Adns
Vendor:
First CVE: Sep 18, 2008 · Active for 17 years
8
Total CVEs
More Total CVEs than 85% of tracked products
4.0
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
8.4
Avg CVSS
Higher Avg CVSS than 74% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Adns over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 18, 2008
17 years ago
Most Recent CVE
Jun 18, 2020
2,226 days ago
CVE Severity & Scoring
Adns8 CVEs
13%
50%
38%
All CVEs352,101 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network7 (87.5%)
Unknown1 (12.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (87.5%)
High0 (0.0%)
Unknown1 (12.5%)
User Interaction
None7 (87.5%)
Unknown1 (12.5%)
Required0 (0.0%)
Privileges Required
Low1 (12.5%)
High0 (0.0%)
None6 (75.0%)
Unknown1 (12.5%)
Top CVEs
Signals from CVEs in this product scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-9104CRITICAL An issue was discovered in adns before 1.5.2. It hangs, eating CPU, if a compression pointer loop is encountered. | Jun 18, 2020 | 9.8 | 32 | NO | NO |
CVE-2017-9109CRITICAL An issue was discovered in adns before 1.5.2. It fails to ignore apparent answers before the first RR that was found the first time. when this is fixed, the second answer scan find | Jun 18, 2020 | 9.8 | 32 | NO | NO |
CVE-2017-9103CRITICAL An issue was discovered in adns before 1.5.2. pap_mailbox822 does not properly check st from adns__findlabel_next. Without this, an uninitialised stack value can be used as the fir | Jun 18, 2020 | 9.8 | 31 | NO | NO |
CVE-2017-9105HIGH An issue was discovered in adns before 1.5.2. It corrupts a pointer when a nameserver speaks first because of a wrong number of pointer dereferences. This bug may well be exploitab | Jun 18, 2020 | 8.8 | 30 | NO | NO |
CVE-2017-9108HIGH An issue was discovered in adns before 1.5.2. adnshost mishandles a missing final newline on a stdin read. It is wrong to increment used as well as setting r, since used is increme | Jun 18, 2020 | 7.5 | 26 | NO | NO |
CVE-2017-9107HIGH An issue was discovered in adns before 1.5.2. It overruns reading a buffer if a domain ends with backslash. If the query domain ended with \, and adns_qf_quoteok_query was specifie | Jun 18, 2020 | 7.5 | 26 | NO | NO |
CVE-2017-9106HIGH An issue was discovered in adns before 1.5.2. adns_rr_info mishandles a bogus *datap. The general pattern for formatting integers is to sprintf into a fixed-size buffer. This is co | Jun 18, 2020 | 7.5 | 25 | NO | NO |
CVE-2008-4100MEDIUM GNU adns 1.4 and earlier uses a fixed source port and sequential transaction IDs for DNS requests, which makes it easier for remote attackers to spoof DNS responses, a different vu | Sep 18, 2008 | 6.4 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (8 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (8 CVEs).
Media Mentions
Signals from CVEs in this product scope (8 CVEs).
Top CNAs Publishing CVEs For Adns
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.3 | 1 | 6.4 | 1.5% | 0 | 0 |
| 1.2 | 1 | 6.4 | 1.5% | 0 | 0 |
| 1.1 | 1 | 6.4 | 1.5% | 0 | 0 |
| 1.0 | 1 | 6.4 | 1.5% | 0 | 0 |
| 0.9 | 1 | 6.4 | 1.5% | 0 | 0 |
| 0.8 | 1 | 6.4 | 1.5% | 0 | 0 |
| 0.7 | 1 | 6.4 | 1.5% | 0 | 0 |
| 0.6 | 1 | 6.4 | 1.5% | 0 | 0 |
| 0.5 | 1 | 6.4 | 1.5% | 0 | 0 |
| 0.4 | 1 | 6.4 | 1.5% | 0 | 0 |
| 0.3 | 1 | 6.4 | 1.5% | 0 | 0 |
| 0.2 | 1 | 6.4 | 1.5% | 0 | 0 |
| 0.1 | 1 | 6.4 | 1.5% | 0 | 0 |