VYPR

Vendor CVEs

Isc

All CVEs

277 total · sorted by risk
  • CVE-2008-4163Sep 22, 2008
    risk 0.00cvss epss 0.05

    Unspecified vulnerability in ISC BIND 9.3.5-P2-W1, 9.4.2-P2-W1, and 9.5.0-P2-W1 on Windows allows remote attackers to cause a denial of service (UDP client handler termination) via unknown vectors.

  • CVE-2007-6283Dec 18, 2007
    risk 0.00cvss epss 0.00

    Red Hat Enterprise Linux 5 and Fedora install the Bind /etc/rndc.key file with world-readable permissions, which allows local users to perform unauthorized named commands, such as causing a denial of service by stopping named.

  • CVE-2007-5471Oct 16, 2007
    risk 0.00cvss epss 0.03

    libgssapi before 0.6-13.7, as used by the ISC BIND named daemon in SUSE Linux Enterprise Server 10 SP 1, terminates upon an initialization error, which allows remote attackers to cause a denial of service (daemon exit) via a GSS-TSIG request. NOTE: this issue probably affects…

  • CVE-2007-2925Jul 24, 2007
    risk 0.00cvss epss 0.06

    The default access control lists (ACL) in ISC BIND 9.4.0, 9.4.1, and 9.5.0a1 through 9.5.0a5 do not set the allow-recursion and allow-query-cache ACLs, which allows remote attackers to make recursive queries and query the cache.

  • CVE-2006-3122Aug 9, 2006
    risk 0.00cvss epss 0.04

    The supersede_lease function in memory.c in ISC DHCP (dhcpd) server 2.0pl5 allows remote attackers to cause a denial of service (application crash) via a DHCPDISCOVER packet with a 32 byte client-identifier, which causes the packet to be interpreted as a corrupt uid and causes…

  • CVE-2003-0914Dec 15, 2003
    risk 0.00cvss epss 0.03

    ISC BIND 8.3.x before 8.3.7, and 8.4.x before 8.4.3, allows remote attackers to poison the cache via a malicious name server that returns negative responses with a large TTL (time-to-live) value.

  • CVE-2002-2212Dec 31, 2002
    risk 0.00cvss epss 0.02

    The DNS resolver in unspecified versions of Fujitsu UXP/V, when resolving recursive DNS queries for arbitrary hosts, allows remote attackers to conduct DNS cache poisoning via a birthday attack that uses a large number of open queries for the same resource record (RR) combined…

  • CVE-2002-2213Dec 31, 2002
    risk 0.00cvss epss 0.02

    The DNS resolver in unspecified versions of Infoblox DNS One, when resolving recursive DNS queries for arbitrary hosts, allows remote attackers to conduct DNS cache poisoning via a birthday attack that uses a large number of open queries for the same resource record (RR)…

  • CVE-2002-0684Aug 12, 2002
    risk 0.00cvss epss 0.06

    Buffer overflow in DNS resolver functions that perform lookup of network names and addresses, as used in BIND 4.9.8 and ported to glibc 2.2.5 and earlier, allows remote malicious DNS servers to execute arbitrary code through a subroutine used by functions such as getnetbyname…

  • CVE-2002-0526Aug 12, 2002
    risk 0.00cvss epss 0.01

    Vulnerability in (1) inews or (2) rnews for INN 2.2.3 and earlier, related to insecure open() calls.

  • CVE-2001-0012Feb 12, 2001
    risk 0.00cvss epss 0.04

    BIND 4 and BIND 8 allow remote attackers to access sensitive information such as environment variables.

  • CVE-2000-0360Oct 20, 2000
    risk 0.00cvss epss 0.03

    Buffer overflow in INN 2.2.1 and earlier allows remote attackers to cause a denial of service via a maliciously formatted article.

  • CVE-2000-0335May 3, 2000
    risk 0.00cvss epss 0.02

    The resolver in glibc 2.1.3 uses predictable IDs, which allows a local attacker to spoof DNS query results.

  • CVE-1999-0706Apr 27, 2000
    risk 0.00cvss epss 0.02

    Linux xmonisdn package allows local users to gain root privileges by modifying the IFS or PATH environmental variables.

  • CVE-1999-0808Dec 31, 1999
    risk 0.00cvss epss 0.03

    Multiple buffer overflows in ISC DHCP Distribution server (dhcpd) 1.0 and 2.0 allow a remote attacker to cause a denial of service (crash) and possibly execute arbitrary commands via long options.

  • CVE-1999-0837Nov 10, 1999
    risk 0.00cvss epss 0.03

    Denial of service in BIND by improperly closing TCP sessions via so_linger.

  • CVE-1999-0851Nov 10, 1999
    risk 0.00cvss epss 0.00

    Denial of service in BIND named via naptr.

  • CVE-1999-0849Nov 10, 1999
    risk 0.00cvss epss 0.03

    Denial of service in BIND named via maxdname.

  • CVE-1999-0833Nov 10, 1999
    risk 0.00cvss epss 0.02

    Buffer overflow in BIND 8.2 via NXT records.

  • CVE-1999-0754May 11, 1999
    risk 0.00cvss epss 0.03

    The INN inndstart program allows local users to gain privileges by specifying an alternate configuration file using the INNCONF environmental variable.

  • CVE-1999-0785May 11, 1999
    risk 0.00cvss epss 0.01

    The INN inndstart program allows local users to gain root privileges via the "pathrun" parameter in the inn.conf file.

  • CVE-1999-0010Apr 8, 1998
    risk 0.00cvss epss 0.02

    Denial of Service vulnerability in BIND 8 Releases via maliciously formatted DNS messages.

  • CVE-1999-0024Aug 13, 1997
    risk 0.00cvss epss 0.05

    DNS cache poisoning via BIND, by predictable query IDs.

  • CVE-1999-0247Jul 21, 1997
    risk 0.00cvss epss 0.04

    Buffer overflow in nnrpd program in INN up to version 1.6 allows remote users to execute arbitrary commands.

  • CVE-1999-0184Jul 1, 1997
    risk 0.00cvss epss 0.02

    When compiled with the -DALLOW_UPDATES option, bind allows dynamic updates to the DNS server, allowing for malicious modification of DNS records.

  • CVE-1999-0868Feb 20, 1997
    risk 0.00cvss epss 0.01

    ucbmail allows remote attackers to execute commands via shell metacharacters that are passed to it from INN.

  • CVE-1999-0100Jan 1, 1997
    risk 0.00cvss epss 0.03

    Remote access in AIX innd 1.5.1, using control messages.

Page 6 of 6