVE-2008-3217: pdns-recursor - PowerDNS Recursor before 3.1.6 does not always use the strongest random number g...
PowerDNS Recursor before 3.1.6 does not always use the strongest random number generator for source port selection, which makes it easier for remote attack vectors to conduct DNS cache poisoning. NOTE: this is related to incomplete integration of security improvements associated with addressing CVE-2008-1637.
Scope: local
bookworm: resolved (fixed in 3.1.7-1)
debian
CVE-2023-26437P4LOWCVSS 3.4fixed in pdns-recursor 4.8.4-1 (bookworm)2023
CVE-2023-26437 [LOW] CVE-2023-26437: pdns-recursor - Denial of service vulnerability in PowerDNS Recursor allows authoritative server...
Denial of service vulnerability in PowerDNS Recursor allows authoritative servers to be marked unavailable.This issue affects Recursor: through 4.6.5, through 4.7.4 , through 4.8.3.
Scope: local
bookworm: resolved (fixed in 4.8.4-1)
bullseye: open
forky: resolved (fixed in 4.8.4-1)
sid: resolved (fixed in 4.8.4-1)
trixie: resolved (fixed in 4.8.4-1)
debian
CVE-2006-2069P4MEDIUMCVSS 5.0fixed in pdns-recursor 3.0.1-1 (bookworm)2006
CVE-2006-2069 [MEDIUM] CVE-2006-2069: pdns-recursor - The recursor in PowerDNS before 3.0.1 allows remote attackers to cause a denial ...
The recursor in PowerDNS before 3.0.1 allows remote attackers to cause a denial of service (application crash) via malformed EDNS0 packets.
Scope: local
bookworm: resolved (fixed in 3.0.1-1)
bullseye: resolved (fixed in 3.0.1-1)
forky: resolved (fixed in 3.0.1-1)
sid: resolved (fixed in 3.0.1-1)
trixie: resolved (fixed in 3.0.1-1)
debian
CVE-2006-4252P4LOWCVSS 5.0fixed in pdns-recursor 3.1.4-1 (bookworm)2006
CVE-2006-4252 [MEDIUM] CVE-2006-4252: pdns - PowerDNS Recursor 3.1.3 and earlier allows remote attackers to cause a denial of...
PowerDNS Recursor 3.1.3 and earlier allows remote attackers to cause a denial of service (resource exhaustion and application crash) via a CNAME record with a zero TTL, which triggers an infinite loop.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
debian
CVE-2018-1000003P4LOWCVSS 3.7fixed in pdns-recursor 4.1.1-1 (bookworm)2018
CVE-2018-1000003 [LOW] CVE-2018-1000003: pdns-recursor - Improper input validation bugs in DNSSEC validators components in PowerDNS versi...
Improper input validation bugs in DNSSEC validators components in PowerDNS version 4.1.0 allow attacker in man-in-the-middle position to deny existence of some data in DNS via packet replay.
Scope: local
bookworm: resolved (fixed in 4.1.1-1)
bullseye: resolved (fixed in 4.1.1-1)
forky: resolved (fixed in 4.1.1-1)
sid: resolved (fixed in 4.1.1-1)
trixie: res
debian
← Previous3 / 3