Adns

Vendor:

First CVE: Sep 18, 2008 · Active for 17 years

8
Total CVEs
More Total CVEs than 85% of tracked products
4.0
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
8.4
Avg CVSS
Higher Avg CVSS than 74% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Adns over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 18, 2008
17 years ago
Most Recent CVE
Jun 18, 2020
2,226 days ago

CVE Severity & Scoring

Adns8 CVEs
All CVEs352,101 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network7 (87.5%)
Unknown1 (12.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (87.5%)
High0 (0.0%)
Unknown1 (12.5%)
User Interaction
None7 (87.5%)
Unknown1 (12.5%)
Required0 (0.0%)
Privileges Required
Low1 (12.5%)
High0 (0.0%)
None6 (75.0%)
Unknown1 (12.5%)

Top CVEs

Signals from CVEs in this product scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
An issue was discovered in adns before 1.5.2. It hangs, eating CPU, if a compression pointer loop is encountered.
Jun 18, 20209.832NONO
An issue was discovered in adns before 1.5.2. It fails to ignore apparent answers before the first RR that was found the first time. when this is fixed, the second answer scan find
Jun 18, 20209.832NONO
An issue was discovered in adns before 1.5.2. pap_mailbox822 does not properly check st from adns__findlabel_next. Without this, an uninitialised stack value can be used as the fir
Jun 18, 20209.831NONO
An issue was discovered in adns before 1.5.2. It corrupts a pointer when a nameserver speaks first because of a wrong number of pointer dereferences. This bug may well be exploitab
Jun 18, 20208.830NONO
An issue was discovered in adns before 1.5.2. adnshost mishandles a missing final newline on a stdin read. It is wrong to increment used as well as setting r, since used is increme
Jun 18, 20207.526NONO
An issue was discovered in adns before 1.5.2. It overruns reading a buffer if a domain ends with backslash. If the query domain ended with \, and adns_qf_quoteok_query was specifie
Jun 18, 20207.526NONO
An issue was discovered in adns before 1.5.2. adns_rr_info mishandles a bogus *datap. The general pattern for formatting integers is to sprintf into a fixed-size buffer. This is co
Jun 18, 20207.525NONO
GNU adns 1.4 and earlier uses a fixed source port and sequential transaction IDs for DNS requests, which makes it easier for remote attackers to spoof DNS responses, a different vu
Sep 18, 20086.419NONO

Exploit Exposure

Signals from CVEs in this product scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (8 CVEs).

Media Mentions

Signals from CVEs in this product scope (8 CVEs).

Top CNAs Publishing CVEs For Adns

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
1.316.41.5%00
1.216.41.5%00
1.116.41.5%00
1.016.41.5%00
0.916.41.5%00
0.816.41.5%00
0.716.41.5%00
0.616.41.5%00
0.516.41.5%00
0.416.41.5%00
0.316.41.5%00
0.216.41.5%00
0.116.41.5%00