ISC / Bind
182 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2020-8621 | Attempting QNAME minimization after forwarding can lead to an assertion failure in resolver.c | HIGH | 7.5 | Aug 21, 2020 |
| CVE-2020-8620 | bind: A specially crafted large TCP payload can trigger an assertion failure in tcpdns.c | HIGH | 7.5 | Aug 21, 2020 |
| CVE-2020-8619 | A buffer boundary check assertion in rdataset.c can fail incorrectly during zone transfer | MEDIUM | 4.9 | Jun 17, 2020 |
| CVE-2020-8618 | A buffer boundary check assertion in rdataset.c can fail incorrectly during zone transfer | MEDIUM | 4.9 | Jun 17, 2020 |
| CVE-2020-8617 | A logic error in code which checks TSIG validity can be used to trigger an assertion failure in tsig.c | HIGH | 7.5 | May 19, 2020 |
| CVE-2020-8616 | BIND does not sufficiently limit the number of fetches performed when processing referrals | HIGH | 8.6 | May 19, 2020 |
| CVE-2019-6477 | TCP-pipelined queries can bypass tcp-clients limit | HIGH | 7.5 | Nov 26, 2019 |
| CVE-2013-5661 | DNS response rate limiting can simplify cache poisoning attacks | MEDIUM | 5.9 | Nov 5, 2019 |
| CVE-2018-5742 | An oversight while backporting a feature leads to an assertion failure in buffer.c:420 | HIGH | 7.5 | Oct 30, 2019 |
| CVE-2019-6476 | An error in QNAME minimization code can cause BIND to exit with an assertion failure | HIGH | 7.5 | Oct 17, 2019 |
| CVE-2019-6475 | A flaw in mirror zone validity checking can allow zone data to be spoofed | HIGH | 7.5 | Oct 17, 2019 |
| CVE-2019-6471 | A race condition when discarding malformed packets can cause BIND to exit with an assertion failure | MEDIUM | 5.9 | Oct 9, 2019 |
| CVE-2019-6469 | BIND Supported Preview Edition can exit with an assertion failure if ECS is in use | HIGH | 7.5 | Oct 9, 2019 |
| CVE-2019-6468 | BIND Supported Preview Edition can exit with an assertion failure if nxdomain-redirect is used | HIGH | 7.5 | Oct 9, 2019 |
| CVE-2019-6467 | An error in the nxdomain redirect feature can cause BIND to exit with an INSIST assertion failure in query.c | HIGH | 7.5 | Oct 9, 2019 |
| CVE-2019-6465 | Zone transfer controls for writable DLZ zones were not effective | MEDIUM | 5.3 | Oct 9, 2019 |
| CVE-2018-5745 | An assertion failure can occur if a trust anchor rolls over to an unsupported key algorithm when using managed-keys | MEDIUM | 4.9 | Oct 9, 2019 |
| CVE-2018-5744 | A specially crafted packet can cause named to leak memory | HIGH | 7.5 | Oct 9, 2019 |
| CVE-2018-5743 | Limiting simultaneous TCP clients was ineffective | HIGH | 7.5 | Oct 9, 2019 |
| CVE-2018-5741 | Update policies krb5-subdomain and ms-subdomain do not enforce controls promised in their documentation | MEDIUM | 6.5 | Jan 16, 2019 |
| CVE-2018-5740 | A flaw in the "deny-answer-aliases" feature can cause an assertion failure in named | HIGH | 7.5 | Jan 16, 2019 |
| CVE-2018-5738 | Some versions of BIND can improperly permit recursive query service to unauthorized clients | HIGH | 7.5 | Jan 16, 2019 |
| CVE-2018-5737 | BIND 9.12's serve-stale implementation can cause an assertion failure in rbtdb.c or other undesirable behavior, even if serve-stale is not enabled. | HIGH | 7.5 | Jan 16, 2019 |
| CVE-2018-5736 | bind: Multiple transfers of a zone in quick succession can cause an assertion failure in rbtdb.c | MEDIUM | 5.3 | Jan 16, 2019 |
| CVE-2018-5734 | A malformed request can trigger an assertion failure in badcache.c | HIGH | 7.5 | Jan 16, 2019 |
Showing 51 to 75 of 182 CVEs