Maradns is a lightweight, open-source authoritative DNS server deployed in a focused, modestly represented niche of the vulnerability landscape. Its durable exposure centers on the core Maradns product and recurs through weakness classes including resource-consumption flaws, input-validation issues, and memory-buffer handling defects that are characteristic of network protocol implementations. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Maradns over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-0024HIGH MaraDNS before 1.3.07.12 and 1.4.x before 1.4.08 computes hash values for DNS data without restricting the ability to trigger hash collisions predictably, which allows remote attac | Jan 8, 2012 | 7.8 | 26 | NO | NO |
CVE-2011-0520HIGH The compress_add_dlabel_points function in dns/Compress.c in MaraDNS 1.4.03, 1.4.05, and probably other versions allows remote attackers to cause a denial of service (segmentation | Jan 28, 2011 | 7.5 | 26 | NO | NO |
CVE-2022-30256HIGH An issue was discovered in MaraDNS Deadwood through 3.5.0021 that allows variant V1 of unintended domain name resolution. A revoked domain name can still be resolvable for a long t | Nov 19, 2022 | 7.5 | 25 | NO | NO |
CVE-2023-31137HIGH MaraDNS is open-source software that implements the Domain Name System (DNS). In version 3.5.0024 and prior, a remotely exploitable integer underflow vulnerability in the DNS packe | May 9, 2023 | 7.5 | 24 | NO | NO |
CVE-2014-2032MEDIUM Deadwood before 2.3.09, 3.x before 3.2.05, and as used in MaraDNS before 1.4.14 and 2.x before 2.0.09, allow remote attackers to cause a denial of service (out-of-bounds read and c | Mar 20, 2018 | 5.9 | 21 | NO | NO |
CVE-2007-3115HIGH Multiple memory leaks in server/MaraDNS.c in MaraDNS before 1.2.12.06, and 1.3.x before 1.3.05, allow remote attackers to cause a denial of service (memory consumption) via (1) rev | Jun 7, 2007 | 7.8 | 20 | NO | NO |
CVE-2004-0789MEDIUM Multiple implementations of the DNS protocol, including (1) Poslib 1.0.2-1 and earlier as used by Posadis, (2) Axis Network products before firmware 3.13, and (3) Men & Mice Suite | Dec 31, 2004 | 5.0 | 20 | NO | NO |
CVE-2012-1570MEDIUM The resolver in MaraDNS before 1.3.0.7.15 and 1.4.x before 1.4.12 overwrites cached server names and TTL values in NS records during the processing of a response to an A record que | Mar 28, 2012 | 4.3 | 18 | NO | NO |
CVE-2011-5055MEDIUM MaraDNS 1.3.07.12 and 1.4.08 computes hash values for DNS data without properly restricting the ability to trigger hash collisions predictably, which allows remote attackers to cau | Jan 8, 2012 | 5.0 | 18 | NO | NO |
CVE-2014-2031MEDIUM Deadwood before 2.3.09, 3.x before 3.2.05, and as used in MaraDNS before 1.4.14 and 2.x before 2.0.09, allow remote attackers to cause a denial of service (out-of-bounds read and c | Mar 20, 2018 | 5.9 | 17 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Maradns.
Media articles that mention a CVE ID that affects a product developed by Maradns — matched by CVE ID, not by vendor name.