Debian Bind9 vulnerabilities
127 known vulnerabilities affecting debian/bind9.
Total CVEs
127
CISA KEV
0
Public exploits
7
Exploited in wild
4
Severity breakdown
HIGH73MEDIUM35LOW19
Vulnerabilities
Page 7 of 7
CVE-2010-3762P4MEDIUMCVSS 4.3fixed in bind9 1:9.7.2.dfsg.P2-1 (bookworm)2010
CVE-2010-3762 [MEDIUM] CVE-2010-3762: bind9 - ISC BIND before 9.7.2-P2, when DNSSEC validation is enabled, does not properly h...
ISC BIND before 9.7.2-P2, when DNSSEC validation is enabled, does not properly handle certain bad signatures if multiple trust anchors exist for a single zone, which allows remote attackers to cause a denial of service (daemon crash) via a DNS query.
Scope: local
bookworm: resolved (fixed in 1:9.7.2.dfsg.P2-1)
bullseye: resolved (fixed in 1:9.7.2.dfsg.P2-1)
forky: res
debian
CVE-2011-1907P4MEDIUMCVSS 5.0fixed in bind9 1:9.8.1.dfsg.P1-1 (bookworm)2011
CVE-2011-1907 [MEDIUM] CVE-2011-1907: bind9 - ISC BIND 9.8.x before 9.8.0-P1, when Response Policy Zones (RPZ) RRset replaceme...
ISC BIND 9.8.x before 9.8.0-P1, when Response Policy Zones (RPZ) RRset replacement is enabled, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via an RRSIG query.
Scope: local
bookworm: resolved (fixed in 1:9.8.1.dfsg.P1-1)
bullseye: resolved (fixed in 1:9.8.1.dfsg.P1-1)
forky: resolved (fixed in 1:9.8.1.dfsg.P1-1)
sid: resolve
debian
CVE-2006-2073P4LOWCVSS 5.0fixed in bind9 1:9.3.3-1 (bookworm)2006
CVE-2006-2073 [MEDIUM] CVE-2006-2073: bind9 - Unspecified vulnerability in ISC BIND allows remote attackers to cause a denial ...
Unspecified vulnerability in ISC BIND allows remote attackers to cause a denial of service via a crafted DNS message with a "broken" TSIG, as demonstrated by the OUSPG PROTOS DNS test suite.
Scope: local
bookworm: resolved (fixed in 1:9.3.3-1)
bullseye: resolved (fixed in 1:9.3.3-1)
forky: resolved (fixed in 1:9.3.3-1)
sid: resolved (fixed in 1:9.3.3-1)
trixie: resolv
debian
CVE-2005-0034P4MEDIUMCVSS 4.3fixed in bind9 1:9.3.1 (bookworm)2005
CVE-2005-0034 [MEDIUM] CVE-2005-0034: bind9 - An "incorrect assumption" in the authvalidated validator function in BIND 9.3.0,...
An "incorrect assumption" in the authvalidated validator function in BIND 9.3.0, when DNSSEC is enabled, allows remote attackers to cause a denial of service (named server exit) via crafted DNS packets that cause an internal consistency test (self-check) to fail.
Scope: local
bookworm: resolved (fixed in 1:9.3.1)
bullseye: resolved (fixed in 1:9.3.1)
forky: resolved (
debian
CVE-2009-4022P4MEDIUMCVSS 2.6fixed in bind9 1:9.6.1.dfsg.P2-1 (bookworm)2009
CVE-2009-4022 [LOW] CVE-2009-4022: bind9 - Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P4, ...
Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P4, 9.5 before 9.5.2-P1, 9.6 before 9.6.1-P2, and 9.7 beta before 9.7.0b3, with DNSSEC validation enabled and checking disabled (CD), allows remote attackers to conduct DNS cache poisoning attacks by receiving a recursive client query and sending a response that contains an Additional section wit
debian
CVE-2011-2465P4LOWCVSS 2.6fixed in bind9 1:9.8.1.dfsg.P1-1 (bookworm)2011
CVE-2011-2465 [LOW] CVE-2011-2465: bind9 - Unspecified vulnerability in ISC BIND 9 9.8.0, 9.8.0-P1, 9.8.0-P2, and 9.8.1b1, ...
Unspecified vulnerability in ISC BIND 9 9.8.0, 9.8.0-P1, 9.8.0-P2, and 9.8.1b1, when recursion is enabled and the Response Policy Zone (RPZ) contains DNAME or certain CNAME records, allows remote attackers to cause a denial of service (named daemon crash) via an unspecified query.
Scope: local
bookworm: resolved (fixed in 1:9.8.1.dfsg.P1-1)
bullseye: resolved (fixed in 1
debian
CVE-2010-0213P4LOWCVSS 2.6fixed in bind9 9.7.1.dfsg.P2 (bookworm)2010
CVE-2010-0213 [LOW] CVE-2010-0213: bind9 - BIND 9.7.1 and 9.7.1-P1, when a recursive validating server has a trust anchor t...
BIND 9.7.1 and 9.7.1-P1, when a recursive validating server has a trust anchor that is configured statically or via DNSSEC Lookaside Validation (DLV), allows remote attackers to cause a denial of service (infinite loop) via a query for an RRSIG record whose answer is not in the cache, which causes BIND to repeatedly send RRSIG queries to the authoritative servers.
Scope:
debian
← Previous7 / 7