VendorsISCbind9.11.5
Vulnerabilities

ISC BIND 9.11.5

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

18CVEs
CVE-2021-25216
A second vulnerability in BIND's GSSAPI security policy negotiation can be targeted by a buffer overflow attack
Published 2021-04-29 · Modified
9.8EPSS 0.824
CVE-2020-8616
BIND does not sufficiently limit the number of fetches performed when processing referrals
Published 2020-05-19 · Modified
8.6EPSS 0.106
CVE-2020-8625
A vulnerability in BIND's GSSAPI security policy negotiation can be targeted by a buffer overflow attack
Published 2021-02-17 · Modified
8.1EPSS 0.642
CVE-2020-8617
A logic error in code which checks TSIG validity can be used to trigger an assertion failure in tsig.c
Published 2020-05-19 · Modified
7.51 PoCEPSS 0.934
CVE-2021-25215
An assertion check can fail while answering queries for DNAME records that require the DNAME to be processed to resolve itself
Published 2021-04-29 · Modified
7.5EPSS 0.114
CVE-2018-5743
Limiting simultaneous TCP clients was ineffective
Published 2019-10-09 · Modified
7.5EPSS 0.065
CVE-2019-6477
TCP-pipelined queries can bypass tcp-clients limit
Published 2019-11-26 · Modified
7.5EPSS 0.041
CVE-2018-5744
A specially crafted packet can cause named to leak memory
Published 2019-10-09 · Modified
7.5EPSS 0.034
CVE-2022-38177
Memory leak in ECDSA DNSSEC verification code
Published 2022-09-21 · Modified
7.5EPSS 0.032
CVE-2022-38178
Memory leaks in EdDSA DNSSEC verification code
Published 2022-09-21 · Modified
7.5EPSS 0.030
CVE-2023-3341
A stack exhaustion flaw in control channel code may cause named to terminate unexpectedly
Published 2023-09-20 · Modified
7.5EPSS 0.029
CVE-2019-6468
BIND Supported Preview Edition can exit with an assertion failure if nxdomain-redirect is used
Published 2019-10-09 · Modified
7.5EPSS 0.026
CVE-2021-25214
A broken inbound incremental zone update (IXFR) can cause named to terminate unexpectedly
Published 2021-04-29 · Modified
6.5EPSS 0.060
CVE-2021-25219
Lame cache can be abused to severely degrade resolver performance
Published 2021-10-27 · Modified
5.3EPSS 0.106
CVE-2019-6465
Zone transfer controls for writable DLZ zones were not effective
Published 2019-10-09 · Modified
5.3EPSS 0.037
CVE-2022-2795
Processing large delegations may severely degrade resolver performance
Published 2022-09-21 · Modified
5.3EPSS 0.022
CVE-2023-5680
Cleaning an ECS-enabled cache may cause excessive CPU load
Published 2024-02-13 · Modified
5.3EPSS 0.006
CVE-2018-5745
An assertion failure can occur if a trust anchor rolls over to an unsupported key algorithm when using managed-keys
Published 2019-10-09 · Modified
4.9EPSS 0.023