Skip to main content

Vendor/product archive

isc / bind CVEs

Beta · best-effort

178 CVEs tagged to isc / bind6 Critical, 90 High, 77 Medium, 5 Low, 0 Unrated.

CVE-2020-8616

Published May 19, 2020

A malicious actor who intentionally exploits this lack of effective limitation on the number of fetches performed when processing referrals can, through the use of specially craft…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2019-6477

Published Nov 26, 2019

With pipelining enabled each incoming query on a TCP connection requires a similar resource allocation to a query received via UDP or via TCP without pipelining enabled. A client…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-5742

Published Oct 30, 2019

While backporting a feature for a newer branch of BIND9, RedHat introduced a path leading to an assertion failure in buffer.c:420. Affects RedHat versions bind-9.9.4-65.el7 -> bin…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-6476

Published Oct 17, 2019

A defect in code added to support QNAME minimization can cause named to exit with an assertion failure if a forwarder returns a referral rather than resolving the query. This affe…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-6475

Published Oct 17, 2019

Mirror zones are a BIND feature allowing recursive servers to pre-cache zone data provided by other servers. A mirror zone is similar to a zone of type secondary, except that its…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-6469

Published Oct 9, 2019

An error in the EDNS Client Subnet (ECS) feature for recursive resolvers can cause BIND to exit with an assertion failure when processing a response that has malformed RRSIGs. Ver…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-6468

Published Oct 9, 2019

In BIND Supported Preview Edition, an error in the nxdomain-redirect feature can occur in versions which support EDNS Client Subnet (ECS) features. In those versions which have EC…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-6467

Published Oct 9, 2019

A programming error in the nxdomain-redirect feature can cause an assertion failure in query.c if the alternate namespace used by nxdomain-redirect is a descendant of a zone that…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-6465

Published Oct 9, 2019

Controls for zone transfers may not be properly applied to Dynamically Loadable Zones (DLZs) if the zones are writable Versions affected: BIND 9.9.0 -> 9.10.8-P1, 9.11.0 -> 9.11.5…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-5745

Published Oct 9, 2019

"managed-keys" is a feature which allows a BIND resolver to automatically maintain the keys used by trust anchors which operators configure for use in DNSSEC validation. Due to an…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-5744

Published Oct 9, 2019

A failure to free memory can occur when processing messages having a specific combination of EDNS options. Versions affected are: BIND 9.10.7 -> 9.10.8-P1, 9.11.3 -> 9.11.5-P1, 9.…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-5741

Published Jan 16, 2019

To provide fine-grained controls over the ability to use Dynamic DNS (DDNS) to update records in a zone, BIND 9 provides a feature called update-policy. Various rules can be confi…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-5740

Published Jan 16, 2019

"deny-answer-aliases" is a little-used feature intended to help recursive server operators protect end users against DNS rebinding attacks, a potential method of circumventing the…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5

CVE-2018-5738

Published Jan 16, 2019

Change #4777 (introduced in October 2017) introduced an unforeseen issue in releases which were issued after that date, affecting which clients are permitted to make recursive que…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-3143

Published Jan 16, 2019

An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSIG key name for the zone and service being targeted may be a…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2017-3142

Published Jan 16, 2019

An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSIG key name may be able to circumvent TSIG authentication of…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2017-3141

Published Jan 16, 2019

The BIND installer on Windows uses an unquoted service path which can enable a local user to achieve privilege escalation if the host file system permissions allow this. Affects B…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 51-75 of 178 CVEsPage 3 of 8