Vulnerability index

Browse CVEs

129 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Bind HIGH 7.8
CVE-2013-3919EPSS 5%

resolver.c in ISC BIND 9.8.5 before 9.8.5-P1, 9.9.3 before 9.9.3-P1, and 9.6-ESV-R9 before 9.6-ESV-R9-P1, when a recursive resolver is configured, al…

Patch available
Fix from $1,950 2013-06-06
Bind HIGH 7.8
CVE-2013-2266EPSS 43%

libdns in ISC BIND 9.7.x and 9.8.x before 9.8.4-P2, 9.8.5 before 9.8.5b2, 9.9.x before 9.9.2-P2, and 9.9.3 before 9.9.3b2 on UNIX platforms allows re…

Mitigation only
Fix from $1,950 2013-03-28
Inn MEDIUM 6.8
CVE-2012-3523

The STARTTLS implementation in nnrpd in INN before 2.5.3 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert…

Fix: after 2.5.2
Fix from $1,600 2012-11-11
Bind HIGH 7.8
CVE-2012-5166EPSS 34%

ISC BIND 9.x before 9.7.6-P4, 9.8.x before 9.8.3-P4, 9.9.x before 9.9.1-P4, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P4 allows remote attackers to c…

Mitigation only
Fix from $1,950 2012-10-10
Bind HIGH 7.8
CVE-2012-4244EPSS 37%

ISC BIND 9.x before 9.7.6-P3, 9.8.x before 9.8.3-P3, 9.9.x before 9.9.1-P3, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P3 allows remote attackers to c…

Mitigation only
Fix from $1,950 2012-09-14
Bind HIGH 7.8
CVE-2012-3817EPSS 27%

ISC BIND 9.4.x, 9.5.x, 9.6.x, and 9.7.x before 9.7.6-P2; 9.8.x before 9.8.3-P2; 9.9.x before 9.9.1-P2; and 9.6-ESV before 9.6-ESV-R7-P2, when DNSSEC …

Mitigation only
Fix from $1,950 2012-07-25
Dhcp MEDIUM 5.7
CVE-2012-3570

Buffer overflow in ISC DHCP 4.2.x before 4.2.4-P1, when DHCPv6 mode is enabled, allows remote attackers to cause a denial of service (segmentation fa…

Mitigation only
Fix from $1,600 2012-07-25
Bind HIGH 8.5
CVE-2012-1667EPSS 13%

ISC BIND 9.x before 9.7.6-P1, 9.8.x before 9.8.3-P1, 9.9.x before 9.9.1-P1, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P1 does not properly handle res…

Mitigation only
Fix from $1,950 2012-06-05
Bind MEDIUM 5.0
CVE-2012-1033EPSS 14%

The resolver in ISC BIND 9 through 9.8.1-P1 overwrites cached server names and TTL values in NS records during the processing of a response to an A r…

Mitigation only
Fix from $1,600 2012-02-08
Dhcp MEDIUM 6.1
CVE-2011-4868

The logging functionality in dhcpd in ISC DHCP before 4.2.3-P2, when using Dynamic DNS (DDNS) and issuing IPv6 addresses, does not properly handle th…

Fix: after 4.2.3
Fix from $1,600 2012-01-15
Bind MEDIUM 5.0
CVE-2011-4313EPSS 16%

query.c in ISC BIND 9.0.x through 9.6.x, 9.4-ESV through 9.4-ESV-R5, 9.6-ESV through 9.6-ESV-R5, 9.7.0 through 9.7.4, 9.8.0 through 9.8.1, and 9.9.0a…

Patch available
Fix from $1,600 2011-11-29
Bind MEDIUM 5.0
CVE-2011-2464EPSS 19%

Unspecified vulnerability in ISC BIND 9 9.6.x before 9.6-ESV-R4-P3, 9.7.x before 9.7.3-P3, and 9.8.x before 9.8.0-P4 allows remote attackers to cause…

Mitigation only
Fix from $1,600 2011-07-08
Bind MEDIUM 5.0
CVE-2011-1910EPSS 25%

Off-by-one error in named in ISC BIND 9.x before 9.7.3-P1, 9.8.x before 9.8.0-P2, 9.4-ESV before 9.4-ESV-R4-P1, and 9.6-ESV before 9.6-ESV-R4-P1 allo…

Mitigation only
Fix from $1,600 2011-05-31
Bind MEDIUM 5.0
CVE-2011-1907EPSS 5%

ISC BIND 9.8.x before 9.8.0-P1, when Response Policy Zones (RPZ) RRset replacement is enabled, allows remote attackers to cause a denial of service (…

Mitigation only
Fix from $1,600 2011-05-09
Bind HIGH 7.1
CVE-2011-0414EPSS 14%

ISC BIND 9.7.1 through 9.7.2-P3, when configured as an authoritative server, allows remote attackers to cause a denial of service (deadlock and daemo…

Mitigation only
Fix from $1,950 2011-02-23
Dhcp HIGH 7.8
CVE-2011-0413EPSS 33%

The DHCPv6 server in ISC DHCP 4.0.x and 4.1.x before 4.1.2-P1, 4.0-ESV and 4.1-ESV before 4.1-ESV-R1, and 4.2.x before 4.2.1b1 allows remote attacker…

Mitigation only
Fix from $1,950 2011-01-31
Dhcp MEDIUM 5.0
CVE-2010-3616EPSS 8%

ISC DHCP server 4.2 before 4.2.0-P2, when configured to use failover partnerships, allows remote attackers to cause a denial of service (communicatio…

Mitigation only
Fix from $1,600 2010-12-17
Bind MEDIUM 6.4
CVE-2010-3614EPSS 15%

named in ISC BIND 9.x before 9.6.2-P3, 9.7.x before 9.7.2-P3, 9.4-ESV before 9.4-ESV-R4, and 9.6-ESV before 9.6-ESV-R3 does not properly determine th…

Mitigation only
Fix from $1,600 2010-12-06
Bind MEDIUM 5.0
CVE-2010-3615EPSS 10%

named in ISC BIND 9.7.2-P2 does not check all intended locations for allow-query ACLs, which might allow remote attackers to make successful requests…

Mitigation only
Fix from $1,600 2010-12-06
Bind MEDIUM 5.0
CVE-2010-0218

ISC BIND 9.7.2 through 9.7.2-P1 uses an incorrect ACL to restrict the ability of Recursion Desired (RD) queries to access the cache, which allows rem…

Patch available
Fix from $1,600 2010-10-05
Dhcp MEDIUM 5.0
CVE-2010-2156EPSS 76%

ISC DHCP 4.1 before 4.1.1-P1 and 4.0 before 4.0.2-P1 allows remote attackers to cause a denial of service (server exit) via a zero-length client ID.

No fix yet
Fix from $1,600 2010-06-07
Bind HIGH 7.6
CVE-2010-0382EPSS 7%

ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta handles out-of-bailiwick data accompanyin…

Mitigation only
Fix from $1,950 2010-01-22
Dhcp MEDIUM 5.0
CVE-2009-1892EPSS 9%

dhcpd in ISC DHCP 3.0.4 and 3.1.1, when the dhcp-client-identifier and hardware ethernet configuration settings are both used, allows remote attacker…

Patch available
Fix from $1,600 2009-07-17
Dhcp HIGH 10.0
CVE-2009-0692EPSS 26%

Stack-based buffer overflow in the script_write_params method in client/dhclient.c in ISC DHCP dhclient 4.1 before 4.1.0p1, 4.0 before 4.0.1p1, 3.1 b…

Patch available
Fix from $1,950 2009-07-14
Bind HIGH 7.5
CVE-2009-0265

Internet Systems Consortium (ISC) BIND 9.6.0 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which al…

Fix: after 9.6.0
Fix from $1,950 2009-01-26
Bind MEDIUM 6.8
CVE-2009-0025EPSS 7%

BIND 9.6.0, 9.5.1, 9.5.0, 9.4.3, and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attac…

Mitigation only
Fix from $1,600 2009-01-07
Bind HIGH 7.8
CVE-2008-4163

Unspecified vulnerability in ISC BIND 9.3.5-P2-W1, 9.4.2-P2-W1, and 9.5.0-P2-W1 on Windows allows remote attackers to cause a denial of service (UDP …

Mitigation only
Fix from $1,950 2008-09-22
Bind MEDIUM 6.8
CVE-2008-1447EPSS 95%

The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windows 2000 SP4, XP SP2 and SP3, …

Patch available
Fix from $1,600 2008-07-08
Bind HIGH 10.0
CVE-2008-0122EPSS 12%

Off-by-one error in the inet_network function in libbind in ISC BIND 9.4.2 and earlier, as used in libc in FreeBSD 6.2 through 7.0-PRERELEASE, allows…

Fix: after 9.4.2
Fix from $1,950 2008-01-16
Bind MEDIUM 5.8
CVE-2007-2925EPSS 6%

The default access control lists (ACL) in ISC BIND 9.4.0, 9.4.1, and 9.5.0a1 through 9.5.0a5 do not set the allow-recursion and allow-query-cache ACL…

Mitigation only
Fix from $1,600 2007-07-24