Skip to main content

CVE detail

CVE-2002-0029

Buffer overflows in the DNS stub resolver library in ISC BIND 4.9.2 through 4.9.10, and other derived libraries such as BSD libc and GNU glibc, allow remote attackers to execute arbitrary code via DNS server responses that trigger the overflow in the (1) getnetbyname, or (2) getnetbyaddr functions, aka "LIBRESOLV: buffer overrun" and a different vulnerability than CVE-2002-0684.

CVSS 7.5 · HighBuzz score 4.01 OTX pulses

Buzz score

Why this CVE is surfacing

Buzz score total 4.0

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 0.0 · diversity 0.0 · KEV 0.0 · OTX 4.0 · PoC 0.0
Mention score
0.0
0 evidence mentions in the snapshot
Diversity score
0.0
0 sources across 0 categories
KEV score
0.0
No KEV entry observed
OTX score
4.0
1 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
0 source links · newest first

    Exploit code

    Public exploit repository references

    Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

    0 repository references · best confidence N/A · max 0 stars
    No public PoC repositories have been matched yet.

    Related records

    Similar CVEs

    6 related CVEs with shared weakness or product evidence
    • CVE-2026-5950

      An unbounded resend loop vulnerability exists in the BIND 9 resolver state machine during bad-server handling, enabling a remote unauthenticated attacker to cause severe resource…

      CVSS 5.3 · Medium
      5 mentions
    • CVE-2026-5947

      Undefined behavior may result due to a race condition leading to a use-after-free violation. If BIND receives an incoming DNS message signed with SIG(0), it begins work to valida…

      CVSS 7.5 · High
    • CVE-2026-5946

      Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS is not Internet (`IN`) — for example, `CHAOS` or `HESIOD`, or DNS messages that…

      CVSS 7.5 · High
    • CVE-2026-3593

      A use-after-free vulnerability exists within the DNS-over-HTTPS implementation. This issue affects BIND 9 versions 9.20.0 through 9.20.22, 9.21.0 through 9.21.21, and 9.20.9-S1 th…

      CVSS 7.4 · High
      8 mentions
    • CVE-2026-3592

      BIND resolvers are vulnerable to an amplified resource consumption/exhaustion attack. If a victim resolver makes a query to a specially crafted zone, the resolver will consume di…

      CVSS 5.3 · Medium
      5 mentions
    • CVE-2026-3039

      BIND servers that are configured to use TKEY-based authentication via GSS-API tokens are vulnerable to excessive memory consumption when receiving and processing maliciously-const…

      CVSS 7.5 · High
      14 mentions