Skip to main content

Vendor/product archive

isc / bind CVEs

Beta · best-effort

178 CVEs tagged to isc / bind6 Critical, 90 High, 77 Medium, 5 Low, 0 Unrated.

CVE-2010-3615

Published Dec 6, 2010

named in ISC BIND 9.7.2-P2 does not check all intended locations for allow-query ACLs, which might allow remote attackers to make successful requests for private DNS records via t…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3614

Published Dec 6, 2010

named in ISC BIND 9.x before 9.6.2-P3, 9.7.x before 9.7.2-P3, 9.4-ESV before 9.4-ESV-R4, and 9.6-ESV before 9.6-ESV-R3 does not properly determine the security status of an NS RRs…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3613

Published Dec 6, 2010

named in ISC BIND 9.6.2 before 9.6.2-P3, 9.6-ESV before 9.6-ESV-R3, and 9.7.x before 9.7.2-P3 does not properly handle the combination of signed negative responses and correspondi…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3762

Published Oct 5, 2010

ISC BIND before 9.7.2-P2, when DNSSEC validation is enabled, does not properly handle certain bad signatures if multiple trust anchors exist for a single zone, which allows remote…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0218

Published Oct 5, 2010

ISC BIND 9.7.2 through 9.7.2-P1 uses an incorrect ACL to restrict the ability of Recursion Desired (RD) queries to access the cache, which allows remote attackers to obtain potent…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0213

Published Jul 28, 2010

BIND 9.7.1 and 9.7.1-P1, when a recursive validating server has a trust anchor that is configured statically or via DNSSEC Lookaside Validation (DLV), allows remote attackers to c…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2010-0382

Published Jan 22, 2010

ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta handles out-of-bailiwick data accompanying a secure response without re…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2010-0290

Published Jan 22, 2010

Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta, with DNSSEC validation enabled and checki…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0097

Published Jan 22, 2010

ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta does not properly validate DNSSEC (1) NSEC and (2) NSEC3 records, which…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2009-4022

Published Nov 25, 2009

Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P4, 9.5 before 9.5.2-P1, 9.6 before 9.6.1-P2, and 9.7 beta before 9.7.0b3, with DNSSEC validation enabl…

CVSS 2.6 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2009-0696

Published Jul 29, 2009

The dns_db_findrdataset function in db.c in named in ISC BIND 9.4 before 9.4.3-P3, 9.5 before 9.5.1-P3, and 9.6 before 9.6.1-P1, when configured as a master server, allows remote…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0265

Published Jan 26, 2009

Internet Systems Consortium (ISC) BIND 9.6.0 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypas…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-0025

Published Jan 7, 2009

BIND 9.6.0, 9.5.1, 9.5.0, 9.4.3, and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attackers to bypass validation of t…

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2008-4163

Published Sep 22, 2008

Unspecified vulnerability in ISC BIND 9.3.5-P2-W1, 9.4.2-P2-W1, and 9.5.0-P2-W1 on Windows allows remote attackers to cause a denial of service (UDP client handler termination) vi…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0122

Published Jan 16, 2008

Off-by-one error in the inet_network function in libbind in ISC BIND 9.4.2 and earlier, as used in libc in FreeBSD 6.2 through 7.0-PRERELEASE, allows context-dependent attackers t…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-2930

Published Sep 12, 2007

The (1) NSID_SHUFFLE_ONLY and (2) NSID_USE_POOL PRNG algorithms in ISC BIND 8 before 8.4.7-P1 generate predictable DNS query identifiers when sending outgoing queries such as NOTI…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-2925

Published Jul 24, 2007

The default access control lists (ACL) in ISC BIND 9.4.0, 9.4.1, and 9.5.0a1 through 9.5.0a5 do not set the allow-recursion and allow-query-cache ACLs, which allows remote attacke…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-2926

Published Jul 24, 2007

ISC BIND 9 through 9.5.0a5 uses a weak random number generator during generation of DNS query ids when answering resolver questions or sending NOTIFY messages to slave name server…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-2241

Published May 2, 2007

Unspecified vulnerability in query.c in ISC BIND 9.4.0, and 9.5.0a1 through 9.5.0a3, when recursion is enabled, allows remote attackers to cause a denial of service (daemon exit)…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0493

Published Jan 25, 2007

Use-after-free vulnerability in ISC BIND 9.3.0 up to 9.3.3, 9.4.0a1 up to 9.4.0a6, 9.4.0b1 up to 9.4.0b4, 9.4.0rc1, and 9.5.0a1 (Bind Forum only) allows remote attackers to cause…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0494

Published Jan 25, 2007

ISC BIND 9.0.x, 9.1.x, 9.2.0 up to 9.2.7, 9.3.0 up to 9.3.3, 9.4.0a1 up to 9.4.0a6, 9.4.0b1 up to 9.4.0b4, 9.4.0rc1, and 9.5.0a1 (Bind Forum only) allows remote attackers to cause…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4096

Published Sep 6, 2006

BIND before 9.2.6-P1 and 9.3.x before 9.3.2-P1 allows remote attackers to cause a denial of service (crash) via a flood of recursive queries, which cause an INSIST failure when th…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-2073

Published Apr 27, 2006

Unspecified vulnerability in ISC BIND allows remote attackers to cause a denial of service via a crafted DNS message with a "broken" TSIG, as demonstrated by the OUSPG PROTOS DNS…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 126-150 of 178 CVEsPage 6 of 8