Vulnerability index

Browse CVEs

129 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2019-6468 In BIND Supported Preview Edition, an error in the nxdomain-redirect feature can occur in versions which support EDNS Client Subnet (ECS) features. I… Bind Mitigation only Fix from $1,9502019-10-09 HIGH 7.5 CVE-2018-5732 Failure to properly bounds-check a buffer used for processing DHCP options allows a malicious server (or an entity masquerading as a server) to cause… Dhcp 4.2.8 / 4.3.6+ Fix from $1,9502019-10-09 HIGH 7.5 CVE-2018-5744 A failure to free memory can occur when processing messages having a specific combination of EDNS options. Versions affected are: BIND 9.10.7 -> 9.10… Bind 9.10.8 / 9.11.5+ Fix from $1,9502019-10-09 MEDIUM 6.5 CVE-2018-5741 To provide fine-grained controls over the ability to use Dynamic DNS (DDNS) to update records in a zone, BIND 9 provides a feature called update-poli… Bind 9.11.5 / 9.12.3+ Fix from $1,6002019-01-16 HIGH 7.8 CVE-2017-3141 The BIND installer on Windows uses an unquoted service path which can enable a local user to achieve privilege escalation if the host file system per… Bind after 9.11.1 Fix from $1,9502019-01-16 HIGH 7.5 CVE-2018-5734EPSS 6% While handling a particular type of malformed packet BIND erroneously selects a SERVFAIL rcode instead of a FORMERR rcode. If the receiving view has … Bind Mitigation only Fix from $1,9502019-01-16 HIGH 7.5 CVE-2018-5737EPSS 10% A problem with the implementation of the new serve-stale feature in BIND 9.12 can lead to an assertion failure in rbtdb.c, even when stale-answer-ena… Bind Mitigation only Fix from $1,9502019-01-16 HIGH 7.5 CVE-2018-5739 An extension to hooks capabilities which debuted in Kea 1.4.0 introduced a memory leak for operators who are using certain hooks library facilities. … Kea Mitigation only Fix from $1,9502019-01-16 MEDIUM 5.9 CVE-2016-9778EPSS 7% An error in handling certain queries can cause an assertion failure when a server is using the nxdomain-redirect feature to cover a zone for which it… Bind Mitigation only Fix from $1,6002019-01-16 MEDIUM 5.9 CVE-2017-3140EPSS 12% If named is configured to use Response Policy Zones (RPZ) an error processing some rule types can lead to a condition where BIND will endlessly loop … Bind after 9.11.1 Fix from $1,6002019-01-16 MEDIUM 5.3 CVE-2018-5736EPSS 18% An error in zone database reference counting can lead to an assertion failure if a server which is running an affected version of BIND attempts sever… Bind Mitigation only Fix from $1,6002019-01-16 HIGH 7.5 CVE-2016-9147EPSS 25% named in ISC BIND 9.9.9-P4, 9.9.9-S6, 9.10.4-P4, and 9.11.0-P1 allows remote attackers to cause a denial of service (assertion failure and daemon exi… Bind Patch available Fix from $1,9502017-01-12 HIGH 7.5 CVE-2016-9444EPSS 18% named in ISC BIND 9.x before 9.9.9-P5, 9.10.x before 9.10.4-P5, and 9.11.x before 9.11.0-P2 allows remote attackers to cause a denial of service (ass… Bind Patch available Fix from $1,9502017-01-12 HIGH 7.5 CVE-2016-2848EPSS 26% ISC BIND 9.1.0 through 9.8.4-P2 and 9.9.0 through 9.9.2-P2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) v… Bind Mitigation only Fix from $1,9502016-10-21 MEDIUM 6.8 CVE-2016-2088EPSS 23% resolver.c in named in ISC BIND 9.10.x before 9.10.3-P4, when DNS cookies are enabled, allows remote attackers to cause a denial of service (INSIST a… Bind Mitigation only Fix from $1,6002016-03-09 MEDIUM 5.9 CVE-2016-1284 rdataset.c in ISC BIND 9 Supported Preview Edition 9.9.8-S before 9.9.8-S5, when nxdomain-redirect is enabled, allows remote attackers to cause a den… Bind Mitigation only Fix from $1,6002016-02-04 HIGH 7.0 CVE-2015-8705EPSS 8% buffer.c in named in ISC BIND 9.10.x before 9.10.3-P3, when debug logging is enabled, allows remote attackers to cause a denial of service (REQUIRE a… Bind Mitigation only Fix from $1,9502016-01-20 MEDIUM 6.5 CVE-2015-8704EPSS 20% apl_42.c in ISC BIND 9.x before 9.9.8-P3, 9.9.x, and 9.10.x before 9.10.3-P3 allows remote authenticated users to cause a denial of service (INSIST a… Bind Mitigation only Fix from $1,6002016-01-20 MEDIUM 6.8 CVE-2015-8373 The kea-dhcp4 and kea-dhcp6 servers 0.9.2 and 1.0.0-beta in ISC Kea, when certain debugging settings are used, allow remote attackers to cause a deni… Kea Mitigation only Fix from $1,6002015-12-22 HIGH 7.1 CVE-2015-8461 Race condition in resolver.c in named in ISC BIND 9.9.8 before 9.9.8-P2 and 9.10.3 before 9.10.3-P2 allows remote attackers to cause a denial of serv… Bind Mitigation only Fix from $1,9502015-12-16 HIGH 7.1 CVE-2015-5986EPSS 26% openpgpkey_61.c in named in ISC BIND 9.9.7 before 9.9.7-P3 and 9.10.x before 9.10.2-P4 allows remote attackers to cause a denial of service (REQUIRE … Bind after 9.10.2 Fix from $1,9502015-09-05 HIGH 7.8 CVE-2015-5722EPSS 34% buffer.c in named in ISC BIND 9.x before 9.9.7-P3 and 9.10.x before 9.10.2-P4 allows remote attackers to cause a denial of service (assertion failure… Bind after 9.10.2 Fix from $1,9502015-09-05 HIGH 7.8 CVE-2015-5477EPSS 91% named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (REQUIRE assertion failure and… Bind after 9.10.2 Fix from $1,9502015-07-29 HIGH 7.8 CVE-2015-4620EPSS 38% name.c in named in ISC BIND 9.7.x through 9.9.x before 9.9.7-P1 and 9.10.x before 9.10.2-P2, when configured as a recursive resolver with DNSSEC vali… Bind Mitigation only Fix from $1,9502015-07-08 MEDIUM 5.4 CVE-2015-1349EPSS 22% named in ISC BIND 9.7.0 through 9.9.6 before 9.9.6-P2 and 9.10.x before 9.10.1-P2, when DNSSEC validation and the managed-keys feature are enabled, a… Bind Mitigation only Fix from $1,6002015-02-19 MEDIUM 5.4 CVE-2014-8680EPSS 9% The GeoIP functionality in ISC BIND 9.10.0 through 9.10.1 allows remote attackers to cause a denial of service (assertion failure and named exit) via… Bind Mitigation only Fix from $1,6002014-12-11 HIGH 7.8 CVE-2014-8500EPSS 58% ISC BIND 9.0.x through 9.8.x, 9.9.0 through 9.9.6, and 9.10.0 through 9.10.1 does not limit delegation chaining, which allows remote attackers to cau… Bind Patch available Fix from $1,9502014-12-11 MEDIUM 5.0 CVE-2014-3859EPSS 7% libdns in ISC BIND 9.10.0 before P2 does not properly handle EDNS options, which allows remote attackers to cause a denial of service (REQUIRE assert… Bind Mitigation only Fix from $1,6002014-06-13 MEDIUM 5.0 CVE-2014-3214EPSS 17% The prefetch implementation in named in ISC BIND 9.10.0, when a recursive nameserver is enabled, allows remote attackers to cause a denial of service… Bind Mitigation only Fix from $1,6002014-05-09 MEDIUM 6.8 CVE-2013-6230EPSS 6% The Winsock WSAIoctl API in Microsoft Windows Server 2008, as used in ISC BIND 9.6-ESV before 9.6-ESV-R10-P1, 9.8 before 9.8.6-P1, 9.9 before 9.9.4-P… Bind Mitigation only Fix from $1,6002013-11-08