Vulnerability index

Browse CVEs

129 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2026-5946 Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS is not Internet (`IN`) — for example, `CHAOS` or `… Bind 9.18.49 / 9.20.23+ Fix from $1,9502026-05-20 MEDIUM 5.9 CVE-2026-5947 Undefined behavior may result due to a race condition leading to a use-after-free violation. If BIND receives an incoming DNS message signed with SI… Bind 9.20.23 / 9.21.22+ Fix from $1,6002026-05-20 MEDIUM 5.3 CVE-2026-5950 An unbounded resend loop vulnerability exists in the BIND 9 resolver state machine during bad-server handling, enabling a remote unauthenticated atta… Bind 9.18.49 / 9.20.23+ Fix from $1,6002026-05-20 CRITICAL 9.8 CVE-2026-3593 A use-after-free vulnerability exists within the DNS-over-HTTPS implementation. This issue affects BIND 9 versions 9.20.0 through 9.20.22, 9.21.0 thr… Bind 9.20.23 / 9.21.22+ Fix from $2,3002026-05-20 HIGH 7.5 CVE-2026-3039 BIND servers that are configured to use TKEY-based authentication via GSS-API tokens are vulnerable to excessive memory consumption when receiving an… Bind 9.18.49 / 9.20.23+ Fix from $1,9502026-05-20 MEDIUM 5.3 CVE-2026-3592 BIND resolvers are vulnerable to an amplified resource consumption/exhaustion attack. If a victim resolver makes a query to a specially crafted zone… Bind 9.18.49 / 9.20.23+ Fix from $1,6002026-05-20 MEDIUM 6.5 CVE-2026-3119 Under certain conditions, `named` may crash when processing a correctly signed query containing a TKEY record. The affected code can only be reached … Bind 9.20.21 / 9.21.20+ Fix from $1,6002026-03-25 MEDIUM 5.4 CVE-2026-3591 A use-after-return vulnerability exists in the `named` server when handling DNS queries signed with SIG(0). Using a specially-crafted DNS request, an… Bind 9.20.21 / 9.21.20+ Fix from $1,6002026-03-25 HIGH 7.5 CVE-2026-3104 A specially crafted domain can be used to cause a memory leak in a BIND resolver simply by querying this domain. This issue affects BIND 9 versions 9… Bind 9.20.21 / 9.21.20+ Fix from $1,9502026-03-25 HIGH 7.5 CVE-2026-1519 If a BIND resolver is performing DNSSEC validation and encounters a maliciously crafted zone, the resolver may consume excessive CPU. Authoritative-o… Bind 9.18.47 / 9.20.21+ Fix from $1,9502026-03-25 HIGH 8.1 CVE-2024-28872 The TLS certificate validation code is flawed. An attacker can obtain a TLS certificate from the Stork server and use it to connect to the Stork agen… Stork 1.15.1+ Fix from $1,9502024-07-11 HIGH 7.5 CVE-2023-6516 To keep its cache database efficient, `named` running as a recursive resolver occasionally attempts to clean up the database. It uses several methods… Bind after 9.16.45 Fix from $1,9502024-02-13 MEDIUM 5.3 CVE-2023-5680 If a resolver cache has a very large number of ECS records stored for the same name, the process of cleaning the cache database node for this name ca… Bind Mitigation only Fix from $1,6002024-02-13 HIGH 7.5 CVE-2023-2829 A `named` instance configured to run as a DNSSEC-validating recursive resolver with the Aggressive Use of DNSSEC-Validated Cache (RFC 8198) option (`… Bind after 9.18.15 Fix from $1,9502023-06-21 HIGH 7.5 CVE-2022-3924EPSS 16% This issue can affect BIND 9 resolvers with `stale-answer-enable yes;` that also make use of the option `stale-answer-client-timeout`, configured wit… Bind 9.16.37 / 9.18.11+ Fix from $1,9502023-01-26 HIGH 7.5 CVE-2022-3736EPSS 49% BIND 9 resolver can crash when stale cache and stale answers are enabled, option `stale-answer-client-timeout` is set to a positive integer, and the … Bind 9.16.37 / 9.18.11+ Fix from $1,9502023-01-26 HIGH 7.5 CVE-2022-3488EPSS 19% Processing of repeated responses to the same query, where both responses contain ECS pseudo-options, but where the first is broken in some way, can c… Bind No fix yet Fix from $1,9502023-01-26 HIGH 7.5 CVE-2022-3094EPSS 13% Sending a flood of dynamic DNS updates may cause `named` to allocate large amounts of memory. This, in turn, may cause `named` to exit due to a lack … Bind 9.16.37 / 9.18.11+ Fix from $1,9502023-01-26 HIGH 8.2 CVE-2022-2881 The underlying bug might cause read past end of the buffer and either read memory it should not read, or crash the process. Bind 9.18.7 / 9.19.5+ Fix from $1,9502022-09-21 HIGH 7.5 CVE-2022-2906 An attacker can leverage this flaw to gradually erode available memory to the point where named crashes for lack of resources. Upon restart the attac… Bind 9.18.7 / 9.19.5+ Fix from $1,9502022-09-21 HIGH 7.5 CVE-2022-1183EPSS 6% On vulnerable configurations, the named daemon may, in some circumstances, terminate with an assertion failure. Vulnerable configurations are those t… Bind after 9.18.2 Fix from $1,9502022-05-19 HIGH 7.5 CVE-2022-0635 Versions affected: BIND 9.18.0 When a vulnerable version of named receives a series of specific queries, the named process will eventually terminate … Bind Mitigation only Fix from $1,9502022-03-23 HIGH 7.5 CVE-2022-0667 When the vulnerability is triggered the BIND process will exit. BIND 9.18.0 Bind No fix yet Fix from $1,9502022-03-22 HIGH 7.5 CVE-2018-5742 While backporting a feature for a newer branch of BIND9, RedHat introduced a path leading to an assertion failure in buffer.c:420. Affects RedHat ver… Bind after 9.9.4-72 Fix from $1,9502019-10-30 HIGH 7.5 CVE-2019-6475 Mirror zones are a BIND feature allowing recursive servers to pre-cache zone data provided by other servers. A mirror zone is similar to a zone of ty… Bind after 9.15.4 Fix from $1,9502019-10-17 HIGH 7.5 CVE-2019-6476 A defect in code added to support QNAME minimization can cause named to exit with an assertion failure if a forwarder returns a referral rather than … Bind after 9.15.4 Fix from $1,9502019-10-17 MEDIUM 6.5 CVE-2019-6472 A packet containing a malformed DUID can cause the Kea DHCPv6 server process (kea-dhcp6) to exit due to an assertion failure. Versions affected: 1.4.… Kea after 1.5.0 Fix from $1,6002019-10-16 MEDIUM 6.5 CVE-2019-6474 A missing check on incoming client requests can be exploited to cause a situation where the Kea server's lease storage contains leases which are reje… Kea after 1.5.0 Fix from $1,6002019-10-16 HIGH 7.5 CVE-2019-6469 An error in the EDNS Client Subnet (ECS) feature for recursive resolvers can cause BIND to exit with an assertion failure when processing a response … Bind Mitigation only Fix from $1,9502019-10-09 HIGH 7.5 CVE-2019-6467EPSS 5% A programming error in the nxdomain-redirect feature can cause an assertion failure in query.c if the alternate namespace used by nxdomain-redirect i… Bind after 9.13.7 Fix from $1,9502019-10-09