Isc Bind vulnerabilities
189 known vulnerabilities affecting isc/bind.
Total CVEs
189
CISA KEV
0
Public exploits
15
Exploited in wild
2
Severity breakdown
CRITICAL8HIGH98MEDIUM77LOW6
Vulnerabilities
Page 6 of 10
CVE-2015-8705HIGHCVSS 7.0v9.0v9.0.1+33 more2016-01-20
CVE-2015-8705 [HIGH] CWE-20 CVE-2015-8705: buffer.c in named in ISC BIND 9.10.x before 9.10.3-P3, when debug logging is enabled, allows remote
buffer.c in named in ISC BIND 9.10.x before 9.10.3-P3, when debug logging is enabled, allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit, or daemon crash) or possibly have unspecified other impact via (1) OPT data or (2) an ECS option.
nvd
CVE-2015-8704MEDIUMCVSS 6.5v9.0v9.0.1+33 more2016-01-20
CVE-2015-8704 [MEDIUM] CWE-20 CVE-2015-8704: apl_42.c in ISC BIND 9.x before 9.9.8-P3, 9.9.x, and 9.10.x before 9.10.3-P3 allows remote authentic
apl_42.c in ISC BIND 9.x before 9.9.8-P3, 9.9.x, and 9.10.x before 9.10.3-P3 allows remote authenticated users to cause a denial of service (INSIST assertion failure and daemon exit) via a malformed Address Prefix List (APL) record.
nvd
CVE-2015-8461HIGHCVSS 7.1v8.4.7v9.0+62 more2015-12-16
CVE-2015-8461 [HIGH] CWE-362 CVE-2015-8461: Race condition in resolver.c in named in ISC BIND 9.9.8 before 9.9.8-P2 and 9.10.3 before 9.10.3-P2
Race condition in resolver.c in named in ISC BIND 9.9.8 before 9.9.8-P2 and 9.10.3 before 9.10.3-P2 allows remote attackers to cause a denial of service (INSIST assertion failure and daemon exit) via unspecified vectors.
nvd
CVE-2015-8000MEDIUMCVSS 5.0v8.4.7v9.0+62 more2015-12-16
CVE-2015-8000 [MEDIUM] CWE-20 CVE-2015-8000: db.c in named in ISC BIND 9.x before 9.9.8-P2 and 9.10.x before 9.10.3-P2 allows remote attackers to
db.c in named in ISC BIND 9.x before 9.9.8-P2 and 9.10.x before 9.10.3-P2 allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via a malformed class attribute.
nvd
CVE-2015-5722HIGHCVSS 7.8≤ 9.9.7≤ 9.10.22015-09-05
CVE-2015-5722 [HIGH] CWE-20 CVE-2015-5722: buffer.c in named in ISC BIND 9.x before 9.9.7-P3 and 9.10.x before 9.10.2-P4 allows remote attacker
buffer.c in named in ISC BIND 9.x before 9.9.7-P3 and 9.10.x before 9.10.2-P4 allows remote attackers to cause a denial of service (assertion failure and daemon exit) by creating a zone containing a malformed DNSSEC key and issuing a query for a name in that zone.
nvd
CVE-2015-5986HIGHCVSS 7.1≤ 9.9.7≤ 9.10.22015-09-05
CVE-2015-5986 [HIGH] CWE-20 CVE-2015-5986: openpgpkey_61.c in named in ISC BIND 9.9.7 before 9.9.7-P3 and 9.10.x before 9.10.2-P4 allows remote
openpgpkey_61.c in named in ISC BIND 9.9.7 before 9.9.7-P3 and 9.10.x before 9.10.2-P4 allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via a crafted DNS response.
nvd
CVE-2015-5477HIGHCVSS 7.8PoC≤ 9.9.7≤ 9.10.22015-07-29
CVE-2015-5477 [HIGH] CWE-19 CVE-2015-5477: named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via TKEY queries.
nvd
CVE-2015-4620HIGHCVSS 7.8v9.7.0v9.7.1+24 more2015-07-08
CVE-2015-4620 [HIGH] CWE-17 CVE-2015-4620: name.c in named in ISC BIND 9.7.x through 9.9.x before 9.9.7-P1 and 9.10.x before 9.10.2-P2, when co
name.c in named in ISC BIND 9.7.x through 9.9.x before 9.9.7-P1 and 9.10.x before 9.10.2-P2, when configured as a recursive resolver with DNSSEC validation, allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) by constructing crafted zone data and then making a query for a name in that zone.
nvd
CVE-2015-1349MEDIUMCVSS 5.4v9.7.0v9.7.1+24 more2015-02-19
CVE-2015-1349 [MEDIUM] CWE-399 CVE-2015-1349: named in ISC BIND 9.7.0 through 9.9.6 before 9.9.6-P2 and 9.10.x before 9.10.1-P2, when DNSSEC valid
named in ISC BIND 9.7.0 through 9.9.6 before 9.9.6-P2 and 9.10.x before 9.10.1-P2, when DNSSEC validation and the managed-keys feature are enabled, allows remote attackers to cause a denial of service (assertion failure and daemon exit, or daemon crash) by triggering an incorrect trust-anchor management scenario in which no key is ready for use.
nvd
CVE-2014-8500HIGHCVSS 7.8v9.0v9.0.1+61 more2014-12-11
CVE-2014-8500 [HIGH] CWE-399 CVE-2014-8500: ISC BIND 9.0.x through 9.8.x, 9.9.0 through 9.9.6, and 9.10.0 through 9.10.1 does not limit delegati
ISC BIND 9.0.x through 9.8.x, 9.9.0 through 9.9.6, and 9.10.0 through 9.10.1 does not limit delegation chaining, which allows remote attackers to cause a denial of service (memory consumption and named crash) via a large or infinite number of referrals.
nvd
CVE-2014-8680MEDIUMCVSS 5.4v9.10.0v9.10.12014-12-11
CVE-2014-8680 [MEDIUM] CWE-20 CVE-2014-8680: The GeoIP functionality in ISC BIND 9.10.0 through 9.10.1 allows remote attackers to cause a denial
The GeoIP functionality in ISC BIND 9.10.0 through 9.10.1 allows remote attackers to cause a denial of service (assertion failure and named exit) via vectors related to (1) the lack of GeoIP databases for both IPv4 and IPv6, or (2) IPv6 support with certain options.
nvd
CVE-2014-3859MEDIUMCVSS 5.0v9.10.02014-06-13
CVE-2014-3859 [MEDIUM] CWE-20 CVE-2014-3859: libdns in ISC BIND 9.10.0 before P2 does not properly handle EDNS options, which allows remote attac
libdns in ISC BIND 9.10.0 before P2 does not properly handle EDNS options, which allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via a crafted packet, as demonstrated by an attack against named, dig, or delv.
nvd
CVE-2014-3214MEDIUMCVSS 5.0v9.10.02014-05-09
CVE-2014-3214 [MEDIUM] CWE-20 CVE-2014-3214: The prefetch implementation in named in ISC BIND 9.10.0, when a recursive nameserver is enabled, all
The prefetch implementation in named in ISC BIND 9.10.0, when a recursive nameserver is enabled, allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via a DNS query that triggers a response with unspecified attributes.
nvd
CVE-2014-0591LOWCVSS 2.6v9.6v9.6.0+19 more2014-01-14
CVE-2014-0591 [LOW] CWE-119 CVE-2014-0591: The query_findclosestnsec3 function in query.c in named in ISC BIND 9.6, 9.7, and 9.8 before 9.8.6-P
The query_findclosestnsec3 function in query.c in named in ISC BIND 9.6, 9.7, and 9.8 before 9.8.6-P2 and 9.9 before 9.9.4-P2, and 9.6-ESV before 9.6-ESV-R10-P2, allows remote attackers to cause a denial of service (INSIST assertion failure and daemon exit) via a crafted DNS query to an authoritative nameserver that uses the NSEC3 signing feature.
nvd
CVE-2013-6230MEDIUMCVSS 6.8v9.6v9.8.0+11 more2013-11-08
CVE-2013-6230 [MEDIUM] CWE-264 CVE-2013-6230: The Winsock WSAIoctl API in Microsoft Windows Server 2008, as used in ISC BIND 9.6-ESV before 9.6-ES
The Winsock WSAIoctl API in Microsoft Windows Server 2008, as used in ISC BIND 9.6-ESV before 9.6-ESV-R10-P1, 9.8 before 9.8.6-P1, 9.9 before 9.9.4-P1, 9.9.3-S1, 9.9.4-S1, and other products, does not properly support the SIO_GET_INTERFACE_LIST command for netmask 255.255.255.255, which allows remote attackers to bypass intended IP address restriction
nvd
CVE-2013-4854HIGHCVSS 7.8Exploitedv9.7.0v9.7.1+17 more2013-07-29
CVE-2013-4854 [HIGH] CVE-2013-4854: The RFC 5011 implementation in rdata.c in ISC BIND 9.7.x and 9.8.x before 9.8.5-P2, 9.8.6b1, 9.9.x b
The RFC 5011 implementation in rdata.c in ISC BIND 9.7.x and 9.8.x before 9.8.5-P2, 9.8.6b1, 9.9.x before 9.9.3-P2, and 9.9.4b1, and DNSco BIND 9.9.3-S1 before 9.9.3-S1-P1 and 9.9.4-S1b1, allows remote attackers to cause a denial of service (assertion failure and named daemon exit) via a query with a malformed RDATA section that is not properly handled during c
nvd
CVE-2013-3919HIGHCVSS 7.8v9.6v9.8.5+1 more2013-06-06
CVE-2013-3919 [HIGH] CVE-2013-3919: resolver.c in ISC BIND 9.8.5 before 9.8.5-P1, 9.9.3 before 9.9.3-P1, and 9.6-ESV-R9 before 9.6-ESV-R
resolver.c in ISC BIND 9.8.5 before 9.8.5-P1, 9.9.3 before 9.9.3-P1, and 9.6-ESV-R9 before 9.6-ESV-R9-P1, when a recursive resolver is configured, allows remote attackers to cause a denial of service (assertion failure and named daemon exit) via a query for a record in a malformed zone.
nvd
CVE-2013-2266HIGHCVSS 7.8v9.9.0v9.9.1+15 more2013-03-28
CVE-2013-2266 [HIGH] CWE-119 CVE-2013-2266: libdns in ISC BIND 9.7.x and 9.8.x before 9.8.4-P2, 9.8.5 before 9.8.5b2, 9.9.x before 9.9.2-P2, and
libdns in ISC BIND 9.7.x and 9.8.x before 9.8.4-P2, 9.8.5 before 9.8.5b2, 9.9.x before 9.9.2-P2, and 9.9.3 before 9.9.3b2 on UNIX platforms allows remote attackers to cause a denial of service (memory consumption) via a crafted regular expression, as demonstrated by a memory-exhaustion attack against a machine running a named process.
nvd
CVE-2012-5689HIGHCVSS 7.1v9.9.0v9.9.1+6 more2013-01-25
CVE-2012-5689 [HIGH] CWE-20 CVE-2012-5689: ISC BIND 9.8.x through 9.8.4-P1 and 9.9.x through 9.9.2-P1, in certain configurations involving DNS6
ISC BIND 9.8.x through 9.8.4-P1 and 9.9.x through 9.9.2-P1, in certain configurations involving DNS64 with a Response Policy Zone that lacks an AAAA rewrite rule, allows remote attackers to cause a denial of service (assertion failure and named daemon exit) via a query for an AAAA record.
nvd
CVE-2012-5688HIGHCVSS 7.8v9.8.0v9.8.1+4 more2012-12-06
CVE-2012-5688 [HIGH] CWE-20 CVE-2012-5688: ISC BIND 9.8.x before 9.8.4-P1 and 9.9.x before 9.9.2-P1, when DNS64 is enabled, allows remote attac
ISC BIND 9.8.x before 9.8.4-P1 and 9.9.x before 9.9.2-P1, when DNS64 is enabled, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted query.
nvd