ISC / Bind
182 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2023-2828 | named's configured cache size limit can be significantly exceeded | HIGH | 7.5 | Jun 21, 2023 |
| CVE-2022-3924 | named configured to answer from stale cache may terminate unexpectedly at recursive-clients soft quota | HIGH | 7.5 | Jan 25, 2023 |
| CVE-2022-3736 | named configured to answer from stale cache may terminate unexpectedly while processing RRSIG queries | HIGH | 7.5 | Jan 25, 2023 |
| CVE-2022-3488 | named may terminate unexpectedly when processing ECS options in repeated responses to iterative queries | HIGH | 7.5 | Jan 25, 2023 |
| CVE-2022-3094 | An UPDATE message flood may cause named to exhaust all available memory | HIGH | 7.5 | Jan 25, 2023 |
| CVE-2022-3080 | BIND 9 resolvers configured to answer from stale cache with zero stale-answer-client-timeout may terminate unexpectedly | HIGH | 7.5 | Sep 21, 2022 |
| CVE-2022-38178 | Memory leaks in EdDSA DNSSEC verification code | HIGH | 7.5 | Sep 21, 2022 |
| CVE-2022-38177 | Memory leak in ECDSA DNSSEC verification code | HIGH | 7.5 | Sep 21, 2022 |
| CVE-2022-2906 | Memory leaks in code handling Diffie-Hellman key exchange via TKEY RRs (OpenSSL 3.0.0+ only) | HIGH | 7.5 | Sep 21, 2022 |
| CVE-2022-2881 | Buffer overread in statistics channel code | HIGH | 8.2 | Sep 21, 2022 |
| CVE-2022-2795 | Processing large delegations may severely degrade resolver performance | MEDIUM | 5.3 | Sep 21, 2022 |
| CVE-2022-1183 | Destroying a TLS session early causes assertion failure | HIGH | 7.5 | May 19, 2022 |
| CVE-2021-25220 | DNS forwarders - cache poisoning vulnerability | MEDIUM | 6.8 | Mar 23, 2022 |
| CVE-2022-0635 | bind: Lookups involving a DNAME could trigger an assertion failure when 'synth-from-dnssec' was enabled (which is the default) | HIGH | 7.5 | Mar 23, 2022 |
| CVE-2022-0396 | DoS from specifically crafted TCP packets | MEDIUM | 5.3 | Mar 23, 2022 |
| CVE-2022-0667 | Assertion failure on delayed DS lookup | HIGH | 7.5 | Mar 22, 2022 |
| CVE-2021-25219 | Lame cache can be abused to severely degrade resolver performance | MEDIUM | 5.3 | Oct 27, 2021 |
| CVE-2021-25218 | A too-strict assertion check could be triggered when responses in BIND 9.16.19 and 9.17.16 require UDP fragmentation if RRL is in use | HIGH | 7.5 | Aug 18, 2021 |
| CVE-2021-25216 | A second vulnerability in BIND's GSSAPI security policy negotiation can be targeted by a buffer overflow attack | CRITICAL | 9.8 | Apr 29, 2021 |
| CVE-2021-25215 | An assertion check can fail while answering queries for DNAME records that require the DNAME to be processed to resolve itself | HIGH | 7.5 | Apr 29, 2021 |
| CVE-2021-25214 | A broken inbound incremental zone update (IXFR) can cause named to terminate unexpectedly | MEDIUM | 6.5 | Apr 29, 2021 |
| CVE-2020-8625 | A vulnerability in BIND's GSSAPI security policy negotiation can be targeted by a buffer overflow attack | HIGH | 8.1 | Feb 17, 2021 |
| CVE-2020-8624 | update-policy rules of type "subdomain" are enforced incorrectly | MEDIUM | 4.3 | Aug 21, 2020 |
| CVE-2020-8623 | A flaw in native PKCS#11 code can lead to a remotely triggerable assertion failure in pk11.c | HIGH | 7.5 | Aug 21, 2020 |
| CVE-2020-8622 | A truncated TSIG response can lead to an assertion failure | MEDIUM | 6.5 | Aug 21, 2020 |
Showing 26 to 50 of 182 CVEs