VendorsISCbindall versions
Vulnerabilities

ISC BIND

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

184CVEs
CVE-2016-2848
ISC BIND 9.1.0 through 9.8.4-P2 and 9.9.0 through 9.9.2-P2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via malformed options data in an OPT resource record.
Published 2016-10-21 · Modified
7.5EPSS 0.258
CVE-2016-9147
named in ISC BIND 9.9.9-P4, 9.9.9-S6, 9.10.4-P4, and 9.11.0-P1 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a response containing an inconsistency among the DNSSEC-related RRsets.
Published 2017-01-12 · Modified
7.5EPSS 0.248
CVE-2022-3488
named may terminate unexpectedly when processing ECS options in repeated responses to iterative queries
Published 2023-01-25 · Modified
7.5EPSS 0.192
CVE-2017-3143
An error in TSIG authentication can permit unauthorized dynamic updates
Published 2019-01-16 · Modified
7.5EPSS 0.183
CVE-2016-9444
named in ISC BIND 9.x before 9.9.9-P5, 9.10.x before 9.10.4-P5, and 9.11.x before 9.11.0-P2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted DS resource record in an answer.
Published 2017-01-12 · Modified
7.5EPSS 0.183
CVE-2017-3135
Combination of DNS64 and RPZ Can Lead to Crash
Published 2019-01-16 · Modified
7.5EPSS 0.172
CVE-2022-3924
named configured to answer from stale cache may terminate unexpectedly at recursive-clients soft quota
Published 2023-01-25 · Modified
7.5EPSS 0.161
CVE-2002-0651
Buffer overflow in the DNS resolver code used in libc, glibc, and libbind, as derived from ISC BIND, allows remote malicious DNS servers to cause a denial of service and possibly execute arbitrary code via the stub resolvers.
Published 2004-09-01 · Modified
7.5EPSS 0.135
CVE-2022-3094
An UPDATE message flood may cause named to exhaust all available memory
Published 2023-01-25 · Modified
7.5EPSS 0.132
CVE-2002-1219
Buffer overflow in named in BIND 4 versions 4.9.10 and earlier, and 8 versions 8.3.3 and earlier, allows remote attackers to execute arbitrary code via a certain DNS server response containing SIG resource records (RR).
Published 2004-09-01 · Modified
7.5EPSS 0.123
CVE-2006-4095
BIND before 9.2.6-P1 and 9.3.x before 9.3.2-P1 allows remote attackers to cause a denial of service (crash) via certain SIG queries, which cause an assertion failure when multiple RRsets are returned.
Published 2006-09-06 · Modified
7.5EPSS 0.118
CVE-2021-25215
An assertion check can fail while answering queries for DNAME records that require the DNAME to be processed to resolve itself
Published 2021-04-29 · Modified
7.5EPSS 0.114
CVE-2018-5738
Some versions of BIND can improperly permit recursive query service to unauthorized clients
Published 2019-01-16 · Modified
7.5EPSS 0.112
CVE-2018-5737
BIND 9.12's serve-stale implementation can cause an assertion failure in rbtdb.c or other undesirable behavior, even if serve-stale is not enabled.
Published 2019-01-16 · Modified
7.5EPSS 0.104
CVE-2002-0029
Buffer overflows in the DNS stub resolver library in ISC BIND 4.9.2 through 4.9.10, and other derived libraries such as BSD libc and GNU glibc, allow remote attackers to execute arbitrary code via DNS server responses that trigger the overflow in the (1) getnetbyname, or (2) getnetbyaddr functions, aka "LIBRESOLV: buffer overrun" and a different vulnerability than CVE-2002-0684.
Published 2002-11-21 · Modified
7.5EPSS 0.099
CVE-2017-3137
A response packet can cause a resolver to terminate when processing an answer containing a CNAME or DNAME
Published 2019-01-16 · Modified
7.5EPSS 0.090
CVE-2006-0527
BIND 4 (BIND4) and BIND 8 (BIND8), if used as a target forwarder, allows remote attackers to gain privileged access via a "Kashpureff-style DNS cache corruption" attack.
Published 2006-02-02 · Modified
7.5EPSS 0.082
CVE-2016-9778
An error handling certain queries using the nxdomain-redirect feature could cause a REQUIRE assertion failure in db.c
Published 2019-01-16 · Modified
7.5EPSS 0.068
CVE-2018-5743
Limiting simultaneous TCP clients was ineffective
Published 2019-10-09 · Modified
7.5EPSS 0.065
CVE-2020-8623
A flaw in native PKCS#11 code can lead to a remotely triggerable assertion failure in pk11.c
Published 2020-08-21 · Modified
7.5EPSS 0.064
CVE-2018-5734
A malformed request can trigger an assertion failure in badcache.c
Published 2019-01-16 · Modified
7.5EPSS 0.063
CVE-2022-1183
Destroying a TLS session early causes assertion failure
Published 2022-05-19 · Modified
7.5EPSS 0.062
CVE-2002-0684
Buffer overflow in DNS resolver functions that perform lookup of network names and addresses, as used in BIND 4.9.8 and ported to glibc 2.2.5 and earlier, allows remote malicious DNS servers to execute arbitrary code through a subroutine used by functions such as getnetbyname and getnetbyaddr.
Published 2002-07-31 · Modified
7.5EPSS 0.059
CVE-2019-6467
An error in the nxdomain redirect feature can cause BIND to exit with an INSIST assertion failure in query.c
Published 2019-10-09 · Modified
7.5EPSS 0.055
CVE-2019-6477
TCP-pipelined queries can bypass tcp-clients limit
Published 2019-11-26 · Modified
7.5EPSS 0.041
CVE-2023-2828
named's configured cache size limit can be significantly exceeded
Published 2023-06-21 · Modified
7.5EPSS 0.038
CVE-2020-8620
In BIND 9.15.6 -> 9.16.5, 9.17.0 -> 9.17.3, An attacker who can establish a TCP connection with the server and send data on that connection can exploit this to trigger the assertion failure, causing the server to exit.
Published 2020-08-21 · Modified
7.5EPSS 0.037
CVE-2021-25218
A too-strict assertion check could be triggered when responses in BIND 9.16.19 and 9.17.16 require UDP fragmentation if RRL is in use
Published 2021-08-18 · Modified
7.5EPSS 0.036
CVE-2018-5744
A specially crafted packet can cause named to leak memory
Published 2019-10-09 · Modified
7.5EPSS 0.034
CVE-2022-38177
Memory leak in ECDSA DNSSEC verification code
Published 2022-09-21 · Modified
7.5EPSS 0.032
CVE-2022-38178
Memory leaks in EdDSA DNSSEC verification code
Published 2022-09-21 · Modified
7.5EPSS 0.030
CVE-2020-8621
Attempting QNAME minimization after forwarding can lead to an assertion failure in resolver.c
Published 2020-08-21 · Modified
7.5EPSS 0.030
CVE-2019-6476
An error in QNAME minimization code can cause BIND to exit with an assertion failure
Published 2019-10-17 · Modified
7.5EPSS 0.029
CVE-2023-3341
A stack exhaustion flaw in control channel code may cause named to terminate unexpectedly
Published 2023-09-20 · Modified
7.5EPSS 0.029
CVE-2019-6468
BIND Supported Preview Edition can exit with an assertion failure if nxdomain-redirect is used
Published 2019-10-09 · Modified
7.5EPSS 0.026
CVE-2009-0265
Internet Systems Consortium (ISC) BIND 9.6.0 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077 and CVE-2009-0025.
Published 2009-01-26 · Modified
7.5EPSS 0.025
CVE-2023-2911
Exceeding the recursive-clients quota may cause named to terminate unexpectedly when stale-answer-client-timeout is set to 0
Published 2023-06-21 · Modified
7.5EPSS 0.025
CVE-2026-3039
BIND 9 server memory exhaustion during GSS-API TKEY negotiation
Published 2026-05-20 · Modified
7.5EPSS 0.023
CVE-2023-4236
named may terminate unexpectedly under high DNS-over-TLS query load
Published 2023-09-20 · Modified
7.5EPSS 0.022
CVE-1999-0833
Buffer overflow in BIND 8.2 via NXT records.
Published 2000-01-04 · Modified
7.5EPSS 0.021
← Prev2 / 5Next →