Skip to main content

Vendor/product archive

isc / bind CVEs

Beta · best-effort

178 CVEs tagged to isc / bind6 Critical, 90 High, 77 Medium, 5 Low, 0 Unrated.

CVE-2006-0987

Published Mar 3, 2006

The default configuration of ISC BIND before 9.4.1-P1, when configured as a caching name server, allows recursive queries and provides additional delegation information to arbitra…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0527

Published Feb 2, 2006

BIND 4 (BIND4) and BIND 8 (BIND8), if used as a target forwarder, allows remote attackers to gain privileged access via a "Kashpureff-style DNS cache corruption" attack.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-0033

Published May 2, 2005

Buffer overflow in the code for recursion and glue fetching in BIND 8.4.4 and 8.4.5 allows remote attackers to cause a denial of service (crash) via queries that trigger the overf…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0034

Published May 2, 2005

An "incorrect assumption" in the authvalidated validator function in BIND 9.3.0, when DNSSEC is enabled, allows remote attackers to cause a denial of service (named server exit) v…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-2211

Published Dec 31, 2002

BIND 4 and BIND 8, when resolving recursive DNS queries for arbitrary hosts, allows remote attackers to conduct DNS cache poisoning via a birthday attack that uses a large number…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-2212

Published Dec 31, 2002

The DNS resolver in unspecified versions of Fujitsu UXP/V, when resolving recursive DNS queries for arbitrary hosts, allows remote attackers to conduct DNS cache poisoning via a b…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-2213

Published Dec 31, 2002

The DNS resolver in unspecified versions of Infoblox DNS One, when resolving recursive DNS queries for arbitrary hosts, allows remote attackers to conduct DNS cache poisoning via…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-0029

Published Nov 29, 2002

Buffer overflows in the DNS stub resolver library in ISC BIND 4.9.2 through 4.9.10, and other derived libraries such as BSD libc and GNU glibc, allow remote attackers to execute a…

CVSS 7.5 · High
Buzz score
4.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-2002-1219

Published Nov 29, 2002

Buffer overflow in named in BIND 4 versions 4.9.10 and earlier, and 8 versions 8.3.3 and earlier, allows remote attackers to execute arbitrary code via a certain DNS server respon…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2002-1220

Published Nov 29, 2002

BIND 8.3.x through 8.3.3 allows remote attackers to cause a denial of service (termination due to assertion failure) via a request for a subdomain that does not exist, with an OPT…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-1221

Published Nov 29, 2002

BIND 8.x through 8.3.3 allows remote attackers to cause a denial of service (crash) via SIG RR elements with invalid expiry times, which are removed from the internal BIND databas…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-0684

Published Aug 12, 2002

Buffer overflow in DNS resolver functions that perform lookup of network names and addresses, as used in BIND 4.9.8 and ported to glibc 2.2.5 and earlier, allows remote malicious…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2002-0651

Published Jul 3, 2002

Buffer overflow in the DNS resolver code used in libc, glibc, and libbind, as derived from ISC BIND, allows remote malicious DNS servers to cause a denial of service and possibly…

CVSS 7.5 · High
Buzz score
4.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-2002-0400

Published Jun 18, 2002

ISC BIND 9 before 9.2.1 allows remote attackers to cause a denial of service (shutdown) via a malformed DNS packet that triggers an error condition that is not properly handled wh…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-0497

Published Jul 21, 2001

dnskeygen in BIND 8.2.4 and earlier, and dnssec-keygen in BIND 9.1.2 and earlier, set insecure permissions for a HMAC-MD5 shared secret key file used for DNS Transactional Signatu…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2001-0010

Published Feb 12, 2001

Buffer overflow in transaction signature (TSIG) handling code in BIND 8 allows remote attackers to gain root privileges.

CVSS 10.0 · Critical
Buzz score
4.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-2001-0011

Published Feb 12, 2001

Buffer overflow in nslookupComplain function in BIND 4 allows remote attackers to gain root privileges.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2001-0012

Published Feb 12, 2001

BIND 4 and BIND 8 allow remote attackers to access sensitive information such as environment variables.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-0013

Published Feb 12, 2001

Format string vulnerability in nslookupComplain function in BIND 4 allows remote attackers to gain root privileges.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2000-0887

Published Dec 19, 2000

named in BIND 8.2 through 8.2.2-P6 allows remote attackers to cause a denial of service by making a compressed zone transfer (ZXFR) request and performing a name service query on…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-0888

Published Dec 19, 2000

named in BIND 8.2 through 8.2.2-P6 allows remote attackers to cause a denial of service by sending an SRV record to the server, aka the "srv bug."

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-1029

Published Dec 11, 2000

Buffer overflow in host command allows a remote attacker to execute arbitrary commands via a long response to an AXFR query.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2000-0335

Published May 3, 2000

The resolver in glibc 2.1.3 uses predictable IDs, which allows a local attacker to spoof DNS query results.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 151-175 of 178 CVEsPage 7 of 8