VYPR

Bind

by Isc

Source repositories

CVEs (225)

  • CVE-2019-6471MedOct 9, 2019
    risk 0.39cvss 5.9epss 0.03

    A race condition which may occur when discarding malformed packets can result in BIND exiting due to a REQUIRE assertion failure in dispatch.c. Versions affected: BIND 9.11.0 -> 9.11.7, 9.12.0 -> 9.12.4-P1, 9.14.0 -> 9.14.2. Also all releases of the BIND 9.13 development branch…

  • CVE-2018-5737MedJan 16, 2019
    risk 0.39cvss 5.9epss 0.10

    A problem with the implementation of the new serve-stale feature in BIND 9.12 can lead to an assertion failure in rbtdb.c, even when stale-answer-enable is off. Additionally, problematic interaction between the serve-stale feature and NSEC aggressive negative caching can in some…

  • CVE-2017-3136MedJan 16, 2019
    risk 0.39cvss 5.9epss 0.11

    A query with a specific set of characteristics could cause a server using DNS64 to encounter an assertion failure and terminate. An attacker could deliberately construct a query, enabling denial-of-service against a server if it was configured to use the DNS64 feature and other…

  • CVE-2016-1284MedFeb 4, 2016
    risk 0.39cvss 5.9epss 0.03

    rdataset.c in ISC BIND 9 Supported Preview Edition 9.9.8-S before 9.9.8-S5, when nxdomain-redirect is enabled, allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via crafted flag values in a query.

  • CVE-2026-77119MedSep 16, 2026
    risk 0.38cvss 5.9epss 0.00

    A validly signed NSEC3 from an unrelated sibling zone may be accepted as an insecurity proof, downgrading a secure delegation and letting a forged unsigned answer through. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25,…

  • CVE-2026-78301MedSep 16, 2026
    risk 0.38cvss 5.8epss 0.00

    A malformed zone may contain an NS or DNAME node above its origin, which `named` treats as a zone cut. If an attacker inserts a malformed zone into a BIND authoritative server (e.g., via zone transfer), queries for names inside the configured zone then lose authoritative status…

  • CVE-2026-19941MedSep 16, 2026
    risk 0.38cvss 5.9epss 0.00

    An inapplicable NSEC record may be accepted by a `named` resolver as proof that no wildcard exists, which could allow an attacker at the same or an upstream level of the zone name to mask the existence of a victim's wildcard record. This issue affects BIND 9 versions 9.11.0…

  • CVE-2026-19662MedSep 16, 2026
    risk 0.38cvss 5.9epss 0.00

    An attacker may be able to cause a `named` resolver to abort. The attack requires inducing the victim resolver to send multiple queries for a DNSSEC-signed zone hosted by an authoritative server under the control of the attacker. If the auth responds with a particular sequence…

  • CVE-2019-6475MedOct 17, 2019
    risk 0.38cvss 5.9epss 0.01

    Mirror zones are a BIND feature allowing recursive servers to pre-cache zone data provided by other servers. A mirror zone is similar to a zone of type secondary, except that its data is subject to DNSSEC validation before being used in answers, as if it had been looked up via…

  • CVE-2022-2881MedSep 21, 2022
    risk 0.36cvss 5.5epss 0.01

    The underlying bug might cause read past end of the buffer and either read memory it should not read, or crash the process.

  • CVE-2018-5736MedJan 16, 2019
    risk 0.36cvss 5.3epss 0.18

    An error in zone database reference counting can lead to an assertion failure if a server which is running an affected version of BIND attempts several transfers of a slave zone in quick succession. This defect could be deliberately exercised by an attacker who is permitted to…

  • CVE-1999-0011MedApr 8, 1998
    risk 0.36cvss 5.4epss 0.05

    Denial of Service vulnerabilities in BIND 4.9 and BIND 8 Releases via CNAME record and zone transfer.

  • CVE-2026-5950MedMay 20, 2026
    risk 0.35cvss 5.3epss 0.01

    An unbounded resend loop vulnerability exists in the BIND 9 resolver state machine during bad-server handling, enabling a remote unauthenticated attacker to cause severe resource exhaustion by sending queries that trigger specific retry conditions. This issue affects BIND 9…

  • CVE-2026-3591MedMar 25, 2026
    risk 0.35cvss 5.4epss 0.00

    A use-after-return vulnerability exists in the `named` server when handling DNS queries signed with SIG(0). Using a specially-crafted DNS request, an attacker may be able to cause an ACL to improperly (mis)match an IP address. In a default-allow ACL (denying only specific IP…

  • CVE-2022-2795MedSep 21, 2022
    risk 0.35cvss 5.3epss 0.02

    By flooding the target resolver with queries exploiting this flaw an attacker can significantly impair the resolver's performance, effectively denying legitimate clients access to the DNS resolution service.

  • CVE-2022-0396MedMar 23, 2022
    risk 0.35cvss 5.3epss 0.03

    BIND 9.16.11 -> 9.16.26, 9.17.0 -> 9.18.0 and versions 9.16.11-S1 -> 9.16.26-S1 of the BIND Supported Preview Edition. Specifically crafted TCP streams can cause connections to BIND to remain in CLOSE_WAIT status for an indefinite period of time, even after the client has…

  • CVE-2021-25219MedOct 27, 2021
    risk 0.35cvss 5.3epss 0.11

    In BIND 9.3.0 -> 9.11.35, 9.12.0 -> 9.16.21, and versions 9.9.3-S1 -> 9.11.35-S1 and 9.16.8-S1 -> 9.16.21-S1 of BIND Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.18 of the BIND 9.17 development branch, exploitation of broken authoritative servers using a…

  • CVE-2019-6465MedOct 9, 2019
    risk 0.35cvss 5.3epss 0.04

    Controls for zone transfers may not be properly applied to Dynamically Loadable Zones (DLZs) if the zones are writable Versions affected: BIND 9.9.0 -> 9.10.8-P1, 9.11.0 -> 9.11.5-P2, 9.12.0 -> 9.12.3-P2, and versions 9.9.3-S1 -> 9.11.5-S3 of BIND 9 Supported Preview Edition.…

  • CVE-2018-5738MedJan 16, 2019
    risk 0.35cvss 5.3epss 0.11

    Change #4777 (introduced in October 2017) introduced an unforeseen issue in releases which were issued after that date, affecting which clients are permitted to make recursive queries to a BIND nameserver. The intended (and documented) behavior is that if an operator has not…

  • CVE-2017-3142MedJan 16, 2019
    risk 0.35cvss 5.3epss 0.05

    An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSIG key name may be able to circumvent TSIG authentication of AXFR requests via a carefully constructed request packet. A server that relies solely on TSIG keys…

Page 6 of 12