cbcvebase.

Debian Bind9 vulnerabilities

166 known vulnerabilities affecting debian/bind9.

Total CVEs
166
CISA KEV
0
Public exploits
9
Exploited in wild
2
Severity breakdown
HIGH73MEDIUM35LOW58

Vulnerabilities

Page 9 of 9
CVE-2005-0364LOWCVSS 5.02005
CVE-2005-0364 [MEDIUM] CVE-2005-0364: bind9 - Unknown vulnerability in BIND 9.2.0 in HP-UX B.11.00, B.11.11, and B.11.23 allow... Unknown vulnerability in BIND 9.2.0 in HP-UX B.11.00, B.11.11, and B.11.23 allows remote attackers to cause a denial of service. Scope: local bookworm: resolved bullseye: resolved forky: resolved sid: resolved trixie: resolved
debian
CVE-2002-1221LOWCVSS 5.02002
CVE-2002-1221 [MEDIUM] CVE-2002-1221: bind9 - BIND 8.x through 8.3.3 allows remote attackers to cause a denial of service (cra... BIND 8.x through 8.3.3 allows remote attackers to cause a denial of service (crash) via SIG RR elements with invalid expiry times, which are removed from the internal BIND database and later cause a null dereference. Scope: local bookworm: resolved bullseye: resolved forky: resolved sid: resolved trixie: resolved
debian
CVE-2002-2211LOWCVSS 5.02002
CVE-2002-2211 [MEDIUM] CVE-2002-2211: bind9 - BIND 4 and BIND 8, when resolving recursive DNS queries for arbitrary hosts, all... BIND 4 and BIND 8, when resolving recursive DNS queries for arbitrary hosts, allows remote attackers to conduct DNS cache poisoning via a birthday attack that uses a large number of open queries for the same resource record (RR) combined with spoofed responses, which increases the possibility of successfully spoofing a response in a way that is more efficient than bru
debian
CVE-2002-0029LOWCVSS 7.52002
CVE-2002-0029 [HIGH] CVE-2002-0029: bind9 - Buffer overflows in the DNS stub resolver library in ISC BIND 4.9.2 through 4.9.... Buffer overflows in the DNS stub resolver library in ISC BIND 4.9.2 through 4.9.10, and other derived libraries such as BSD libc and GNU glibc, allow remote attackers to execute arbitrary code via DNS server responses that trigger the overflow in the (1) getnetbyname, or (2) getnetbyaddr functions, aka "LIBRESOLV: buffer overrun" and a different vulnerability than CVE-2
debian
CVE-2002-1220LOWCVSS 5.0PoC2002
CVE-2002-1220 [MEDIUM] CVE-2002-1220: bind9 - BIND 8.3.x through 8.3.3 allows remote attackers to cause a denial of service (t... BIND 8.3.x through 8.3.3 allows remote attackers to cause a denial of service (termination due to assertion failure) via a request for a subdomain that does not exist, with an OPT resource record with a large UDP payload size. Scope: local bookworm: resolved bullseye: resolved forky: resolved sid: resolved trixie: resolved
debian
CVE-2002-1219LOWCVSS 7.52002
CVE-2002-1219 [HIGH] CVE-2002-1219: bind9 - Buffer overflow in named in BIND 4 versions 4.9.10 and earlier, and 8 versions 8... Buffer overflow in named in BIND 4 versions 4.9.10 and earlier, and 8 versions 8.3.3 and earlier, allows remote attackers to execute arbitrary code via a certain DNS server response containing SIG resource records (RR). Scope: local bookworm: resolved bullseye: resolved forky: resolved sid: resolved trixie: resolved
debian