VendorsISCbind9.16.8
Vulnerabilities

ISC BIND 9.16.8

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

15CVEs
CVE-2021-25216
A second vulnerability in BIND's GSSAPI security policy negotiation can be targeted by a buffer overflow attack
Published 2021-04-29 · Modified
9.8EPSS 0.824
CVE-2020-8625
A vulnerability in BIND's GSSAPI security policy negotiation can be targeted by a buffer overflow attack
Published 2021-02-17 · Modified
8.1EPSS 0.642
CVE-2022-3488
named may terminate unexpectedly when processing ECS options in repeated responses to iterative queries
Published 2023-01-25 · Modified
7.5EPSS 0.192
CVE-2022-3094
An UPDATE message flood may cause named to exhaust all available memory
Published 2023-01-25 · Modified
7.5EPSS 0.132
CVE-2021-25215
An assertion check can fail while answering queries for DNAME records that require the DNAME to be processed to resolve itself
Published 2021-04-29 · Modified
7.5EPSS 0.114
CVE-2022-38177
Memory leak in ECDSA DNSSEC verification code
Published 2022-09-21 · Modified
7.5EPSS 0.032
CVE-2022-38178
Memory leaks in EdDSA DNSSEC verification code
Published 2022-09-21 · Modified
7.5EPSS 0.030
CVE-2023-3341
A stack exhaustion flaw in control channel code may cause named to terminate unexpectedly
Published 2023-09-20 · Modified
7.5EPSS 0.029
CVE-2023-4408
Parsing large DNS messages may cause excessive CPU load
Published 2024-02-13 · Modified
7.5EPSS 0.013
CVE-2023-5517
Querying RFC 1918 reverse zones may cause an assertion failure when "nxdomain-redirect" is enabled
Published 2024-02-13 · Modified
7.5EPSS 0.012
CVE-2023-6516
Specific recursive query patterns may lead to an out-of-memory condition
Published 2024-02-13 · Modified
7.5EPSS 0.011
CVE-2021-25214
A broken inbound incremental zone update (IXFR) can cause named to terminate unexpectedly
Published 2021-04-29 · Modified
6.5EPSS 0.060
CVE-2021-25219
Lame cache can be abused to severely degrade resolver performance
Published 2021-10-27 · Modified
5.3EPSS 0.106
CVE-2022-2795
Processing large delegations may severely degrade resolver performance
Published 2022-09-21 · Modified
5.3EPSS 0.022
CVE-2023-5680
Cleaning an ECS-enabled cache may cause excessive CPU load
Published 2024-02-13 · Modified
5.3EPSS 0.006