VendorsISCbindany version
Vulnerabilities

ISC BIND any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

82CVEs
CVE-2023-4236
named may terminate unexpectedly under high DNS-over-TLS query load
Published 2023-09-20 · Modified
7.5EPSS 0.023
CVE-2026-3039
BIND 9 server memory exhaustion during GSS-API TKEY negotiation
Published 2026-05-20 · Modified
7.5EPSS 0.023
CVE-2022-2906
Memory leaks in code handling Diffie-Hellman key exchange via TKEY RRs (OpenSSL 3.0.0+ only)
Published 2022-09-21 · Modified
7.5EPSS 0.021
CVE-2022-3080
BIND 9 resolvers configured to answer from stale cache with zero stale-answer-client-timeout may terminate unexpectedly
Published 2022-09-21 · Modified
7.5EPSS 0.019
CVE-2026-5946
Invalid handling of CLASS != IN
Published 2026-05-20 · Modified
7.5EPSS 0.017
CVE-2026-1519
Excessive NSEC3 iterations cause high CPU load during insecure delegation validation
Published 2026-03-25 · Modified
7.5EPSS 0.016
CVE-2018-5742
An oversight while backporting a feature leads to an assertion failure in buffer.c:420
Published 2019-10-30 · Modified
7.5EPSS 0.016
CVE-2023-4408
Parsing large DNS messages may cause excessive CPU load
Published 2024-02-13 · Modified
7.5EPSS 0.013
CVE-2019-6475
A flaw in mirror zone validity checking can allow zone data to be spoofed
Published 2019-10-17 · Modified
7.5EPSS 0.013
CVE-2023-5517
Querying RFC 1918 reverse zones may cause an assertion failure when "nxdomain-redirect" is enabled
Published 2024-02-13 · Modified
7.5EPSS 0.012
CVE-2023-5679
Enabling both DNS64 and serve-stale may cause an assertion failure during recursive resolution
Published 2024-02-13 · Modified
7.5EPSS 0.012
CVE-2026-3104
Memory leak in code preparing DNSSEC proofs of non-existence
Published 2026-03-25 · Modified
7.5EPSS 0.012
CVE-2023-6516
Specific recursive query patterns may lead to an out-of-memory condition
Published 2024-02-13 · Modified
7.5EPSS 0.011
CVE-2023-2829
Malformed NSEC records can cause named to terminate unexpectedly when synth-from-dnssec is enabled
Published 2023-06-21 · Modified
7.5EPSS 0.009
CVE-2026-5947
SIG(0) validation during query flood may lead to undefined behavior
Published 2026-05-20 · Modified
7.5EPSS 0.008
CVE-2015-5986
openpgpkey_61.c in named in ISC BIND 9.9.7 before 9.9.7-P3 and 9.10.x before 9.10.2-P4 allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via a crafted DNS response.
Published 2015-09-05 · Modified
7.1EPSS 0.261
CVE-2016-1285
named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 does not properly handle DNAME records when parsing fetch reply messages, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed packet to the rndc (aka control channel) interface, related to alist.c and sexpr.c.
Published 2016-03-09 · Modified
6.8EPSS 0.591
CVE-2021-25220
DNS forwarders - cache poisoning vulnerability
Published 2022-03-23 · Modified
6.8EPSS 0.034
CVE-2016-6170
ISC BIND through 9.9.9-P1, 9.10.x through 9.10.4-P1, and 9.11.x through 9.11.0b1 allows primary DNS servers to cause a denial of service (secondary DNS server crash) via a large AXFR response, and possibly allows IXFR servers to cause a denial of service (IXFR client crash) via a large IXFR response and allows remote authenticated users to cause a denial of service (primary DNS server crash) via a large UPDATE message.
Published 2016-07-06 · Modified
6.5EPSS 0.409
CVE-2021-25214
A broken inbound incremental zone update (IXFR) can cause named to terminate unexpectedly
Published 2021-04-29 · Modified
6.5EPSS 0.060
CVE-2020-8622
A truncated TSIG response can lead to an assertion failure
Published 2020-08-21 · Modified
6.5EPSS 0.056
CVE-2018-5741
Update policies krb5-subdomain and ms-subdomain do not enforce controls promised in their documentation
Published 2019-01-16 · Modified
6.5EPSS 0.035
CVE-2026-3119
Authenticated query containing a TKEY record may cause named to terminate unexpectedly
Published 2026-03-25 · Analyzed
6.5EPSS 0.006
CVE-2016-2775
ISC BIND 9.x before 9.9.9-P2, 9.10.x before 9.10.4-P2, and 9.11.x before 9.11.0b2, when lwresd or the named lwres option is enabled, allows remote attackers to cause a denial of service (daemon crash) via a long request that uses the lightweight resolver protocol.
Published 2016-07-19 · Modified
5.9EPSS 0.633
CVE-2017-3140
An error processing RPZ rules can cause named to loop endlessly after handling a query
Published 2019-01-16 · Modified
5.9EPSS 0.122
CVE-2017-3136
An error handling synthesized records could cause an assertion failure when using DNS64 with "break-dnssec yes;"
Published 2019-01-16 · Modified
5.9EPSS 0.112
CVE-2013-5661
Cache Poisoning issue exists in DNS Response Rate Limiting.
Published 2019-11-05 · Modified
5.9EPSS 0.035
CVE-2019-6471
A race condition when discarding malformed packets can cause BIND to exit with an assertion failure
Published 2019-10-09 · Modified
5.9EPSS 0.033
CVE-2026-3591
A stack use-after-return flaw in SIG(0) handling code may enable ACL bypass
Published 2026-03-25 · Analyzed
5.4EPSS 0.003
CVE-2021-25219
Lame cache can be abused to severely degrade resolver performance
Published 2021-10-27 · Modified
5.3EPSS 0.106
CVE-2017-3142
An error in TSIG authentication can permit unauthorized zone transfers
Published 2019-01-16 · Modified
5.3EPSS 0.054
CVE-2019-6465
Zone transfer controls for writable DLZ zones were not effective
Published 2019-10-09 · Modified
5.3EPSS 0.037
CVE-2022-0396
DoS from specifically crafted TCP packets
Published 2022-03-23 · Modified
5.3EPSS 0.027
CVE-2022-2795
Processing large delegations may severely degrade resolver performance
Published 2022-09-21 · Modified
5.3EPSS 0.022
CVE-2026-5950
Unbounded resend loop in BIND 9 resolver
Published 2026-05-20 · Analyzed
5.3EPSS 0.008
CVE-2026-3592
Amplification vulnerabilities via self-pointed glue records
Published 2026-05-20 · Analyzed
5.3EPSS 0.006
CVE-2018-5745
An assertion failure can occur if a trust anchor rolls over to an unsupported key algorithm when using managed-keys
Published 2019-10-09 · Modified
4.9EPSS 0.023
CVE-2020-8619
A buffer boundary check assertion in rdataset.c can fail incorrectly during zone transfer
Published 2020-06-17 · Modified
4.9EPSS 0.021
CVE-2020-8618
A buffer boundary check assertion in rdataset.c can fail incorrectly during zone transfer
Published 2020-06-17 · Modified
4.9EPSS 0.018
CVE-2010-3762
ISC BIND before 9.7.2-P2, when DNSSEC validation is enabled, does not properly handle certain bad signatures if multiple trust anchors exist for a single zone, which allows remote attackers to cause a denial of service (daemon crash) via a DNS query.
Published 2010-10-05 · Modified
4.3EPSS 0.081
← Prev2 / 3Next →