CVE-1999-0024
published 1997-08-13CVE-1999-0024: DNS cache poisoning via BIND, by predictable query IDs.
PriorityP416medium5CVSS 2.0
AVNACLAuNCNIPAN
EPSS
4.93%
91.2th percentile
DNS cache poisoning via BIND, by predictable query IDs.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| bsdi | bsd_os | — | — |
| bsdi | bsd_os | — | — |
| ibm | aix | — | — |
| ibm | aix | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| nec | asl_ux_4800 | — | — |
| nec | ews-ux_v | — | — |
| nec | ews-ux_v | — | — |
| nec | up-ux_v | — | — |
| sco | open_desktop | — | — |
| sco | openserver | — | — |
| sco | unix | — | — |
| sco | unixware | — | — |
| sun | solaris | — | — |
| sun | solaris | — | — |
| sun | solaris | — | — |
| sun | solaris | — | — |
| sun | sunos | — | — |
| sun | sunos | — | — |
| sun | sunos | — | — |
| sun | sunos | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
ISC BIND 4.9.5/8.1 Query ID improper authentication (Nessus ID 10539 / ID 15034)
vuldb·2026-04-17·CVSS 5.0
CVE-1999-0024 [MEDIUM] ISC BIND 4.9.5/8.1 Query ID improper authentication (Nessus ID 10539 / ID 15034)
A vulnerability was found in ISC BIND 4.9.5/8.1. It has been declared as critical. Impacted is an unknown function of the component Query ID Handler. Such manipulation leads to improper authentication.
This vulnerability is traded as CVE-1999-0024. The attack may be launched remotely. There is no exploit available. This vulnerability is historically impactful due to its background and the reception it garnered.
It is recommended to upgrade the affected component.
GHSA
GHSA-34jm-h6vm-gxqp: DNS cache poisoning via BIND, by predictable query IDs
ghsa_unreviewed·2022-04-30
CVE-1999-0024 [MEDIUM] GHSA-34jm-h6vm-gxqp: DNS cache poisoning via BIND, by predictable query IDs
DNS cache poisoning via BIND, by predictable query IDs.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
1997-08-13
Published