Vulnerability index

Browse CVEs

54 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Bind MEDIUM 5.3
CVE-2023-5680

If a resolver cache has a very large number of ECS records stored for the same name, the process of cleaning the cache database node for this name ca…

Mitigation only
Fix from $1,600 2024-02-13
Bind HIGH 7.5
CVE-2022-3488EPSS 19%

Processing of repeated responses to the same query, where both responses contain ECS pseudo-options, but where the first is broken in some way, can c…

No fix yet
Fix from $1,950 2023-01-26
Bind HIGH 7.5
CVE-2022-0635

Versions affected: BIND 9.18.0 When a vulnerable version of named receives a series of specific queries, the named process will eventually terminate …

Mitigation only
Fix from $1,950 2022-03-23
Bind HIGH 7.5
CVE-2022-0667

When the vulnerability is triggered the BIND process will exit. BIND 9.18.0

No fix yet
Fix from $1,950 2022-03-22
Bind HIGH 7.5
CVE-2019-6469

An error in the EDNS Client Subnet (ECS) feature for recursive resolvers can cause BIND to exit with an assertion failure when processing a response …

Mitigation only
Fix from $1,950 2019-10-09
Bind HIGH 7.5
CVE-2019-6468

In BIND Supported Preview Edition, an error in the nxdomain-redirect feature can occur in versions which support EDNS Client Subnet (ECS) features. I…

Mitigation only
Fix from $1,950 2019-10-09
Bind HIGH 7.5
CVE-2018-5734EPSS 6%

While handling a particular type of malformed packet BIND erroneously selects a SERVFAIL rcode instead of a FORMERR rcode. If the receiving view has …

Mitigation only
Fix from $1,950 2019-01-16
Bind HIGH 7.5
CVE-2018-5737EPSS 10%

A problem with the implementation of the new serve-stale feature in BIND 9.12 can lead to an assertion failure in rbtdb.c, even when stale-answer-ena…

Mitigation only
Fix from $1,950 2019-01-16
Kea HIGH 7.5
CVE-2018-5739

An extension to hooks capabilities which debuted in Kea 1.4.0 introduced a memory leak for operators who are using certain hooks library facilities. …

Mitigation only
Fix from $1,950 2019-01-16
Bind MEDIUM 5.9
CVE-2016-9778EPSS 7%

An error in handling certain queries can cause an assertion failure when a server is using the nxdomain-redirect feature to cover a zone for which it…

Mitigation only
Fix from $1,600 2019-01-16
Bind MEDIUM 5.3
CVE-2018-5736EPSS 18%

An error in zone database reference counting can lead to an assertion failure if a server which is running an affected version of BIND attempts sever…

Mitigation only
Fix from $1,600 2019-01-16
Bind HIGH 7.5
CVE-2016-2848EPSS 26%

ISC BIND 9.1.0 through 9.8.4-P2 and 9.9.0 through 9.9.2-P2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) v…

Mitigation only
Fix from $1,950 2016-10-21
Bind MEDIUM 6.8
CVE-2016-2088EPSS 23%

resolver.c in named in ISC BIND 9.10.x before 9.10.3-P4, when DNS cookies are enabled, allows remote attackers to cause a denial of service (INSIST a…

Mitigation only
Fix from $1,600 2016-03-09
Bind MEDIUM 5.9
CVE-2016-1284

rdataset.c in ISC BIND 9 Supported Preview Edition 9.9.8-S before 9.9.8-S5, when nxdomain-redirect is enabled, allows remote attackers to cause a den…

Mitigation only
Fix from $1,600 2016-02-04
Bind HIGH 7.0
CVE-2015-8705EPSS 8%

buffer.c in named in ISC BIND 9.10.x before 9.10.3-P3, when debug logging is enabled, allows remote attackers to cause a denial of service (REQUIRE a…

Mitigation only
Fix from $1,950 2016-01-20
Bind MEDIUM 6.5
CVE-2015-8704EPSS 20%

apl_42.c in ISC BIND 9.x before 9.9.8-P3, 9.9.x, and 9.10.x before 9.10.3-P3 allows remote authenticated users to cause a denial of service (INSIST a…

Mitigation only
Fix from $1,600 2016-01-20
Kea MEDIUM 6.8
CVE-2015-8373

The kea-dhcp4 and kea-dhcp6 servers 0.9.2 and 1.0.0-beta in ISC Kea, when certain debugging settings are used, allow remote attackers to cause a deni…

Mitigation only
Fix from $1,600 2015-12-22
Bind HIGH 7.1
CVE-2015-8461

Race condition in resolver.c in named in ISC BIND 9.9.8 before 9.9.8-P2 and 9.10.3 before 9.10.3-P2 allows remote attackers to cause a denial of serv…

Mitigation only
Fix from $1,950 2015-12-16
Bind HIGH 7.8
CVE-2015-4620EPSS 38%

name.c in named in ISC BIND 9.7.x through 9.9.x before 9.9.7-P1 and 9.10.x before 9.10.2-P2, when configured as a recursive resolver with DNSSEC vali…

Mitigation only
Fix from $1,950 2015-07-08
Bind MEDIUM 5.4
CVE-2015-1349EPSS 22%

named in ISC BIND 9.7.0 through 9.9.6 before 9.9.6-P2 and 9.10.x before 9.10.1-P2, when DNSSEC validation and the managed-keys feature are enabled, a…

Mitigation only
Fix from $1,600 2015-02-19
Bind MEDIUM 5.4
CVE-2014-8680EPSS 9%

The GeoIP functionality in ISC BIND 9.10.0 through 9.10.1 allows remote attackers to cause a denial of service (assertion failure and named exit) via…

Mitigation only
Fix from $1,600 2014-12-11
Bind MEDIUM 5.0
CVE-2014-3859EPSS 7%

libdns in ISC BIND 9.10.0 before P2 does not properly handle EDNS options, which allows remote attackers to cause a denial of service (REQUIRE assert…

Mitigation only
Fix from $1,600 2014-06-13
Bind MEDIUM 5.0
CVE-2014-3214EPSS 17%

The prefetch implementation in named in ISC BIND 9.10.0, when a recursive nameserver is enabled, allows remote attackers to cause a denial of service…

Mitigation only
Fix from $1,600 2014-05-09
Bind MEDIUM 6.8
CVE-2013-6230EPSS 6%

The Winsock WSAIoctl API in Microsoft Windows Server 2008, as used in ISC BIND 9.6-ESV before 9.6-ESV-R10-P1, 9.8 before 9.8.6-P1, 9.9 before 9.9.4-P…

Mitigation only
Fix from $1,600 2013-11-08
Bind HIGH 7.8
CVE-2013-2266EPSS 43%

libdns in ISC BIND 9.7.x and 9.8.x before 9.8.4-P2, 9.8.5 before 9.8.5b2, 9.9.x before 9.9.2-P2, and 9.9.3 before 9.9.3b2 on UNIX platforms allows re…

Mitigation only
Fix from $1,950 2013-03-28
Bind HIGH 7.8
CVE-2012-5166EPSS 34%

ISC BIND 9.x before 9.7.6-P4, 9.8.x before 9.8.3-P4, 9.9.x before 9.9.1-P4, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P4 allows remote attackers to c…

Mitigation only
Fix from $1,950 2012-10-10
Bind HIGH 7.8
CVE-2012-4244EPSS 37%

ISC BIND 9.x before 9.7.6-P3, 9.8.x before 9.8.3-P3, 9.9.x before 9.9.1-P3, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P3 allows remote attackers to c…

Mitigation only
Fix from $1,950 2012-09-14
Bind HIGH 7.8
CVE-2012-3817EPSS 27%

ISC BIND 9.4.x, 9.5.x, 9.6.x, and 9.7.x before 9.7.6-P2; 9.8.x before 9.8.3-P2; 9.9.x before 9.9.1-P2; and 9.6-ESV before 9.6-ESV-R7-P2, when DNSSEC …

Mitigation only
Fix from $1,950 2012-07-25
Dhcp MEDIUM 5.7
CVE-2012-3570

Buffer overflow in ISC DHCP 4.2.x before 4.2.4-P1, when DHCPv6 mode is enabled, allows remote attackers to cause a denial of service (segmentation fa…

Mitigation only
Fix from $1,600 2012-07-25
Bind HIGH 8.5
CVE-2012-1667EPSS 13%

ISC BIND 9.x before 9.7.6-P1, 9.8.x before 9.8.3-P1, 9.9.x before 9.9.1-P1, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P1 does not properly handle res…

Mitigation only
Fix from $1,950 2012-06-05