VendorsISCbind8.2.1
Vulnerabilities

ISC BIND 8.2.1

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

13CVEs
CVE-2001-0010
Buffer overflow in transaction signature (TSIG) handling code in BIND 8 allows remote attackers to gain root privileges.
Published 2001-05-07 · Modified
10.04 PoCEPSS 0.316
CVE-1999-0837
Denial of service in BIND by improperly closing TCP sessions via so_linger.
Published 2000-01-04 · Modified
10.0EPSS 0.027
CVE-2002-1219
Buffer overflow in named in BIND 4 versions 4.9.10 and earlier, and 8 versions 8.3.3 and earlier, allows remote attackers to execute arbitrary code via a certain DNS server response containing SIG resource records (RR).
Published 2004-09-01 · Modified
7.5EPSS 0.123
CVE-1999-0833
Buffer overflow in BIND 8.2 via NXT records.
Published 2000-01-04 · Modified
7.5EPSS 0.021
CVE-2000-0335
The resolver in glibc 2.1.3 uses predictable IDs, which allows a local attacker to spoof DNS query results.
Published 2000-10-13 · Modified
7.5EPSS 0.016
CVE-2002-2211
BIND 4 and BIND 8, when resolving recursive DNS queries for arbitrary hosts, allows remote attackers to conduct DNS cache poisoning via a birthday attack that uses a large number of open queries for the same resource record (RR) combined with spoofed responses, which increases the possibility of successfully spoofing a response in a way that is more efficient than brute force methods.
Published 2006-05-23 · Modified
5.0EPSS 0.083
CVE-2002-1221
BIND 8.x through 8.3.3 allows remote attackers to cause a denial of service (crash) via SIG RR elements with invalid expiry times, which are removed from the internal BIND database and later cause a null dereference.
Published 2004-09-01 · Modified
5.0EPSS 0.076
CVE-2000-0888
named in BIND 8.2 through 8.2.2-P6 allows remote attackers to cause a denial of service by sending an SRV record to the server, aka the "srv bug."
Published 2001-01-22 · Modified
5.0EPSS 0.075
CVE-1999-0848
Denial of service in BIND named via consuming more than "fdmax" file descriptors.
Published 2000-01-04 · Modified
5.01 PoCEPSS 0.064
CVE-2001-0012
BIND 4 and BIND 8 allow remote attackers to access sensitive information such as environment variables.
Published 2001-05-07 · Modified
5.0EPSS 0.035
CVE-1999-0849
Denial of service in BIND named via maxdname.
Published 2000-01-04 · Modified
5.0EPSS 0.026
CVE-2002-2212
The DNS resolver in unspecified versions of Fujitsu UXP/V, when resolving recursive DNS queries for arbitrary hosts, allows remote attackers to conduct DNS cache poisoning via a birthday attack that uses a large number of open queries for the same resource record (RR) combined with spoofed responses, which increases the possibility of successfully spoofing a response in a way that is more efficient than brute force methods.
Published 2006-05-23 · Modified
5.0EPSS 0.024
CVE-2002-2213
The DNS resolver in unspecified versions of Infoblox DNS One, when resolving recursive DNS queries for arbitrary hosts, allows remote attackers to conduct DNS cache poisoning via a birthday attack that uses a large number of open queries for the same resource record (RR) combined with spoofed responses, which increases the possibility of successfully spoofing a response in a way that is more efficient than brute force methods.
Published 2006-05-23 · Modified
5.0EPSS 0.024