ISC / BIND9
23 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2022-3080 | BIND 9 resolvers configured to answer from stale cache with zero stale-answer-client-timeout may terminate unexpectedly | HIGH | 7.5 | Sep 21, 2022 |
| CVE-2022-38178 | Memory leaks in EdDSA DNSSEC verification code | HIGH | 7.5 | Sep 21, 2022 |
| CVE-2022-38177 | Memory leak in ECDSA DNSSEC verification code | HIGH | 7.5 | Sep 21, 2022 |
| CVE-2022-2906 | Memory leaks in code handling Diffie-Hellman key exchange via TKEY RRs (OpenSSL 3.0.0+ only) | HIGH | 7.5 | Sep 21, 2022 |
| CVE-2022-2881 | Buffer overread in statistics channel code | HIGH | 8.2 | Sep 21, 2022 |
| CVE-2022-2795 | Processing large delegations may severely degrade resolver performance | MEDIUM | 5.3 | Sep 21, 2022 |
| CVE-2022-1183 | Destroying a TLS session early causes assertion failure | HIGH | 7.5 | May 19, 2022 |
| CVE-2021-25219 | Lame cache can be abused to severely degrade resolver performance | MEDIUM | 5.3 | Oct 27, 2021 |
| CVE-2021-25218 | A too-strict assertion check could be triggered when responses in BIND 9.16.19 and 9.17.16 require UDP fragmentation if RRL is in use | HIGH | 7.5 | Aug 18, 2021 |
| CVE-2021-25216 | A second vulnerability in BIND's GSSAPI security policy negotiation can be targeted by a buffer overflow attack | CRITICAL | 9.8 | Apr 29, 2021 |
| CVE-2021-25215 | An assertion check can fail while answering queries for DNAME records that require the DNAME to be processed to resolve itself | HIGH | 7.5 | Apr 29, 2021 |
| CVE-2021-25214 | A broken inbound incremental zone update (IXFR) can cause named to terminate unexpectedly | MEDIUM | 6.5 | Apr 29, 2021 |
| CVE-2020-8625 | A vulnerability in BIND's GSSAPI security policy negotiation can be targeted by a buffer overflow attack | HIGH | 8.1 | Feb 17, 2021 |
| CVE-2020-8624 | update-policy rules of type "subdomain" are enforced incorrectly | MEDIUM | 4.3 | Aug 21, 2020 |
| CVE-2020-8623 | A flaw in native PKCS#11 code can lead to a remotely triggerable assertion failure in pk11.c | HIGH | 7.5 | Aug 21, 2020 |
| CVE-2020-8622 | A truncated TSIG response can lead to an assertion failure | MEDIUM | 6.5 | Aug 21, 2020 |
| CVE-2020-8621 | Attempting QNAME minimization after forwarding can lead to an assertion failure in resolver.c | HIGH | 7.5 | Aug 21, 2020 |
| CVE-2020-8620 | bind: A specially crafted large TCP payload can trigger an assertion failure in tcpdns.c | HIGH | 7.5 | Aug 21, 2020 |
| CVE-2020-8619 | A buffer boundary check assertion in rdataset.c can fail incorrectly during zone transfer | MEDIUM | 4.9 | Jun 17, 2020 |
| CVE-2020-8618 | A buffer boundary check assertion in rdataset.c can fail incorrectly during zone transfer | MEDIUM | 4.9 | Jun 17, 2020 |
| CVE-2020-8617 | A logic error in code which checks TSIG validity can be used to trigger an assertion failure in tsig.c | HIGH | 7.5 | May 19, 2020 |
| CVE-2020-8616 | BIND does not sufficiently limit the number of fetches performed when processing referrals | HIGH | 8.6 | May 19, 2020 |
| CVE-2019-6477 | TCP-pipelined queries can bypass tcp-clients limit | HIGH | 7.5 | Nov 26, 2019 |
Showing 1 to 23 of 23 CVEs