Isc Bind 9 vulnerabilities
68 known vulnerabilities affecting isc/bind_9.
Total CVEs
68
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH48MEDIUM18LOW1
Vulnerabilities
Page 4 of 4
CVE-2026-5950P4MEDIUMCVSS 5.3≥ 9.18.36, ≤ 9.18.48≥ 9.20.8, ≤ 9.20.22+3 more2026-05-20
CVE-2026-5950 [MEDIUM] CWE-606 CVE-2026-5950: An unbounded resend loop vulnerability exists in the BIND 9 resolver state machine during bad-server
An unbounded resend loop vulnerability exists in the BIND 9 resolver state machine during bad-server handling, enabling a remote unauthenticated attacker to cause severe resource exhaustion by sending queries that trigger specific retry conditions.
This issue affects BIND 9 versions 9.18.36 through 9.18.48, 9.20.8 through 9.20.22, 9.21.7 through 9.21.
nvd
CVE-2026-3591P4MEDIUMCVSS 5.4≥ 9.20.0, ≤ 9.20.20≥ 9.21.0, ≤ 9.21.19+1 more2026-03-25
CVE-2026-3591 [MEDIUM] CWE-305 CVE-2026-3591: A use-after-return vulnerability exists in the `named` server when handling DNS queries signed with
A use-after-return vulnerability exists in the `named` server when handling DNS queries signed with SIG(0). Using a specially-crafted DNS request, an attacker may be able to cause an ACL to improperly (mis)match an IP address. In a default-allow ACL (denying only specific IP addresses), this may lead to unauthorized access. Default-deny ACLs should fai
nvd
CVE-2019-6465P4MEDIUMCVSS 5.3vBIND 9.9.0 -> 9.10.8-P1, 9.11.0 -> 9.11.5-P2, 9.12.0 -> 9.12.3-P2, and versions 9.9.3-S1 -> 9.11.5-S3 of BIND 9 Supported Preview Edition. Versions 9.13.0 -> 9.13.6 of the 9.13 development branch are also affected. Versions prior to BIND 9.9.0 have not been evaluated for vulnerability to CVE-2019-6465.2019-10-09
CVE-2019-6465 [MEDIUM] CWE-732 CVE-2019-6465: Controls for zone transfers may not be properly applied to Dynamically Loadable Zones (DLZs) if the
Controls for zone transfers may not be properly applied to Dynamically Loadable Zones (DLZs) if the zones are writable Versions affected: BIND 9.9.0 -> 9.10.8-P1, 9.11.0 -> 9.11.5-P2, 9.12.0 -> 9.12.3-P2, and versions 9.9.3-S1 -> 9.11.5-S3 of BIND 9 Supported Preview Edition. Versions 9.13.0 -> 9.13.6 of the 9.13 development branch are also affected. V
nvd
CVE-2019-6471P4MEDIUMCVSS 5.9vBIND 9.11.0 -> 9.11.7, 9.12.0 -> 9.12.4-P1, 9.14.0 -> 9.14.2. Also all releases of the BIND 9.13 development branch and version 9.15.0 of the BIND 9.15 development branch and BIND Supported Preview Edition versions 9.11.3-S1 -> 9.11.7-S1.2019-10-09
CVE-2019-6471 [MEDIUM] CWE-362 CVE-2019-6471: A race condition which may occur when discarding malformed packets can result in BIND exiting due to
A race condition which may occur when discarding malformed packets can result in BIND exiting due to a REQUIRE assertion failure in dispatch.c. Versions affected: BIND 9.11.0 -> 9.11.7, 9.12.0 -> 9.12.4-P1, 9.14.0 -> 9.14.2. Also all releases of the BIND 9.13 development branch and version 9.15.0 of the BIND 9.15 development branch and BIND Supported
nvd
CVE-2026-3592P4MEDIUMCVSS 5.3≥ 9.11.0, ≤ 9.16.50≥ 9.18.0, ≤ 9.18.48+5 more2026-05-20
CVE-2026-3592 [MEDIUM] CWE-408 CVE-2026-3592: BIND resolvers are vulnerable to an amplified resource consumption/exhaustion attack. If a victim r
BIND resolvers are vulnerable to an amplified resource consumption/exhaustion attack. If a victim resolver makes a query to a specially crafted zone, the resolver will consume disproportionate resources.
This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.48, 9.20.0 through 9.20.22, 9.21.0 through 9.21.21, 9.11.3-S1 through 9
nvd
CVE-2023-5680P4MEDIUMCVSS 5.3≥ 9.11.3-S1, ≤ 9.11.37-S1≥ 9.16.8-S1, ≤ 9.16.45-S1+1 more2024-02-13
CVE-2023-5680 [MEDIUM] CVE-2023-5680: If a resolver cache has a very large number of ECS records stored for the same name, the process of
If a resolver cache has a very large number of ECS records stored for the same name, the process of cleaning the cache database node for this name can significantly impair query performance.
This issue affects BIND 9 versions 9.11.3-S1 through 9.11.37-S1, 9.16.8-S1 through 9.16.45-S1, and 9.18.11-S1 through 9.18.21-S1.
nvd
CVE-2018-5745P4MEDIUMCVSS 4.9vBIND 9.9.0 -> 9.10.8-P1, 9.11.0 -> 9.11.5-P1, 9.12.0 -> 9.12.3-P1, and versions 9.9.3-S1 -> 9.11.5-S3 of BIND 9 Supported Preview Edition. Versions 9.13.0 -> 9.13.6 of the 9.13 development branch are also affected. Versions prior to BIND 9.9.0 have not been evaluated for vulnerability to CVE-2018-5745.2019-10-09
CVE-2018-5745 [MEDIUM] CWE-327 CVE-2018-5745: "managed-keys" is a feature which allows a BIND resolver to automatically maintain the keys used by
"managed-keys" is a feature which allows a BIND resolver to automatically maintain the keys used by trust anchors which operators configure for use in DNSSEC validation. Due to an error in the managed-keys feature it is possible for a BIND server which uses managed-keys to exit due to an assertion failure if, during key rollover, a trust anchor's keys
nvd
CVE-2017-3142P4LOWCVSS 3.7v9.4.0->9.8.8, 9.9.0->9.9.10-P1, 9.10.0->9.10.5-P1, 9.11.0->9.11.1-P1, 9.9.3-S1->9.9.10-S2, 9.10.5-S1->9.10.5-S22019-01-16
CVE-2017-3142 [LOW] CWE-20 CVE-2017-3142: An attacker who is able to send and receive messages to an authoritative DNS server and who has know
An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSIG key name may be able to circumvent TSIG authentication of AXFR requests via a carefully constructed request packet. A server that relies solely on TSIG keys for protection with no other ACL protection could be manipulated into: providi
nvd
← Previous4 / 4