VendorsISCbindall versions
Vulnerabilities

ISC BIND

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

184CVEs
CVE-2022-2906
Memory leaks in code handling Diffie-Hellman key exchange via TKEY RRs (OpenSSL 3.0.0+ only)
Published 2022-09-21 · Modified
7.5EPSS 0.021
CVE-2019-6469
BIND Supported Preview Edition can exit with an assertion failure if ECS is in use
Published 2019-10-09 · Modified
7.5EPSS 0.020
CVE-2022-3080
BIND 9 resolvers configured to answer from stale cache with zero stale-answer-client-timeout may terminate unexpectedly
Published 2022-09-21 · Modified
7.5EPSS 0.019
CVE-2026-5946
Invalid handling of CLASS != IN
Published 2026-05-20 · Modified
7.5EPSS 0.017
CVE-2026-1519
Excessive NSEC3 iterations cause high CPU load during insecure delegation validation
Published 2026-03-25 · Modified
7.5EPSS 0.016
CVE-2000-0335
The resolver in glibc 2.1.3 uses predictable IDs, which allows a local attacker to spoof DNS query results.
Published 2000-10-13 · Modified
7.5EPSS 0.016
CVE-2018-5742
An oversight while backporting a feature leads to an assertion failure in buffer.c:420
Published 2019-10-30 · Modified
7.5EPSS 0.016
CVE-2022-0635
Versions affected: BIND 9.18.0 When a vulnerable version of named receives a series of specific queries, the named process will eventually terminate due to a failed assertion check.
Published 2022-03-23 · Modified
7.5EPSS 0.013
CVE-2022-0667
Assertion failure on delayed DS lookup
Published 2022-03-22 · Modified
7.5EPSS 0.013
CVE-2023-4408
Parsing large DNS messages may cause excessive CPU load
Published 2024-02-13 · Modified
7.5EPSS 0.013
CVE-2019-6475
A flaw in mirror zone validity checking can allow zone data to be spoofed
Published 2019-10-17 · Modified
7.5EPSS 0.013
CVE-2023-5517
Querying RFC 1918 reverse zones may cause an assertion failure when "nxdomain-redirect" is enabled
Published 2024-02-13 · Modified
7.5EPSS 0.012
CVE-2023-5679
Enabling both DNS64 and serve-stale may cause an assertion failure during recursive resolution
Published 2024-02-13 · Modified
7.5EPSS 0.012
CVE-2026-3104
Memory leak in code preparing DNSSEC proofs of non-existence
Published 2026-03-25 · Modified
7.5EPSS 0.012
CVE-2023-6516
Specific recursive query patterns may lead to an out-of-memory condition
Published 2024-02-13 · Modified
7.5EPSS 0.011
CVE-2023-2829
Malformed NSEC records can cause named to terminate unexpectedly when synth-from-dnssec is enabled
Published 2023-06-21 · Modified
7.5EPSS 0.009
CVE-2026-5947
SIG(0) validation during query flood may lead to undefined behavior
Published 2026-05-20 · Modified
7.5EPSS 0.008
CVE-2015-5986
openpgpkey_61.c in named in ISC BIND 9.9.7 before 9.9.7-P3 and 9.10.x before 9.10.2-P4 allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via a crafted DNS response.
Published 2015-09-05 · Modified
7.1EPSS 0.261
CVE-2011-0414
ISC BIND 9.7.1 through 9.7.2-P3, when configured as an authoritative server, allows remote attackers to cause a denial of service (deadlock and daemon hang) by sending a query at the time of (1) an IXFR transfer or (2) a DDNS update.
Published 2011-02-23 · Modified
7.1EPSS 0.136
CVE-2012-5689
ISC BIND 9.8.x through 9.8.4-P1 and 9.9.x through 9.9.2-P1, in certain configurations involving DNS64 with a Response Policy Zone that lacks an AAAA rewrite rule, allows remote attackers to cause a denial of service (assertion failure and named daemon exit) via a query for an AAAA record.
Published 2013-01-25 · Modified
7.1EPSS 0.120
CVE-2007-2241
Unspecified vulnerability in query.c in ISC BIND 9.4.0, and 9.5.0a1 through 9.5.0a3, when recursion is enabled, allows remote attackers to cause a denial of service (daemon exit) via a sequence of queries processed by the query_addsoa function.
Published 2007-05-02 · Modified
7.1EPSS 0.076
CVE-2015-8461
Race condition in resolver.c in named in ISC BIND 9.9.8 before 9.9.8-P2 and 9.10.3 before 9.10.3-P2 allows remote attackers to cause a denial of service (INSIST assertion failure and daemon exit) via unspecified vectors.
Published 2015-12-16 · Modified
7.1EPSS 0.048
CVE-2015-8705
buffer.c in named in ISC BIND 9.10.x before 9.10.3-P3, when debug logging is enabled, allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit, or daemon crash) or possibly have unspecified other impact via (1) OPT data or (2) an ECS option.
Published 2016-01-20 · Modified
7.0EPSS 0.077
CVE-2008-1447
The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2; and other implementations allow remote attackers to spoof DNS traffic via a birthday attack that uses in-bailiwick referrals to conduct cache poisoning against recursive resolvers, related to insufficient randomness of DNS transaction IDs and source ports, aka "DNS Insufficient Socket Entropy Vulnerability" or "the Kaminsky bug."
Published 2008-07-08 · Modified
6.83 PoCEPSS 0.952
CVE-2016-1285
named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 does not properly handle DNAME records when parsing fetch reply messages, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed packet to the rndc (aka control channel) interface, related to alist.c and sexpr.c.
Published 2016-03-09 · Modified
6.8EPSS 0.591
CVE-2016-2088
resolver.c in named in ISC BIND 9.10.x before 9.10.3-P4, when DNS cookies are enabled, allows remote attackers to cause a denial of service (INSIST assertion failure and daemon exit) via a malformed packet with more than one cookie option.
Published 2016-03-09 · Modified
6.8EPSS 0.228
CVE-2015-8704
apl_42.c in ISC BIND 9.x before 9.9.8-P3, 9.9.x, and 9.10.x before 9.10.3-P3 allows remote authenticated users to cause a denial of service (INSIST assertion failure and daemon exit) via a malformed Address Prefix List (APL) record.
Published 2016-01-20 · Modified
6.8EPSS 0.203
CVE-2009-0025
BIND 9.6.0, 9.5.1, 9.5.0, 9.4.3, and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.
Published 2009-01-07 · Modified
6.8EPSS 0.069
CVE-2013-6230
The Winsock WSAIoctl API in Microsoft Windows Server 2008, as used in ISC BIND 9.6-ESV before 9.6-ESV-R10-P1, 9.8 before 9.8.6-P1, 9.9 before 9.9.4-P1, 9.9.3-S1, 9.9.4-S1, and other products, does not properly support the SIO_GET_INTERFACE_LIST command for netmask 255.255.255.255, which allows remote attackers to bypass intended IP address restrictions by leveraging misinterpretation of this netmask as a 0.0.0.0 netmask.
Published 2013-11-08 · Modified
6.8EPSS 0.057
CVE-2021-25220
DNS forwarders - cache poisoning vulnerability
Published 2022-03-23 · Modified
6.8EPSS 0.034
CVE-2016-6170
ISC BIND through 9.9.9-P1, 9.10.x through 9.10.4-P1, and 9.11.x through 9.11.0b1 allows primary DNS servers to cause a denial of service (secondary DNS server crash) via a large AXFR response, and possibly allows IXFR servers to cause a denial of service (IXFR client crash) via a large IXFR response and allows remote authenticated users to cause a denial of service (primary DNS server crash) via a large UPDATE message.
Published 2016-07-06 · Modified
6.5EPSS 0.409
CVE-2021-25214
A broken inbound incremental zone update (IXFR) can cause named to terminate unexpectedly
Published 2021-04-29 · Modified
6.5EPSS 0.060
CVE-2020-8622
A truncated TSIG response can lead to an assertion failure
Published 2020-08-21 · Modified
6.5EPSS 0.056
CVE-2017-3138
named exits with a REQUIRE assertion failure if it receives a null command string on its control channel
Published 2019-01-16 · Modified
6.5EPSS 0.055
CVE-2018-5741
Update policies krb5-subdomain and ms-subdomain do not enforce controls promised in their documentation
Published 2019-01-16 · Modified
6.5EPSS 0.035
CVE-2026-3119
Authenticated query containing a TKEY record may cause named to terminate unexpectedly
Published 2026-03-25 · Analyzed
6.5EPSS 0.006
CVE-2010-3614
named in ISC BIND 9.x before 9.6.2-P3, 9.7.x before 9.7.2-P3, 9.4-ESV before 9.4-ESV-R4, and 9.6-ESV before 9.6-ESV-R3 does not properly determine the security status of an NS RRset during a DNSKEY algorithm rollover, which might allow remote attackers to cause a denial of service (DNSSEC validation error) by triggering a rollover.
Published 2010-12-03 · Modified
6.4EPSS 0.145
CVE-1999-0184
When compiled with the -DALLOW_UPDATES option, bind allows dynamic updates to the DNS server, allowing for malicious modification of DNS records.
Published 1999-09-29 · Modified
6.4EPSS 0.019
CVE-2016-2775
ISC BIND 9.x before 9.9.9-P2, 9.10.x before 9.10.4-P2, and 9.11.x before 9.11.0b2, when lwresd or the named lwres option is enabled, allows remote attackers to cause a denial of service (daemon crash) via a long request that uses the lightweight resolver protocol.
Published 2016-07-19 · Modified
5.9EPSS 0.633
CVE-2017-3140
An error processing RPZ rules can cause named to loop endlessly after handling a query
Published 2019-01-16 · Modified
5.9EPSS 0.122
← Prev3 / 5Next →