ISC / Bind
182 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-5950 | Unbounded resend loop in BIND 9 resolver | MEDIUM | 5.3 | May 20, 2026 |
| CVE-2026-5947 | SIG(0) validation during query flood may lead to undefined behavior | HIGH | 7.5 | May 20, 2026 |
| CVE-2026-5946 | Invalid handling of CLASS != IN | HIGH | 7.5 | May 20, 2026 |
| CVE-2026-3593 | Heap use-after-free vulnerability in BIND 9 DNS-over-HTTPS implementation | CRITICAL | 9.8 | May 20, 2026 |
| CVE-2026-3592 | Amplification vulnerabilities via self-pointed glue records | MEDIUM | 5.3 | May 20, 2026 |
| CVE-2026-3039 | BIND 9 server memory exhaustion during GSS-API TKEY negotiation | HIGH | 7.5 | May 20, 2026 |
| CVE-2026-3591 | A stack use-after-return flaw in SIG(0) handling code may enable ACL bypass | MEDIUM | 5.4 | Mar 25, 2026 |
| CVE-2026-3119 | Authenticated query containing a TKEY record may cause named to terminate unexpectedly | MEDIUM | 6.5 | Mar 25, 2026 |
| CVE-2026-3104 | Memory leak in code preparing DNSSEC proofs of non-existence | HIGH | 7.5 | Mar 25, 2026 |
| CVE-2026-1519 | Excessive NSEC3 iterations cause high CPU load during insecure delegation validation | HIGH | 7.5 | Mar 25, 2026 |
| CVE-2024-4076 | Assertion failure when serving both stale cache data and authoritative zone content | HIGH | 7.5 | Jul 23, 2024 |
| CVE-2024-1975 | SIG(0) can be used to exhaust CPU resources | HIGH | 7.5 | Jul 23, 2024 |
| CVE-2024-1737 | BIND's database will be slow if a very large number of RRs exist at the same name | HIGH | 7.5 | Jul 23, 2024 |
| CVE-2024-0760 | A flood of DNS messages over TCP may make the server unstable | HIGH | 7.5 | Jul 23, 2024 |
| CVE-2023-50868 | bind9: Preparing an NSEC3 closest encloser proof can exhaust CPU resources | HIGH | 7.5 | Feb 14, 2024 |
| CVE-2023-50387 | bind9: KeyTrap - Extreme CPU consumption in DNSSEC validator | HIGH | 7.5 | Feb 14, 2024 |
| CVE-2023-6516 | Specific recursive query patterns may lead to an out-of-memory condition | HIGH | 7.5 | Feb 13, 2024 |
| CVE-2023-5680 | Cleaning an ECS-enabled cache may cause excessive CPU load | MEDIUM | 5.3 | Feb 13, 2024 |
| CVE-2023-5679 | Enabling both DNS64 and serve-stale may cause an assertion failure during recursive resolution | HIGH | 7.5 | Feb 13, 2024 |
| CVE-2023-5517 | Querying RFC 1918 reverse zones may cause an assertion failure when "nxdomain-redirect" is enabled | HIGH | 7.5 | Feb 13, 2024 |
| CVE-2023-4408 | Parsing large DNS messages may cause excessive CPU load | HIGH | 7.5 | Feb 13, 2024 |
| CVE-2023-4236 | named may terminate unexpectedly under high DNS-over-TLS query load | HIGH | 7.5 | Sep 20, 2023 |
| CVE-2023-3341 | A stack exhaustion flaw in control channel code may cause named to terminate unexpectedly | HIGH | 7.5 | Sep 20, 2023 |
| CVE-2023-2911 | Exceeding the recursive-clients quota may cause named to terminate unexpectedly when stale-answer-client-timeout is set to 0 | HIGH | 7.5 | Jun 21, 2023 |
| CVE-2023-2829 | Malformed NSEC records can cause named to terminate unexpectedly when synth-from-dnssec is enabled | HIGH | 7.5 | Jun 21, 2023 |
Showing 1 to 25 of 182 CVEs