ISC / Bind
182 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2017-3145 | Improper fetch cleanup sequencing in the resolver can cause named to crash | HIGH | 7.5 | Jan 16, 2019 |
| CVE-2017-3143 | An error in TSIG authentication can permit unauthorized dynamic updates | HIGH | 7.5 | Jan 16, 2019 |
| CVE-2017-3142 | An error in TSIG authentication can permit unauthorized zone transfers | MEDIUM | 5.3 | Jan 16, 2019 |
| CVE-2017-3141 | Windows service and uninstall paths are not quoted when BIND is installed | HIGH | 7.8 | Jan 16, 2019 |
| CVE-2017-3140 | An error processing RPZ rules can cause named to loop endlessly after handling a query | MEDIUM | 5.9 | Jan 16, 2019 |
| CVE-2017-3138 | named exits with a REQUIRE assertion failure if it receives a null command string on its control channel | MEDIUM | 6.5 | Jan 16, 2019 |
| CVE-2017-3137 | A response packet can cause a resolver to terminate when processing an answer containing a CNAME or DNAME | HIGH | 7.5 | Jan 16, 2019 |
| CVE-2017-3136 | An error handling synthesized records could cause an assertion failure when using DNS64 with "break-dnssec yes;" | MEDIUM | 5.9 | Jan 16, 2019 |
| CVE-2017-3135 | Combination of DNS64 and RPZ Can Lead to Crash | HIGH | 7.5 | Jan 16, 2019 |
| CVE-2016-9778 | An error handling certain queries using the nxdomain-redirect feature could cause a REQUIRE assertion failure in db.c | HIGH | 7.5 | Jan 16, 2019 |
| CVE-2016-9444 | bind: assertion failure while handling an unusually-formed DS record response | HIGH | 7.5 | Jan 12, 2017 |
| CVE-2016-9147 | bind: assertion failure while handling a query response containing inconsistent DNSSEC information | HIGH | 7.5 | Jan 12, 2017 |
| CVE-2016-9131 | bind: assertion failure while processing response to an ANY query | HIGH | 7.5 | Jan 12, 2017 |
| CVE-2016-8864 | bind: assertion failure while handling responses containing a DNAME answer | HIGH | 7.5 | Nov 2, 2016 |
| CVE-2016-2848 | bind: assertion failure triggered by a packet with malformed options | HIGH | 7.5 | Oct 21, 2016 |
| CVE-2016-2776 | bind: assertion failure in buffer.c while building responses to a specifically constructed request | HIGH | 7.5 | Sep 28, 2016 |
| CVE-2016-2775 | bind: Too long query name causes segmentation fault in lwresd | MEDIUM | 5.9 | Jul 19, 2016 |
| CVE-2016-6170 | bind: Improper restriction of zone size limit | MEDIUM | 6.5 | Jul 6, 2016 |
| CVE-2016-2088 | bind: malformed packet containing multiple cookie options can trigger assertion failure | MEDIUM | 6.8 | Mar 9, 2016 |
| CVE-2016-1286 | bind: malformed signature records for DNAME records can trigger assertion failure | HIGH | 8.6 | Mar 9, 2016 |
| CVE-2016-1285 | bind: malformed packet sent to rndc can trigger assertion failure | MEDIUM | 6.8 | Mar 9, 2016 |
| CVE-2016-1284 | rdataset.c in ISC BIND 9 Supported Preview Edition 9.9.8-S before 9.9.8-S5, when nxdomain-redirect is enabled, allows remote attackers to cause a denial of ser… | MEDIUM | 5.9 | Feb 4, 2016 |
| CVE-2015-8705 | bind: crash when converting OPT resource records and ECS options to text format | HIGH | 7.0 | Jan 20, 2016 |
| CVE-2015-8704 | bind: specific APL data could trigger an INSIST in apl_42.c | MEDIUM | 6.5 | Jan 20, 2016 |
| CVE-2015-8461 | bind: race condition when handling socket errors can lead to an assertion failure in resolver.c | HIGH | 7.1 | Dec 16, 2015 |
Showing 76 to 100 of 182 CVEs